Sunday, May 14, 2017

Wcry Ransomware Spread Across the Internet

The first worrying thing about Wcry worm is when it attacked health care
facilities in the U.K. They had to wave off patients and direct them to
another hospital. Then an ISP in Spain was attacked too. It encrypts and
locks your data and demands payment before it decrypts it.

Wcry attacks a vulnerability in Windows known to the NSA who
deliberately kept it a secret. Wcry was stopped dead by a happy
accident. A malware researcher who was analysing the attack found a
subroutine that HTTP's to an unregistered domain. He registered that
domain to a prepared sinkhole. So the researcher already has prepared
infrastructure to trap malware like this. The subroutine exits once it
gets a registered domain, basically a killswitch.
Post a Comment

Reflections On My Blogging: Keeping It Honest

When you're facing a white, blank screen trying to decide what to write, it seemed hopeless and hopeful at the same time. It's like...