Know How... (Audio)

KH 312: Networking 102: WannaCry Ransomware


Listen Later

We take a look at how the ransomware WannaCry works and how, along with how not to get infected and what to do if you are.

WannaCry

Infection
* Used the NSA-developed "Eternal Blue" that was released by the shadow brokers
* Initial infection was via emailed link or attachment
* Once Infected
1. Checks a domain to see if it responds (kill-switch)
2. Exploits an SMB vulnerability to move laterally
3. Installs the "DoublePulsar" Backdoor (which stays even if ransom is paid for decrypt)
4. Demands $300-$600 in bitcoin
* We have to wait for numbers, but anecdotally it seems that XP is taking the brunt of the attack

First Impact
* > 400,000 computers infected so far
* > 200 countries (Across Europe, Asia, some of the Americas)
* Shut down manufacturing at Renault in France and Romania
* Shut down Nissan in England
* Also affected health services in Brittian and required patients to be redirected

Mitigation
* Didn't hit the US as much b/c by the time the attack had turned, filters were attuned to the Phishing attack
* A British researcher, "@MalwareTechBlog" on Twitter, noticed that the malware was trying ot connect to a domain. He registered it and it mitigated the attacks.
- We know he's a 22-year old from south-west England who works for LA-based threat-intelligence company, "Kryptos Logic"

Second Impact
* Researchers are confirming that there is a second revision of WannaCry in circulation that removed the kill-switch check
* There have been MILLIONS of office computers left attended over the weekend, many probably left on.
- There WAS a rise in infections, but not the MASSIVE infection some were worried about

Second Mitigation
* Non-tech media (and even CNET/CBS) are speaking of this attack as if it is over. VERY not the case
* The second version does NOT check for the kill-switch site
* Steps to take:
1. Backup
2. No clicking, no attachments
3. If you are in a high-risk network, disconnect, d/l the patches from a secured machine, run offline, reconnect
4. If you have the tools, look for probing SMB attacks

Notes
* MS released a patch for this in March 2017
** They ALSO released a patch for XP and Sever 2003, even though those are no longer in use.

What to watch for LLMNR
* Local-Link Multicast Name Resolution
* This is a Windows protocol that provides name resolution for hosts on the same local link

Hosts: Fr. Robert Ballecer, SJ and Bryan Burnett

Connect with us!

  • Don't forget to check out our large library of projects at https://twit.tv/shows/know-how.
  • Join our Google+ Community.
  • Tweet at us at @PadreSJ, @Cranky_Hippo, and @Anelf3.

Thanks to CacheFly for the bandwidth for this show.

...more
View all episodesView all episodes
Download on the App Store

Know How... (Audio)By TWiT

  • 4.5
  • 4.5
  • 4.5
  • 4.5
  • 4.5

4.5

35 ratings


More shows like Know How... (Audio)

View all
The Giz Wiz (Audio) by Dick DeBartolo & Chad Johnson

The Giz Wiz (Audio)

138 Listeners

This Week in Law (Audio) by TWiT

This Week in Law (Audio)

110 Listeners

Jumping Monkeys (Audio) by TWiT

Jumping Monkeys (Audio)

72 Listeners

Dr. Kiki's Science Hour (Audio) by TWiT

Dr. Kiki's Science Hour (Audio)

96 Listeners

Maxwell's House (Audio) by TWiT

Maxwell's House (Audio)

35 Listeners

net@night (Video) by TWiT

net@night (Video)

24 Listeners

Futures in Biotech (Video) by TWiT

Futures in Biotech (Video)

10 Listeners

Ham Nation by Josh Nass

Ham Nation

115 Listeners

Trey's Variety Hour (Video) by TWiT

Trey's Variety Hour (Video)

35 Listeners

This Week in Enterprise Tech (Audio) by TWiT

This Week in Enterprise Tech (Audio)

94 Listeners

The Giz Wiz (HD Video) by Dick DeBartolo & Chad Johnson

The Giz Wiz (HD Video)

28 Listeners

This Week in Law (Video) by TWiT

This Week in Law (Video)

6 Listeners

This Week in YouTube (Audio) by TWiT

This Week in YouTube (Audio)

9 Listeners

FourCast (Audio) by TWiT

FourCast (Audio)

0 Listeners

Coding 101 (Audio) by TWiT

Coding 101 (Audio)

15 Listeners

Padre's Corner (Video) by TWiT

Padre's Corner (Video)

9 Listeners

The New Screen Savers (Audio) by TWiT

The New Screen Savers (Audio)

50 Listeners

Ask The Tech Guy (Vintage) (Audio) by TWiT

Ask The Tech Guy (Vintage) (Audio)

28 Listeners

Hands-On Photography (Audio) by TWiT

Hands-On Photography (Audio)

31 Listeners

Ask The Tech Guy (Video) by TWiT

Ask The Tech Guy (Video)

0 Listeners