ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    F***kin WannaCry

    IT Discussion
    8
    17
    4.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Emad RE
      Emad R
      last edited by Emad R

      https://www.cyphort.com/eternalblue-exploit-actively-used-deliver-remote-access-trojans/

      According to this site:

      It creates a job file “Mysa” that would download a file a.exe via FTP from BAD SITE
      
      Then it will execute c.bat and execute another DLL file item.dat:
      
      rundll32.exe c:\windows\debug\item.dat,ServiceMain aaaa
       
      2nd Stage Payload: Item.dat
      
      We were not able to capture item.dat from our own server. This file is saved as C:\Windows\debug\item.dat and the [cmd] command expects it to be there. We believe that this is the second stage payload. 
      

      It appears that the Virus is not reaching the second state, but it advertising my machine, cause the filte item.dat and ok.dat are not found in my:

      C:\Windows\debug

      It seems the UK guy that purchased the domain of Wannacry might saved my ass.

      but this is good info for people that wants to fight this, but I wonder how did those tasks got re-created, I ran :
      schtasks /delete /tn * /f
      Last time...

      1 Reply Last reply Reply Quote 1
      • Emad RE
        Emad R @EddieJennings
        last edited by Emad R

        @EddieJennings said in F***kin WannaCry:

        Sometimes for malware, you have to nuke and start over. 😞

        Maybe its time to format and move to Windows 10, I feel like I am the last of the
        Windows 7 folks around here.

        But atleast I have the LGBT version of 10, cause I am gay and I get attacked with stupid Viruses, cause I dont like to have realtime AV scanner install slowing down my system and I thought I much smarter to get infected... Oh i meant Windows 10 LTSB version

        IRJI EddieJenningsE RojoLocoR scottalanmillerS 4 Replies Last reply Reply Quote -1
        • IRJI
          IRJ @Emad R
          last edited by

          @msff-amman-Itofficer said in F***kin WannaCry:

          @EddieJennings said in F***kin WannaCry:

          Sometimes for malware, you have to nuke and start over. 😞

          Maybe its time to format and move to Windows 10, I feel like I am the last of the
          Windows 7 folks around here.

          But atleast I have the LGBT version of 10, cause I am gay and I get attacked with stupid Viruses, cause I dont like to have realtime AV scanner install slowing down my system and I thought I much smarter to get infected... Oh i meant Windows 10 LTSB version

          I would definitely nuke and move on.

          I am not sure what you meant by the last part. I am confused?

          DustinB3403D 1 Reply Last reply Reply Quote 1
          • DustinB3403D
            DustinB3403 @IRJ
            last edited by

            @IRJ said in F***kin WannaCry:

            I would definitely nuke and move on.

            I am not sure what you meant by the last part. I am confused?

            Same

            1 Reply Last reply Reply Quote 1
            • EddieJenningsE
              EddieJennings @Emad R
              last edited by

              @msff-amman-Itofficer said in F***kin WannaCry:

              @EddieJennings said in F***kin WannaCry:

              Sometimes for malware, you have to nuke and start over. 😞

              Maybe its time to format and move to Windows 10, I feel like I am the last of the
              Windows 7 folks around here.

              But atleast I have the LGBT version of 10, cause I am gay and I get attacked with stupid Viruses, cause I dont like to have realtime AV scanner install slowing down my system and I thought I much smarter to get infected... Oh i meant Windows 10 LTSB version

              Or install Korora :D. Not sure what you mean by LGBT version of 10, but I do know Korora installs the same regardless of sexual orientation.

              1 Reply Last reply Reply Quote 0
              • RojoLocoR
                RojoLoco @Emad R
                last edited by

                @msff-amman-Itofficer WTF does sexual proclivity have to do with malware??? I don't know about anyone else, but I don't take kindly to homophobes.

                Emad RE 1 Reply Last reply Reply Quote 1
                • Emad RE
                  Emad R @RojoLoco
                  last edited by

                  @RojoLoco said in F***kin WannaCry:

                  @msff-amman-Itofficer WTF does sexual proclivity have to do with malware??? I don't know about anyone else, but I don't take kindly to homophobes.

                  how do you feel about people that get all sensitive for nothing ?

                  its joke man its just goes LSTB looks close to LGBT

                  J scottalanmillerS 2 Replies Last reply Reply Quote -2
                  • J
                    JackCPickup @Emad R
                    last edited by

                    @msff-amman-Itofficer said in F***kin WannaCry:

                    @RojoLoco said in F***kin WannaCry:

                    @msff-amman-Itofficer WTF does sexual proclivity have to do with malware??? I don't know about anyone else, but I don't take kindly to homophobes.

                    how do you feel about people that get all sensitive for nothing ?

                    its joke man its just goes LSTB looks close to LGBT

                    It sounds like a really shitty HIV/AIDS joke, makes you look like a dick if intended or not.

                    1 Reply Last reply Reply Quote 3
                    • scottalanmillerS
                      scottalanmiller @EddieJennings
                      last edited by

                      @EddieJennings said in F***kin WannaCry:

                      Sometimes for malware, you have to nuke and start over. 😞

                      No. Always for malware. There really is no exception.

                      1 Reply Last reply Reply Quote 3
                      • scottalanmillerS
                        scottalanmiller @Emad R
                        last edited by

                        @msff-amman-Itofficer said in F***kin WannaCry:

                        @EddieJennings said in F***kin WannaCry:

                        Sometimes for malware, you have to nuke and start over. 😞

                        Maybe its time to format and move to Windows 10, I feel like I am the last of the
                        Windows 7 folks around here.

                        It is and you are. Even far more trivial malware I would considered the machine lost. For something like WannaCry, keeping the machine should never be considered.

                        And yes, Windows 7 is ancient.

                        1 Reply Last reply Reply Quote 4
                        • scottalanmillerS
                          scottalanmiller @Emad R
                          last edited by

                          @msff-amman-Itofficer said in F***kin WannaCry:

                          its joke man its just goes LSTB looks close to LGBT

                          LTSB... Long Term Support Build.

                          Should have just been LTS, the industry standard term. Why they added the B to the end, no one knows.

                          DashrenderD 1 Reply Last reply Reply Quote 0
                          • DashrenderD
                            Dashrender @scottalanmiller
                            last edited by

                            @scottalanmiller said in F***kin WannaCry:

                            @msff-amman-Itofficer said in F***kin WannaCry:

                            its joke man its just goes LSTB looks close to LGBT

                            LTSB... Long Term Support Build.

                            Should have just been LTS, the industry standard term. Why they added the B to the end, no one knows.

                            Thought it was Long Term Servicing Branch?

                            I agree with Scott - if you think your computer is ever infected, you can't really ever trust it again. Format and reinstall - or restore to an old backup, whatever.. get to a known clean state.

                            scottalanmillerS 1 Reply Last reply Reply Quote 1
                            • scottalanmillerS
                              scottalanmiller @Dashrender
                              last edited by

                              @Dashrender said in F***kin WannaCry:

                              @scottalanmiller said in F***kin WannaCry:

                              @msff-amman-Itofficer said in F***kin WannaCry:

                              its joke man its just goes LSTB looks close to LGBT

                              LTSB... Long Term Support Build.

                              Should have just been LTS, the industry standard term. Why they added the B to the end, no one knows.

                              Thought it was Long Term Servicing Branch?

                              I agree with Scott - if you think your computer is ever infected, you can't really ever trust it again. Format and reinstall - or restore to an old backup, whatever.. get to a known clean state.

                              In other words, scorched earth.

                              1 Reply Last reply Reply Quote 1
                              • Emad RE
                                Emad R @Emad R
                                last edited by

                                @msff-amman-Itofficer

                                It stalking me, I disabled task scheduler service just to give me some extra few days ...

                                1_1498938549022_2017-07-01 22_45_40-Process Hacker [MeDo-PC_MeDo]+.png 0_1498938549020_2017-07-01 22_45_29-Process Hacker [MeDo-PC_MeDo]+.png

                                1 Reply Last reply Reply Quote 0
                                • Emad RE
                                  Emad R @Emad R
                                  last edited by

                                  @msff-amman-Itofficer 0_1498938797651_2017-07-01 22_52_06-debug - Clover.png
                                  0_1498938800203_2017-07-01 22_53_01-Antivirus scan for 981528cbeafd245f003c838e0db3fb55d755b447631b0472fd2c164de72dc.png

                                  1 Reply Last reply Reply Quote 0
                                  • 1 / 1
                                  • First post
                                    Last post