Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Tuesday’s massive ransomware outbreak was, in fact, something much worse
ArsTechnica ^ | 6/29/2017 | DAN GOODIN

Posted on 06/28/2017 9:51:49 PM PDT by TigerLikesRooster

Tuesday’s massive ransomware outbreak was, in fact, something much worse

Payload delivered in mass attack destroys data, with no hope of recovery.

DAN GOODIN - 6/29/2017, 5:30 AM

Tuesday's massive outbreak of malware that shut down computers around the world has been almost universally blamed on ransomware, which by definition seeks to make money by unlocking data held hostage only if victims pay a hefty fee. Now, some researchers are drawing an even bleaker assessment—that the malware was a wiper with the objective of permanently destroying data.

Initially, researchers said the malware was a new version of the Petya ransomware that first struck in early 2016. Later, researchers said it was a new, never-before-seen ransomware package that mimicked some of Petya's behaviors. With more time to analyze the malware, researchers on Wednesday are highlighting some curious behavior for a piece of malware that was nearly perfect in almost all other respects: its code is so aggressive that it's impossible for victims to recover their data.

In other words, the researchers said, the payload delivered in Tuesday's outbreak wasn't ransomware at all. Instead, its true objective was to permanently wipe as many hard drives as possible on infected networks, in much the way the Shamoon disk wiper left a wake of destruction in Saudi Arabia. Some researchers have said Shamoon is likely the work of developers sponsored by an as-yet unidentified country. Researchers analyzing Tuesday's malware—alternatively dubbed PetyaWrap, NotPetya, and ExPetr—are speculating the ransom note left behind in Tuesday's attack was, in fact, a hoax intended to capitalize on media interest sparked by last month's massive WCry outbreak.

(Excerpt) Read more at arstechnica.com ...


TOPICS: Chit/Chat; Computers/Internet
KEYWORDS: petya; ransomware; ukraine
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-73 next last
To: TigerLikesRooster

Hillary Clinton on line 2....


21 posted on 06/28/2017 11:39:46 PM PDT by relictele
[ Post Reply | Private Reply | To 1 | View Replies]

To: TigerLikesRooster

Can they just target Mueller and his minions?


22 posted on 06/29/2017 12:03:44 AM PDT by Paladin2 (No spelchk nor wrong word auto substition on mobile dev. Please be intelligent and deal with it....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TigerLikesRooster

I swear, for decades it’s always those darn DO Looops that allow one to Bigly enhance one’s ability to make mistakes.


23 posted on 06/29/2017 12:09:43 AM PDT by Paladin2 (No spelchk nor wrong word auto substition on mobile dev. Please be intelligent and deal with it....)
[ Post Reply | Private Reply | To 4 | View Replies]

To: TigerLikesRooster
Simple Windows vaccine for current version of Petya:

https://www.bleepingcomputer.com/news/security/vaccine-not-killswitch-found-for-petya-notpetya-ransomware-outbreak/

That page contains a link to this short batch file program:

https://download.bleepingcomputer.com/bats/nopetyavac.bat

Download it, right click the downloaded program, and run it as administrator.

Don't be surprised if a later version of Petya is not blocked by this technique.

24 posted on 06/29/2017 12:13:10 AM PDT by TChad
[ Post Reply | Private Reply | To 1 | View Replies]

To: Paladin2
Nearly impossible to write a program with no loops, though.
New generation of object-oriented languages turned simple loop tasks into methods attached to an object. Still you eventually need your own user-defined loops.
25 posted on 06/29/2017 12:22:49 AM PDT by TigerLikesRooster (dead parakeet + lost fishing gear = freep all day)
[ Post Reply | Private Reply | To 23 | View Replies]

To: TChad

Ping


26 posted on 06/29/2017 1:37:38 AM PDT by BushCountry (thinks he needs a gal whose name doesn't end in ".jpg")
[ Post Reply | Private Reply | To 24 | View Replies]

To: 867V309

If you use Firefox (mine’s Linux version, Iceweasel) there is a plugin called No Script. I’ve used it for several years.

That and task manager is how I combat Java script attacks. I commonly get them. I only enable the minimum number of Java scripts for a specific site. It has helped.

It may not be protection from this attack.


27 posted on 06/29/2017 2:58:11 AM PDT by Texas Fossil ((Texas is not where you were born, but a Free State of Heart, Mind & Attitude!))
[ Post Reply | Private Reply | To 17 | View Replies]

To: 867V309

But all of what you said is true and valid advice.


28 posted on 06/29/2017 2:59:00 AM PDT by Texas Fossil ((Texas is not where you were born, but a Free State of Heart, Mind & Attitude!))
[ Post Reply | Private Reply | To 17 | View Replies]

To: TChad

So how does one know this is safe?


29 posted on 06/29/2017 3:13:32 AM PDT by mad_as_he$$ (Not my circus. Not my monkeys.)
[ Post Reply | Private Reply | To 24 | View Replies]

To: dr_lew

Fie on the cloud! Why anyone would want ANY of their stuff “out there” in cyberspace is beyond me.


30 posted on 06/29/2017 3:21:02 AM PDT by MayflowerMadam ("Negative people make healthy people sick." - Roger Ailes)
[ Post Reply | Private Reply | To 9 | View Replies]

To: TigerLikesRooster
From the article:

In almost all other aspects, Tuesday's malware was impressive. It used two exploits developed by and later stolen from the National Security Agency. It combined those exploits with custom code that stole network credentials so the malware could infect fully patched Windows computers. And it was seeded by compromising the update mechanism for M.E.Doc, a tax-filing application that is almost mandatory for companies that do business in Ukraine.

31 posted on 06/29/2017 3:21:04 AM PDT by dynachrome (When an empire dies, you are left with vast monuments in front of which peasants squat to defecate)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MayflowerMadam
You may dodge cloud onslaught for now, but all big IT companies will force people to use cloud. A growing number of companies offer cloud-only service.
32 posted on 06/29/2017 3:26:37 AM PDT by TigerLikesRooster (dead parakeet + lost fishing gear = freep all day)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Strac6
FOUR TB FOR $129, Incredible!

I remember looking in awe at a 1GB drive.

33 posted on 06/29/2017 3:36:36 AM PDT by fso301
[ Post Reply | Private Reply | To 20 | View Replies]

To: TigerLikesRooster

“You may dodge cloud onslaught for now, but all big IT companies will force people to use cloud.”

That’s fine, I guess. I’m almost 70 and retired, and I don’t really have/do anything important. I’ll just continue to use my 2T external for now.


34 posted on 06/29/2017 3:38:37 AM PDT by MayflowerMadam ("Negative people make healthy people sick." - Roger Ailes)
[ Post Reply | Private Reply | To 32 | View Replies]

To: Strac6

Actually, I think it was a 2.1GB drive. Might have been a Seagate drive.


35 posted on 06/29/2017 3:43:22 AM PDT by fso301
[ Post Reply | Private Reply | To 20 | View Replies]

To: MayflowerMadam
Keep all your program installation CD’s and offline installation files. That will come handy someday. They may not even allow offline program installation soon.
36 posted on 06/29/2017 3:45:06 AM PDT by TigerLikesRooster (dead parakeet + lost fishing gear = freep all day)
[ Post Reply | Private Reply | To 34 | View Replies]

To: fso301

I paid nearly $800 for a 20 MB SCSI hard drive. Hard to believe...


37 posted on 06/29/2017 3:47:18 AM PDT by rlmorel (Liberals are in a state of constant cognitive dissonance, which explains their mental instability.)
[ Post Reply | Private Reply | To 33 | View Replies]

To: TigerLikesRooster

Clinton Foundation has a lot of cash to help pay for such work around the globe to meet their ends.


38 posted on 06/29/2017 3:52:26 AM PDT by CincyRichieRich (We must never shut up. Covfefe: A great dish served piping hot!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fso301
Seagate drives are not really reliable. Might have some convenient features, but they tend to die sooner than I expected.

If you want them for purely backup purpose, Japanese drives could be better choices. They are purely external storage devices, not trying to be close substitutes for internal hard drives, which have to handle constant data transfer. My experience shows that they are more durable. I used to use Seagate but switched to Toshiba. So far they are doing well.

39 posted on 06/29/2017 3:53:23 AM PDT by TigerLikesRooster (dead parakeet + lost fishing gear = freep all day)
[ Post Reply | Private Reply | To 35 | View Replies]

To: Strac6

I have a hard drive dock and several hard drives in a box in my closet. At least once a week I take the oldest backup and overwrite it with a new full image backup. I also have a program that views all email in non-HTML mode so I can delete anything questionable before loading my mail program.


40 posted on 06/29/2017 3:54:20 AM PDT by AMiller (Almiller)
[ Post Reply | Private Reply | To 20 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-73 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson