Malware- Wana DecryptOr - Need some help

I've got struggling with ransomware before don't know how to decrypt your files but i have some suggestion for Windows VPS may help you:
- After setting up your VPS, change the remote desktop connection port : 3389 to another port , keep it secret so only you can remote connect to your VPS.
- Setup a Kaspersky or any licensed antivirus program on your VPS to protect it.
These changes will help your VPS safer.
 
I guess you talk by what you heard / read on the net which is often misleading and contribute to feed wrong beliefs like if you pay at 80% it will be sent to you unlocking code.

You guess wrong my friend.

If the ransom would have automation, would be a lot easier intercept network connections it would be trying to establish and to trace source/take down for authorities.

Have you even seen a C&C of any ransomware or botnet in general ?

You know that the almost every malware bin ( ransomware included, with some standalone exceptions ) connects to the C&C on certain intervals to post alive status and other information.

If catching a compromised host was that easy to trace from only a single network intercept than this world would be easily cleansed of malware.

The communication encryption + the usage of fast flux in advance botnets makes it almost impossible to pin point the host origin.

I could keep on going about this but since you are an expert i guess you already know all about this.

I talk by experience for doing forensic analysis on about 15 variants of ransom.

If you have truly done forensic analysis on 15 variants of ransomware than we would be having a whole different conversation.

Cheers
 
I guess its over? At least slowed down...
http://abcnews.go.com/International/researcher-accidentally-stops-spread-unprecedented-global-cyberattack/story?id=47390745

I was about to start monetizing on this chaos by posting to local facebook groups about getting them the appropriate patch installed and beef up security with antiviruses and just do a "tune up" of their PC's.

Still can. Any hustler should be contacting businesses and monetize the chaos.
 
You guess wrong my friend.

So you code ransom?

You know that the almost every malware bin ( ransomware included, with some standalone exceptions ) connects to the C&C on certain intervals to post alive status and other information.

Not true for ransomwares, you talk by having botnet background. Please post some variant name/evidence, or you are just yapping
 
I don't know if they knew they targeted hospitals but if they did I hope karma will strike them soon!
 
Is phishing emails the only way this thing is getting around? Or are there other means?

Spent 3 hours today finding the latest security update and manually updating all my devices.

WannaCry is self replicating through the IP ranges. It was seeded by some phishing emails at first and then it escalated through the networks (either network shares or incrementing the IP)
Fortunately, the first wave was contained and it only required a domain registration as the malware had a condition to replicate only if a domain wasn't resolving. It is more likely a kill switch to keep a certain control.

It was using the NSA toolkit exploit, we have posted more details about the threat at the link below :

https://www.host-stage.net/blog/world-wide-ransomware-outbreak-using-the-nsa-toolkit/
 
Back
Top