iTnews

New WannaCrypt variants emerge

By Juha Saarinen, iTnews on May 16, 2017 6:48AM
New WannaCrypt variants emerge

Fears of no kill switch unfounded so far.

The WannaCrypt ransomware worm has been modified with new "kill switch" domain names, researchers have found.

Comae Technologies researcher Matt Suiche said he had discovered new variants of WannaCrypt on infected machines.

As with the original WannaCrypt malware, one of the new variants had a domain name hard coded in.

WannaCrypt tries to connect to a server at the domain name in question. It is potentially a test to see if WannaCrypt is being executed in a sandboxed environment - as used by researchers analysing malware - and if it succeeds in contacting the domain, it will not attempt to spread further.

A British researcher who goes by the name of MalwareTech took advantage of this, and registered the original domain name hard coded into WannaCrypt in order to slow down the spread of the worm.

Suiche similarly registered the new domain name in the modified WannaCrypt variant he found, so it could act as a "kill switch" and stop the execution of the malware.

He said over 10,000 machines were connected to the domain, mainly from Russia, and did not continue to spread WannaCrypt as a result of his registration.

Security vendor Check Point Software also discovered a new variant of WannaCrypt and registered its “kill switch” domain name.

The company said that apart from the domain name, the rest of the code in the new WannaCrypt variant was similar to older versions of the malware.

Another sample of WannaCrypt that appears to have been patched to remove the "kill switch" domain name was shared by Kaspersky researcher Constantin Raiu, sparking fears that the simple trick preventing the malware from spreading would no longer work.

However, the sample shared by Raiu turned to be corrupt, and only works partially; it is not able to infect systems.

Suiche believes this is a temporary mistake and a WannaCrypt version without the domain name "kill switch" will appear soon.

Five variants of WannaCrypt have been found in the wild so far.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
ransomware security wannacrypt wcrypt

Partner Content

Beat the DDoS blackmails in 2021
Partner Content Beat the DDoS blackmails in 2021
Why companies fail at picking cloud modernisation partners
Partner Content Why companies fail at picking cloud modernisation partners
Shut the door on ransomware
Partner Content Shut the door on ransomware
MSI shows first laptops with Wi-Fi 6E, Nvidia RTX 30 graphics
Partner Content MSI shows first laptops with Wi-Fi 6E, Nvidia RTX 30 graphics

Sponsored Whitepapers

Five questions to ask before you upgrade to a SIEM solution
Five questions to ask before you upgrade to a SIEM solution
Effectively addressing advanced threats
Effectively addressing advanced threats
The risky business of open source
The risky business of open source
Ensure your e-signatures are legally binding
Ensure your e-signatures are legally binding
Mitigating open source risk in your organisation
Mitigating open source risk in your organisation

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
  • Beat the DDoS blackmailers in 2021
By Juha Saarinen, iTnews
May 16 2017
6:48AM
0 Comments

Related Articles

  • Ransomware gang Ryuk thought to have pulled in US$150 million
  • Ransomware outed as cause of State Transit Authority outage
  • Law In Order hit by ransomware attack
  • Isentia ransomware attack expected to cost at least $7 million
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Telstra blasts plan to 'set aside' mobile spectrum for Optus and TPG, but not it

Telstra blasts plan to 'set aside' mobile spectrum for Optus and TPG, but not it

Australia Post is building a digital twin of its delivery network

Australia Post is building a digital twin of its delivery network

Trump pardons former Google self-driving car engineer

Trump pardons former Google self-driving car engineer

Defence switches on initial SAP ERP system capability

Defence switches on initial SAP ERP system capability

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.