A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #30350  by maddog4012
 Mon May 15, 2017 1:49 pm
v3rd1ct wrote:maddog, your included password is not working?

my bad sorry all samples use the password virus
 #30354  by EP_X0FF
 Tue May 16, 2017 7:37 am
Regarding to numerous "kill wannacryers" spreading rapidly via twitter.

So you want to say that users have enough admin rights to install piece of shit code (and yes it is exactly piece of shit) which purpose is to create a fucking mutex (from service OMG WTF) and add entries to hosts. But the same users magically cannot install official MS patch and block a fucking SMB port? Excuse but this is fucking lol as well as all this overhyped story.

And don't forget all these "my super complete technical ultimate analysis of wanacry", lol. Since when ransomware was so fucking advanced so they required so much attention to their "technical part"? Classical attention whoring from so called "security community".
 #30356  by ikolor
 Tue May 16, 2017 4:11 pm
Maybe stupid question .But I will try .Who used and spread this malware code.Some said North Korea .
 #30357  by EP_X0FF
 Tue May 16, 2017 5:16 pm
ikolor wrote:Maybe stupid question .But I will try .Who used and spread this malware code.Some said North Korea .
If it were North Korea then ransomware would sank somewhere in the middle of Sea of Japan.