Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

The worm that spreads WanaCrypt0r

39 views
Skip to first unread message

Real Troll

unread,
May 14, 2017, 10:00:55 PM5/14/17
to
The snippet code is here:

<https://blog.malwarebytes.com/threat-analysis/2017/05/the-worm-that-spreads-wanacrypt0r/>

Use your brains to get it work for you in your test labs.

No Jesus needed here.

Chris M. Thomasson

unread,
May 15, 2017, 12:57:42 AM5/15/17
to
Thank you for posting this.

Chris M. Thomasson

unread,
May 15, 2017, 1:18:10 AM5/15/17
to
The one point that has me thinking is the missing leading underscore to
the _beginthreadex function:

https://msdn.microsoft.com/en-us/library/kdzttdcb.aspx

It should not link? Weird. Also, that function is used to create threads
along with an initialization of the CRT for said thread. So, the virus is C.

Creating code on Windows that does not use the CRT can make use of
CreateThread. Strange that a virus is not written in assembly language.

Rick C. Hodgin

unread,
May 15, 2017, 3:18:40 AM5/15/17
to
Real Troll wrote:
> No Jesus needed here.

This belief will seem to work well until you leave this world and are summoned
by name to give an account of your life and it's realized your sin is still with
you, God is real, judgment for sin is real, and Hellfire is real.

It's why God warns you in advance ... to give you space and time to repent,
and to come to Jesus asking forgiveness.

You must do this today, because none of us are promised tomorrow.

Thank you,
Rick C. Hodgin

Cholo Lennon

unread,
May 15, 2017, 9:33:58 AM5/15/17
to
On 15/05/17 02:18, Chris M. Thomasson wrote:
> Strange that a virus is not written in assembly language.

Well, nowadays it's very unusual for a virus/malware to be written in
assembler, it has no sense (IMO)


--
Cholo Lennon
Bs.As.
ARG

Chris M. Thomasson

unread,
May 15, 2017, 1:32:36 PM5/15/17
to
On 5/15/2017 6:33 AM, Cholo Lennon wrote:
> On 15/05/17 02:18, Chris M. Thomasson wrote:
>> Strange that a virus is not written in assembly language.
>
> Well, nowadays it's very unusual for a virus/malware to be written in
> assembler, it has no sense (IMO)

Okay. I have not been keeping up.

0 new messages