Trojan.Ransom.WannaCrypt (WanaCrypt0r 2.0/WannaCry, NHS Ransomware)

Sdílet
Vložit
  • čas přidán 13. 05. 2017
  • / danooct1
    / danooct1
    a few links for further (and interesting) reading: www.malwaretech.com/2017/05/h...
    www.theguardian.com/technolog...
    major thanks to malwaretech team for stopping the ransomware in its tracks, xylitol for the hookup once again, and all of you who took the time to message me about the ransomware.
    Thanks to the following $5+ patrons!
    John Kizer
    Numou
    crymera
    handsome jack
    Thomas H Khoury
    Joshua Mack
    Mister Sparkly
    Jade
    squigly-kip
    Matthew K
    Alice J
    Renaud Bedard
    Blaise
    Sleepy Owl
    Rosenator
    Robert G
    Si Mellor
    BluePolar Bearz
  • Zábava

Komentáře • 1,5K

  • @AwesumIndustrys
    @AwesumIndustrys Před 7 lety +3150

    You know it's serious shit when obsolete software gets patched.

    • @DMack6464
      @DMack6464 Před 7 lety +40

      Are they gonna release a patch for Windows 95?

    • @cam6656
      @cam6656 Před 7 lety +74

      microsoft still cares about xp, so you can still use it :)

    • @b_28282
      @b_28282 Před 7 lety +92

      Cam No they don't

    • @CWINDOWSsystem32
      @CWINDOWSsystem32 Před 7 lety +2

      +InfernoDukem It's pretty much a fact that Windows XP is obsolete by now...

    • @johnl.38
      @johnl.38 Před 7 lety +16

      pretty sure gas stations still run XP on pumps and ATMs may also do the same

  • @Leurak
    @Leurak Před 7 lety +1980

    If it works without the network connected, where is the decryption key saved?

    • @mrdaxtercrane
      @mrdaxtercrane Před 7 lety +293

      It's so early into investigation, I would assume they didn't know.

    • @realcomputerdude100
      @realcomputerdude100 Před 7 lety +489

      I would imagine that it attempts to send it, fails, and continues to delete the key.

    • @OGZClanChannel
      @OGZClanChannel Před 7 lety +178

      that's a really good question lmao

    • @LiEnby
      @LiEnby Před 7 lety +93

      run it in sandboxie and check?

    • @abcddd32123
      @abcddd32123 Před 7 lety +47

      @thecomputerman100 ^this

  • @DrachenYT
    @DrachenYT Před 7 lety +3125

    When you hit that point in your life where it wouldn't even matter if you got hit by this because worst case scenario you just lose your memes.

    • @b_28282
      @b_28282 Před 7 lety +167

      But my Minecraft worlds would be gone too!!!
      *_*pays 0.17 BTC_**

    • @chcikety
      @chcikety Před 7 lety +69

      I actually did lose my memes to ransomeware :( It was devestating... I hate those boogerheads >:(

    • @bitelaserkhalif
      @bitelaserkhalif Před 7 lety +2

      Drachen you lose the moddig projects

    • @BigOlSmellyFlashlight
      @BigOlSmellyFlashlight Před 7 lety +9

      Drachen I lose all my animations and backups from 2013

    • @w4str
      @w4str Před 7 lety +2

      true my friend

  • @EthanBB
    @EthanBB Před 7 lety +907

    Actually, there is absolutely no point to pay the ransom. It has only 3 bitcoin addresses hardcoded into program (shown randomly) and there is no way attacker could recognize the payment was from you. Meaning there was never any intention to be able to decrypt the files.

    • @White_Tiger93
      @White_Tiger93 Před 5 lety +9

      so how do you solve this problem without resort to pay them??

    • @stedmangg
      @stedmangg Před 5 lety +241

      *you don't*

    • @karlkastor
      @karlkastor Před 5 lety +104

      @@White_Tiger93 wait till someone writes a decryption program and/or the decryption keys leak. I believe there is already free decryption software for WannaCry out there. Sometimes the keys needed for decryption are still in the RAM of the computer, so there might be software that can get the keys, but it only works a short time after the malware was started.

    • @GRBtutorials
      @GRBtutorials Před 5 lety +89

      @@White_Tiger93 Restore from backup. Because you have a backup, don't you?

    • @patriotapatriotski4809
      @patriotapatriotski4809 Před 5 lety +4

      I was wondering can u use safe mode in this situation ???

  • @itsdustyy598
    @itsdustyy598 Před 7 lety +2117

    You have a girlfriend?
    Me- I used to have one, but she Ransomewhere.

    • @PsychoFizz
      @PsychoFizz Před 7 lety +84

      ItsDustyy I laughed harder than necessary at this.

    • @FrigidBirostrixRay
      @FrigidBirostrixRay Před 6 lety +9

      ItsDustyy
      LMAO

    • @WhoLetTheDogOut
      @WhoLetTheDogOut Před 6 lety +13

      ItsDustyy
      Really? Only 10 Likes? That was freaking clever and funny!

    • @goodbyetothemaskedme
      @goodbyetothemaskedme Před 6 lety +5

      ItsDustyy I'm laughing harder than I should be 😂😂

    • @manaralameri1650
      @manaralameri1650 Před 6 lety +25

      ItsDustyy it’s true, she ran some where, and you have to pay her or else she leaves you.

  • @austyn.l6289
    @austyn.l6289 Před 7 lety +2003

    Ooops, this comment has been encrypted!

    • @b_28282
      @b_28282 Před 7 lety +135

      WHERE DO I SEND MY BITCOINS?!

    • @andy56duky
      @andy56duky Před 7 lety +49

      /b/ 28282 ah shit. my ass got encrypted as well.

    • @adamwilderspin7854
      @adamwilderspin7854 Před 7 lety +14

      Austyn LeDrew How many bit coins to decrypt it...?

    • @Komeiji0401
      @Komeiji0401 Před 7 lety +19

      Here is a key to decrypt your comment:
      hssianaizbwhu72!*hwnai;#!isn8#!@62;#8$;

    • @michaelbaterna8386
      @michaelbaterna8386 Před 7 lety +11

      Error: File not found

  • @Zyzzywyz
    @Zyzzywyz Před 7 lety +179

    Lol, "It's rich af" in the Rich Text document.

  • @Wozzot
    @Wozzot Před 7 lety +177

    The interesting thing about the kill-switch is that it's actually a poorly implemented sandbox test.
    Malware authors want to thwart security researchers for as long as possible to delay any attempt at a countermeasure, and one technique for doing so is refusing to run in any sandboxed virtual machine environment. Sandboxes for malware often give it everything they want in order to analyze it to the fullest extent possible: for instance, if something wants to access a domain, the sandbox will give it something to connect to, whether or not it exists on the real Internet. Thus, if WannaCrypt manages to connect to a domain that it thinks doesn't exist, it'll conclude that it's being monitored and self-terminate.
    Normally, malware of this kind randomly generates the domains to be checked, but the author of WannaCrypt hard-coded it into the program instead, meaning that since someone registered the domain in the real world, it always mistakenly thinks that it's being run in a VM, whether or not it actually is.

    • @aamyushh
      @aamyushh Před rokem +6

      thank you for this i have been wondering for hours now and its 4am and am deep down a rabbithole

    • @smashi4088
      @smashi4088 Před rokem +4

      that's a super clever strategy, good thing whoever made this didn't think of that

  • @CWINDOWSsystem32
    @CWINDOWSsystem32 Před 7 lety +349

    Hey, props to Microsoft for actually releasing a patch for XP for this. Pretty ridiculous that some government systems are still running a 16 year-old unsupported OS though...

    • @QuantumEcho7
      @QuantumEcho7 Před 7 lety +1

      CWINDOWSsystem32 I guess it's cheaper for our stupid government

    • @CWINDOWSsystem32
      @CWINDOWSsystem32 Před 7 lety +8

      +QEproductions7 I hope they learned their lesson from this and actually hire some decent IT people and upgrade the systems to at least Windows 7...

    • @QuantumEcho7
      @QuantumEcho7 Před 7 lety +2

      CWINDOWSsystem32 I suppose they're too busy sitting back and waiting for their victory in the election to care about the country lol

    • @danem2215
      @danem2215 Před 4 lety +22

      The United States ran its entire nuclear missile command from 50 year old 8" floppy drives until like 6 months ago

    • @notgray88
      @notgray88 Před 4 lety +1

      My high school was still running windows 98 just 3 years ago lmao.

  • @rougeamp1
    @rougeamp1 Před 7 lety +257

    this is how the civil war started

  • @rcollosi
    @rcollosi Před 2 lety +17

    i remember when this was the biggest threat to your computer. feels just like yesterday, even though it was 4 years ago

    • @Solaceon
      @Solaceon Před rokem +3

      Don't worry, ransomware is still going strong.

  • @baradragonsftw9310
    @baradragonsftw9310 Před 7 lety +359

    *viruses, years ago: haha i wrecked your computer, lol, you lost everything*
    *viruses now: pls give me money*

    • @AWISECROW
      @AWISECROW Před 5 lety +30

      NotPetya: pls give me money (wrecked your computer, lol, you lost everything anyway)

    • @daniloaltamera8385
      @daniloaltamera8385 Před 5 lety

      PandoTech:Hold my beer

    • @OiranDaki
      @OiranDaki Před 4 lety +4

      @Floppy 6022 ???

    • @ABC-in2le
      @ABC-in2le Před 4 lety +5

      Viruses now: MEEEEEEEMZ

    • @GodzillaKaijuGK
      @GodzillaKaijuGK Před 2 lety +1

      @@ABC-in2le there should be a MEMZ computer epidemic

  • @BlinkLed
    @BlinkLed Před 7 lety +103

    It's the new Captain Crunch cereal, "Oops, All Ransomware"

    • @radioactivian
      @radioactivian Před 3 lety

      jokes on you I speak enchantment table

    • @ChaseMC215
      @ChaseMC215 Před 2 lety

      That's nice, Captain. But oh that time you fucked up and your cereal was just All Berries?

  • @vwestlife
    @vwestlife Před 7 lety +38

    People on MSFN are saying that it is impossible for WannaCry to infect a system running from a FAT32 partition, because it relies upon NTFS to encrypt the files. Can you verify this?

  • @jadegecko
    @jadegecko Před 7 lety +20

    Here I was, thinking of you as a retro '90s-virus connoisseur. And here you are on the bleeding edge of world news.
    Albeit world news that affects people with badly out of date systems...
    Anyway, you're awesome. It's really neat to get to see this stuff in a context that's not dangerous or malicious in nature.

  • @unsatisfiedfans7422
    @unsatisfiedfans7422 Před 4 měsíci +3

    I just want to thank you because your computer virus highlight videos (especially on ransomwares) are the inspiration for my thesis on computer virus

  • @burrito64burrito64
    @burrito64burrito64 Před 7 lety +337

    Hey Danooct1 you should have put the blog post Microsoft put on their webpage. It's almost like a middle finger to the NSA

    • @SimplyChem32
      @SimplyChem32 Před 7 lety +13

      blogs.microsoft.com/on-the-issues/2017/05/14/need-urgent-collective-action-keep-people-safe-online-lessons-last-weeks-cyberattack/#sm.0000otkst81x2dg2rb51g3fgd0f6k There's the full blog post from their site, 8th paragraph down talks about the NSA.

    • @userPrehistoricman
      @userPrehistoricman Před 7 lety +1

      Then why don't you link it???

    • @Scootaloose
      @Scootaloose Před 7 lety +7

      That kind of comment is the same kind of crap you see on support forums when someone goes "found the problem it's fixed now" but never posts the solution.
      Link in question:
      blogs.microsoft.com/on-the-issues/2017/05/14/need-urgent-collective-action-keep-people-safe-online-lessons-last-weeks-cyberattack/

    • @burrito64burrito64
      @burrito64burrito64 Před 7 lety +13

      Prehistoricman
      I posted a reply with a link to it, but I think it get deleted as spam. The link appears on my screen right below my comment.
      Can you see it?

    • @Werwa_
      @Werwa_ Před 7 lety

      burrito64burrito64 nope. Try adding a space in between the link and the ".com" or something

  • @pcsecuritychannel
    @pcsecuritychannel Před 7 lety +61

    They have come up with a newer version that doesn't have the killswitch. Another wave may be coming soon. Hopefully people are patched up.

  • @AllHailNannerpuss
    @AllHailNannerpuss Před 7 lety +205

    #18 on Trending. My nigga Dan made it

    • @poke548
      @poke548 Před 7 lety +8

      I know, I felt so proud when I saw it.

    • @CWINDOWSsystem32
      @CWINDOWSsystem32 Před 7 lety +1

      +Tornexted No, but Matt is...

  • @Jamesthe1
    @Jamesthe1 Před 7 lety +7

    I never knew it had a killswitch. Very good; this thing actually put cancer patients' lives in danger.

  • @omni9030
    @omni9030 Před 5 lety +56

    The memories of WannaCrypt for me are amazing! Being only a child at the time and seeing a red screen of death, I was terrified. We subsequently had a friend come over to fix this supposed virus, but I never touched that same computer again >:c

    • @Belchmaster41
      @Belchmaster41 Před 9 měsíci +2

      this is what happens when you don't have Norton's Smart Firewall engaged

  • @whoismatteo3737
    @whoismatteo3737 Před 6 lety +5

    I hate the way that ransomware makes me feel... it's so creepy, it gives me this sort of "dark, doomed" vibe

  • @burgerdiverbanandodansparc9154

    I actually wanna know that Mushroom Chicken recipe, if you're okay with that.

  • @InterstellarVulpine
    @InterstellarVulpine Před 7 lety +224

    Any virus that wants to get between me and my lego memes is going to get what's coming to it.

  • @Leurak
    @Leurak Před 7 lety +348

    yes

    • @PanPakaPanKancolleisgud
      @PanPakaPanKancolleisgud Před 7 lety +11

      Hey it's memz guy, when did you start watching Danooct?

    • @byRKZY
      @byRKZY Před 7 lety +7

      Jack He is he's number one fan. :p

    • @plushifoxed
      @plushifoxed Před 7 lety +22

      danooct literally did the first video out there on memz you dingdong

    • @ThatLinuxDude
      @ThatLinuxDude Před 7 lety +4

      Hey man

    • @michaelbaterna8386
      @michaelbaterna8386 Před 7 lety

      CONFURMED: teh memz guyy is the cRator off waanay cripty ransomwore

  • @SirajRaval
    @SirajRaval Před 7 lety +207

    bro 200K views in 2 days god status

  • @fr0sth4x0r
    @fr0sth4x0r Před 7 lety +1

    Great video, been following for about 3 years and this is hilarious

  • @ShiningLuma90
    @ShiningLuma90 Před 7 lety +190

    TempleOS doesn't have this problem

    • @kutsuro3901
      @kutsuro3901 Před 4 lety +1

      too soon?

    • @badcop9604
      @badcop9604 Před 4 lety +4

      MS-DOS doesn't have this problem

    • @ggffd3704
      @ggffd3704 Před 4 lety +1

      templeos has the problem of being able to rewrite mbr in a line

    • @SandboxerSandy
      @SandboxerSandy Před 4 lety +4

      @@potato_x69 bruh why the fuck do you hate weebs

    • @quizzys7106
      @quizzys7106 Před 4 lety

      @@potato_x69 lmao

  • @jimbob20051
    @jimbob20051 Před 7 lety +8

    *opens Rich Text Document and reads* "it's rich af"
    that has killed me XD

  • @vzangel
    @vzangel Před 7 lety +14

    What happens with the already encrypted files if it's executed again? Does it encrypt them again or leaves them alone based on the file extension? If the latter happens, very important files could be protected by changing the file extension in anticipation.

  • @klaasbousma7013
    @klaasbousma7013 Před 7 lety

    the news here in the Netherlands are just talking about this virus every time, and i was waiting for this video. now it's here. i love your content. it's really impressive and interesting to watch. keep it up

  • @ItsKardamin
    @ItsKardamin Před 7 lety

    Congrats on getting on the top video list! Thank you for showing this one

  • @GRBtutorials
    @GRBtutorials Před 5 lety +14

    "We will decrypt your file because nobody will trust us if we cheat users" That has to be the lamest reason I've ever heard! Nobody trusts them!

  • @sewertendo
    @sewertendo Před 7 lety +40

    Just a tidbit on why XP was patched. It's because of companies that still use XP tend despite the vulnerabilities. They usually set up individual contracts with Microsoft for this type of thing so that they can have some kind of extended support, although usually they have some kind of endpoint based security that filters most of the uninvited stuff. Part of it is to cut costs, or because certain applications simply won't work with newer OSes (so it's not just the OS you would be changing). There have obviously been ransomware in the past, but normally the network layers of security would be sufficient for it. This is why XP got patched despite the lack of support.
    Unless you're one of these organizations, don't freakin' use XP.

    • @MaximilienNoal
      @MaximilienNoal Před 7 lety +5

      Biggerboot I use XP from time to time on a dedicated retro computer. I even use Windows 98SE. It's the bomb for 3dfx games. And of course both have network shares 'cause it's convenient. The key here is that there is nothing important on it and it's offline most of the time, with Wake On Lan disabled. :p

    • @sewertendo
      @sewertendo Před 7 lety +5

      Absolutely. If you're using it in those capacities then you obviously know what you're doing. I'm just a little worried when I see comments like "DOZ THIS MEEN XPEE IZ SPPRTD AGIN?" I mean I guess it's youtube comments and it could be sarcastic, but ultimately misinforming. :P

  • @zerozerito14
    @zerozerito14 Před 7 lety +1

    Was waiting for this video, thanks :D !!!

  • @RonLaws
    @RonLaws Před 5 lety +1

    what a fun year this was at work. Having Non-windows based NAS Servers with volume level snapshots was a saving grace :D

  • @chm_mmx
    @chm_mmx Před 7 lety +17

    This malware uses two critical flaws. One is MS13-010 that has been patched for every Windows since XP/2003 (because someone still has Vista for some reason). The second is the fact companies take ages to release updates on their computers. My school, for example, has hundreds of Win7 Pro computers. They all haven't been updated since November 2016 (and today I'll go look if they have MS13-010)

  • @xylan9543
    @xylan9543 Před 7 lety +83

    That moment when you hack your own computer cause you want to erase your trash memes

    • @NOVA-en4ci
      @NOVA-en4ci Před 6 lety +5

      The trash memes were still funnier than most new popular memes nowadays though. *cough cough ugandan knuckles cough cough*

  • @omgtsn
    @omgtsn Před 7 lety

    i wonder if you set the time to a week ahead if it would actually delete the files

  • @firebucket8203
    @firebucket8203 Před 7 lety +1

    Congrats on making it on trending Dan !!!

  • @bugfriendz
    @bugfriendz Před 6 měsíci +3

    i got infected with wannacrypt when i was younger, kind of terrifying!

  • @mienafoxa1885
    @mienafoxa1885 Před 7 lety +40

    so Windows 10 can get this Virus?.....
    Woah, technology

    • @Mykoo
      @Mykoo Před 7 lety +4

      Miley Fox Im pretty sure you can get in any version of Windows if youre opening a .exe file, however, but dont quote me on this, if you have Windows 10 with your firewall enabled and anti-virus running + all the recent updates from Microsoft, you can't get infected through the network.

    • @OMspot2277
      @OMspot2277 Před 7 lety

      only if you didn't update windows 10 with that March update. But if you did then you were safe

    • @dirtkiller23
      @dirtkiller23 Před 7 lety +5

      Auto Windows Updates.This is the only case where it helps.

  • @sharath9893
    @sharath9893 Před 7 lety

    finally!
    i was eagerly waiting for this!

  • @XJLuxury
    @XJLuxury Před 7 lety

    yes ive been waiting for this video! ive checked your profile every day since this came out

  • @DMack6464
    @DMack6464 Před 7 lety +5

    When I saw the headlines, I instantly thought "danoct1"

  • @vepokk7554
    @vepokk7554 Před 7 lety +6

    you know shit gets real when an update for windows xp is released

  • @Dnk-fs8ks
    @Dnk-fs8ks Před 7 lety

    I was looking for this video. Thanks Dan

  • @piloticle2445
    @piloticle2445 Před 7 lety +1

    DANOOCT IS ON TRENDING. never thought i'd see the day my dudes

  • @Fnmods
    @Fnmods Před 2 lety +7

    Old days

  • @PimpMatt0
    @PimpMatt0 Před 7 lety +56

    Feels like the 90s again with these viruses.

  • @thetrashman5381
    @thetrashman5381 Před 7 lety +2

    You know a ransom ware is bad when Dan's video is trending

  • @GreatJobStudio
    @GreatJobStudio Před 7 lety

    You're on trending, my guy! Gratz.

  • @codex4336
    @codex4336 Před 7 lety +3

    Does disabling the SMB feature in Windows keeps you safe from this computer worm?

  • @Pokycraftgamer9
    @Pokycraftgamer9 Před 7 lety +13

    you know when something is serious if Microsoft updated Windows XP

  • @kieran7378
    @kieran7378 Před 7 lety +1

    I've been waiting for this.

  • @okdev5420
    @okdev5420 Před 7 lety

    holy shit #20 on Trending GOOD JOB danooct!

  • @ninelivesbobcat3619
    @ninelivesbobcat3619 Před 7 lety +269

    *hears that Microsoft patched Windows XP*
    Does this mean Windows XP is back? YAAAA--
    *realises that's it only to prevent the ransomware and that Windows XP will never be supported ever again*
    Ohhhhh. ;_;

    • @boofcario
      @boofcario Před 7 lety +62

      Solution: Keep making ransomware that exploits XP. Support forever :D

    • @archived527
      @archived527 Před 7 lety +6

      Who knows, there is a possibility that one of the patches could be ported to XP again if another serious attack like this happens. There was another post EOL patch in May 2014.

    • @computethis7128
      @computethis7128 Před 7 lety +9

      NinelivesBobcat I ran windows XP pro in a virtual machine yesterday, and was soo shocked to find people actually playing the internet Microsoft games so frequently finding someone instantly. why was I shocked? so many people still use XP. even though the internet browser was buggered and wouldn't open any https links and not load others.

    • @anasarkawi4331
      @anasarkawi4331 Před 7 lety +3

      windows xp is the king os oses!

    • @TexelGuy
      @TexelGuy Před 7 lety +8

      Dang crybabies, suck it up and update. You're missing out on basically everything.

  • @Ranged66
    @Ranged66 Před 7 lety +8

    There's this interesting tool called Ransomfree, cold you consider testing it at some point with this malware to see if it works? It basically places bait files all around your computer and when it detects a ransomware messing with it it will try and stop it.

  • @xander2698
    @xander2698 Před 7 lety

    I've been waiting for this video

  • @yannisvill6806
    @yannisvill6806 Před 7 lety +1

    Danooct1 is back!!! So many memories :')

  • @lordofwolve
    @lordofwolve Před 7 lety +5

    Good job NSA you provided me with the stuff to make people's lives worse. Thanks again

  • @connorhare9359
    @connorhare9359 Před 7 lety +6

    when u want kids but she not ready
    O O O P S

  • @Wignut
    @Wignut Před 7 lety

    Was waiting for this one.

  • @saeedo1998
    @saeedo1998 Před 7 lety

    Woo i was waiting for this

  • @realcomputerdude100
    @realcomputerdude100 Před 7 lety +5

    greetz from @danooct1 ya boi wit da malware yoooooooooooooooooooooooooooooooooooooooooooooooooooooooo

  • @Rctive
    @Rctive Před 7 lety +5

    for about 2 seconds when you were typing that message
    you sounded like joel

  • @FIXTREME
    @FIXTREME Před 4 lety +1

    That Atari-esque Hava Naguila is nectar to my ears!🐱

  • @Kamal_AL-Hinai
    @Kamal_AL-Hinai Před 7 lety

    hey bro, i love your work so much

  • @yourbuddymuddy
    @yourbuddymuddy Před 7 lety +57

    holy shit this is the earliest ive ever been to a video ever

    • @ki9980
      @ki9980 Před 7 lety

      Muddy Bear ikr

    • @VreyIsGrey
      @VreyIsGrey Před 7 lety +10

      You're not late. You're on time.

  • @TheKingBJ
    @TheKingBJ Před 7 lety +10

    >shows a malware that asks for money to recover your files
    >outro plays a 8bit klezmer song
    oy vey

  • @stupidstuff9046
    @stupidstuff9046 Před 7 lety

    as soon as I saw this in the news I knew I'd see a danooct video

  • @Xyaena
    @Xyaena Před 7 lety

    I managed to share this video to some of my friends.

  • @stevegamer68
    @stevegamer68 Před 4 lety +4

    Imagine if the scammers accidentally encrypted their computers

    • @ChanceOfOne344254
      @ChanceOfOne344254 Před rokem +2

      This has actually happened allegedly, but not with this ransomware
      Allegedly, the author of Rensenware, had to complete his own task (score 2 billion points on lunatic mode in TouHou) in order to decrypt his own files due to forgetting to run the program in a virtual machine.

    • @RMED24
      @RMED24 Před 11 měsíci +2

      ​@@ChanceOfOne344254that's partially false actually. What really happened is that he did encrypt his files, so he used cheat engine to force the score required to unlock the files. He then developed a tool which did all this automatically for those who were affected by rensenware

  • @DiamondTurtleGamer
    @DiamondTurtleGamer Před 7 lety +5

    I just realized how you don't kill your computer every time you do these videos..
    virtual machine.

  • @Ununoctium-
    @Ununoctium- Před 7 lety

    I was waiting for this

  • @joshuaromero6620
    @joshuaromero6620 Před 7 lety

    I was looking forward to this video

  • @hippiemcfake6364
    @hippiemcfake6364 Před 7 lety +3

    Awwww i wished you'd demonstrate the 'decrypt' button. It says that you can decrypt some files for free.

  • @HiyaItsHailey
    @HiyaItsHailey Před 7 lety +27

    You should've pulled a rogueamp and just posted a video of you driving in your 129° car.

    • @RavenousRabbler
      @RavenousRabbler Před 7 lety +4

      "What up guys, RogueAmp here, today I heard that the worst malware attack since Conficker has finally happened. Because ransomware is totally not my specialty, I'm just gonna drive in my car and blast some E U R O B E A T"

  • @plasmididdlydoo7465
    @plasmididdlydoo7465 Před 7 lety

    This thing sends a chill down my spine..

  • @PashaCracken
    @PashaCracken Před 7 lety +1

    Hey @danooct1
    I am, interested in getting into malware analysis. How do you have your lab setup and how do you get samples to play with like this?

  • @iyok050106
    @iyok050106 Před 7 lety +11

    my school alerted about this worm spreading and told everyone to not turn on their computer today and tomorrow, but screw it, I'm using a Mac! :p

  • @cisjik
    @cisjik Před 7 lety +3

    Finally, MS who abandon Windows XP upload the second update for Windows XPIt's seem Bill know a lot of people use Windows XP

  • @decoy3418
    @decoy3418 Před 7 lety

    was waiting for this.

  • @00GMS00
    @00GMS00 Před 7 lety

    gracias por la demostración de este ransomware

  • @Dragnerve.
    @Dragnerve. Před 7 lety +3

    the key is WNcry@2o17

  • @quatex.854
    @quatex.854 Před 6 lety +6

    lol i got "BEST FREE ANTIVIRUS" ad more like BEST TROYAN VIRUS amiright?

  • @twitchytails
    @twitchytails Před 7 lety

    Yo dan got to the front page! Congrats dude!

  • @BrVendan
    @BrVendan Před 7 lety

    Whoa! You're 22 on trending! Congrats!

  • @anentityshroudedinmystery.8037

    mushroom_chicken.docx
    Why did I type this comment

  • @captainmexico5483
    @captainmexico5483 Před 7 lety +83

    I didnt watch all the video yet but the unlock code to the virus is " WNcry@2ol7 " thumbs up to let everyone know

    • @DMack6464
      @DMack6464 Před 7 lety +1

      How did you find it?

    • @raymond2136
      @raymond2136 Před 6 lety

      fr? well shit lol

    • @the_lava_wielder6996
      @the_lava_wielder6996 Před 5 lety +16

      I'm pretty sure it's randomized for each user

    • @MatrixJ21
      @MatrixJ21 Před 5 lety +9

      It is. The key is sent from the program to an external server on execution of the payload, then removed from storage (and/or memory) on the target computer.

    • @nyanezt9636
      @nyanezt9636 Před 5 lety

      "WannaCryAt2017"... huh

  • @flamingolegs
    @flamingolegs Před 7 lety

    This has been EVERYWHERE in Italy recently.
    My dad works as a computer technic (??) at an university and he tried it out on a VM.
    I'm gonna ask him if it's this one. Thanks for the video!

  • @cargopros8246
    @cargopros8246 Před 6 lety +2

    Yes I wanna crypt, thank you for asking.

  • @aurathedraak7909
    @aurathedraak7909 Před 7 lety +6

    we knew this would happen xD

  • @tomferrari517
    @tomferrari517 Před 7 lety +4

    "it's rich af" xD

  • @safe-keeper1042
    @safe-keeper1042 Před 6 lety +1

    Thank you for this reminder to backup my files ;P

  • @dancoster7332
    @dancoster7332 Před 7 lety +1

    Just curious, where did you download the executable file, I can't find this anywhere.

  • @nikolatesla6992
    @nikolatesla6992 Před 7 lety +3

    2.0 is going to be released shortly with no kill switch (Verified) The internet will be gone before the end of the year. Nokia bricks will be back in style as soon as data goes bye bye. Welcome to 1984, get comfy.

  • @panzermann1181
    @panzermann1181 Před 6 lety +3

    Viruses back then: I'm a flying plane, catch me if you can!
    Viruses now: I encrypted ur filez lollololololol, if you want ur crap back gimme your moolah!

  • @foofin25
    @foofin25 Před 7 lety

    Hell yea, danooct got trending.

  • @springer1985
    @springer1985 Před 2 lety +1

    Someone I knew lost very important information worth a lot of money. They had this same virus, paid the $300 in bitcoin and got everything back and the scammers were actually very friendly to work with which was odd.