A domain name was the off-switch for WannaCry
The WannaCry virus asked one hardcoded domain name for permission before it encrypted anything. Nobody had bought that domain yet. It was about ten dollars, and the sinkhole behind it is still live.
Friday, 12 May 2017.
In England, hospitals have to send patients home. Renault and Telefónica’s systems are down too.
Meanwhile, a 22-year-old British computer scientist runs a copy of the WannaCry worm on his own computer at home. While watching the network traffic, he realizes that the virus is trying to communicate towards a domain name that is unregistered.
He buys the domain, which costs about $10. Then he points it to his own sinkhole server, a server built to swallow malicious traffic and log the requests.
Then, by afternoon, all newly infected machines globally are stopping the encryption.
When you register a domain name, you effectively control how every piece of software that looks it up behaves, all at the same time wherever the request is coming from.
The WannaCry virus was checking one single thing. Is that specific domain name resolvable? If it got a reply, it stopped. If there was no reply, the encryption started. Since this domain name was deeply burned into the code and no one registered it before, all the infected machines in the world were waiting for guidance from this single domain registration.
Marcus Hutchins, who at the time was working for Kryptos Logic, knew nothing about this when he paid for the registration. He made a habit out of buying up those free domain names that malicious viruses relied on, and according to his own reporting, to monitor botnets and to estimate the number of their victims. But this time, the domain name was the kill switch.
As he explained the following day, the creators didn’t intend the lookup as a kill switch. When cyber security specialists are testing malicious software within their sandboxes, they set up the environment in a way that every DNS query is being answered, even for the domains that are unregistered. So when malicious software looks up a nonsensical domain name and receives a reply, it concludes that it is being watched, therefore it stops. This same trick was built in here too, around a fixed domain name, that the code looked up at every run.
The attackers were relying on an unregistered domain for their malicious code to start.
This particular domain name has had to be kept alive ever since, and it’s been alive for nine years now.
Throughout the first days, this sinkhole had to resist a complete Mirai botnet distributed attack that tried to put it down. In the meantime, the authorities seized the two servers behind it, wrongly assuming that it was distributing the WannaCry virus. Four days later, Cloudflare took over its hosting. The domain is still kept alive as of today by Kryptos Logic.
It is still up and running as I am typing in these words, right now: Sinkholed by Kryptos Logic.
In 2019, Cloudflare reported that every year they get take-down requests from those who mistakenly think it is distributing malicious software instead of realizing that this is the cure for it.
However, all the machines globally on the internet that are unpatched against this virus are waiting silently to become active when the domain name goes silent. It would be enough for the domain to simply not be renewed anymore. It would be just as fatal if a transfer or trade request came up, or if the registry suspended the domain, or if anyone throughout the chain of registration allowed a takedown request.
If we zoom out here, we can see that our own systems are prone to the same problem, in silent modes: update servers, license checks, telemetry endpoints or those CDNs from where the payment scripts are loaded into our websites. Behind all those systems there is a domain name, and our software behaves the way we expect it to, only as long as someone makes sure that the domain name stays registered.
Hard to say whether it’s rather comforting or rather absurd that the online world’s protection against a second wave of WannaCry stands on the renewal of a domain name.
Those who keep our domain names registered have their fingers on switches that are not present in any architecture diagrams of our systems.
Magyar változat: [zona.hu/a-wannacry-zsarolovirus-leallitogombja-egy-meg-nem-regisztralt-domain-volt/]



