{"id":5990,"date":"2018-06-21T23:14:21","date_gmt":"2018-06-21T21:14:21","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=5990"},"modified":"2019-03-24T06:58:31","modified_gmt":"2019-03-24T05:58:31","slug":"wannacry-is-back-no-its-scam-a-mail","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2018\/06\/21\/wannacry-is-back-no-its-scam-a-mail\/","title":{"rendered":"WannaCry is back? No, it&rsquo;s a scam mail"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" height=\"47\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2018\/06\/21\/wannacry-wiederkehr-von-wegen-betrugs-mail\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]During the last hours I stumbled twice over the keyword WannaCry. What looks like a return of this pest may turn out to be a scam or fraud email campaign. I thought I'd post it here for admins' information.<\/p>\n<p><!--more--><\/p>\n<h2>Two hits on WannaCry<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vg01.met.vgwort.de\/na\/aed2ed0679904ad2af070c67f1b6bd5d\" alt=\"\" width=\"1\" height=\"1\" \/>The first impact came during browsing through postings on a German administrator forum, when I came across the article <a href=\"https:\/\/www.administrator.de\/content\/detail.php?id=377606\" target=\"_blank\" rel=\"noopener noreferrer\">Wannacry \u2013 Malwarebytes<\/a>. The question 'could it be the start of a new WannaCry' sprang into my head. But due to the nature of the forum posting I did not investigate further (the posting asked questions, that no admin will ask after a real WannaCry infection, hitting network computers.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"de\">\n<p dir=\"ltr\" lang=\"en\">Scriptkiddies sending out emails pretending to be WannaCry telling people if they don't pay their files will be deleted <a href=\"https:\/\/t.co\/FkLETQqdml\">https:\/\/t.co\/FkLETQqdml<\/a><\/p>\n<p>\u2014 MalwareTech (@MalwareTechBlog) 21. Juni 2018<\/p><\/blockquote>\n<p><span id=\"preserved0fd3f34e7604bc1afb107b178d614aa\" class=\"wlWriterPreserve\"><script src=\"https:\/\/platform.twitter.com\/widgets.js\" async=\"\" charset=\"utf-8\"><\/script><\/span><\/p>\n<p>Then I saw the above Tweet, which immediately triggered an 'Ok, an explanation' reaction.<\/p>\n<h2>Scammer plays WannaCry<\/h2>\n<p>The background to the MalwareTech Tweet is described by The Register in the article <a href=\"https:\/\/www.theregister.co.uk\/2018\/06\/21\/wannacry_is_back_except_its_not\/\" target=\"_blank\" rel=\"noopener noreferrer\">WannaCry is back! (Psych. It's just phisher folk doing what they do)<\/a>. Thursday, 21.06.2018 was not only Midsummer. But there was an unusually large wave of phishing emails (at least in Brittain). Action Fraud UK reported over 200 reports of this 'WannaCry attack' until The Register article was created.<\/p>\n<p>IT support companies &#8211; apparently mainly based in the UK &#8211; have been bombarded with requests from insecure users. The supporters asked the customers to delete the mails and continue working. Black sheep among the supporters took the opportunity to install additional security software for the customer \u2026<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"de\">\n<p dir=\"ltr\" lang=\"en\">We are receiving reports this morning of a <a href=\"https:\/\/twitter.com\/hashtag\/wannacry?src=hash&amp;ref_src=twsrc%5Etfw\">#wannacry<\/a> threat email being widely received.<\/p>\n<p>It is designed to cause panic resulting in payment of their empty threat.<\/p>\n<p>If you have concerns speak with your IT company.<\/p>\n<p>Finally &#8211; use this as an opportunity to review your backups! <a href=\"https:\/\/t.co\/GQSOCmwdk1\">pic.twitter.com\/GQSOCmwdk1<\/a><\/p>\n<p>\u2014 Pro-Networks (@pronetworksuk) <a href=\"https:\/\/twitter.com\/pronetworksuk\/status\/1009730084293500928?ref_src=twsrc%5Etfw\">21. Juni 2018<\/a><\/p><\/blockquote>\n<p><span id=\"preserve737658f70905464c8240b08ba6f1771c\" class=\"wlWriterPreserve\"><script src=\"https:\/\/platform.twitter.com\/widgets.js\" async=\"\" charset=\"utf-8\"><\/script><\/span><\/p>\n<p>Affected users received the e-mail shown in <a href=\"https:\/\/twitter.com\/pronetworksuk\/status\/1009730084293500928\" target=\"_blank\" rel=\"noopener noreferrer\">the tweet<\/a> above. Within the mail, the senders claim that WannaCry is back and that all files on the victim's computer will be encrypted. This can only be avoided by paying 0.1 bitcoins (approx. 650 US dollars). The aim of the message, with a payment deadline of June 22, 2018, is to create panic and collect the money. So if something like this comes to your attention: Just delete the mail and continue with your daily work.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]During the last hours I stumbled twice over the keyword WannaCry. What looks like a return of this pest may turn out to be a scam or fraud email campaign. I thought I'd post it here for admins' information.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69,832],"class_list":["post-5990","post","type-post","status-publish","format-standard","hentry","category-security","tag-security","tag-wannacry"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/5990","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=5990"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/5990\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=5990"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=5990"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=5990"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}