blog.hamels.be

  • Blog

blog.hamels.be

  • Blog
General, Security,

Decryption tool for WannaCry

by PieterMay 19, 2017no comment
0
Shares
Share on FacebookShare on Twitter
wannacry-screencap_thumb800

A French security researcher from Quarkslab, Adrien Guinet, discovered a way to retrieve the secret encryption keys used by WannyCry ransomware without having to pay.

The WannaCry encryption works by generating a pair of keys on the infected computer that rely on prime numbers. a public and private key for encrypting and decrypting the files on the infected machine.

Now here’s the fun part! WannaCry doesn’t erase the prime numbers used for the generation of the encryption keys before freeing the associated memory.

Based on this, Guinet releqse a WannaCry ransomware decryption, named WannaKey which basically tries to retrieve the two prime numbers used to generate the encryption keys from the memory.

The limitation of this method is though, that:

  1. The affected computer should not have been rebooted after being infected
  2. The associated memory should not have been allocated and erased by some other process.

The tool however, only pulls the prime numbers from the memory of the infected computer, so you can use those numbers to generate the decryption key manually to decrypt your WannaCry encrypted files.

Although, another security researcher named Benjamin Delpy, created a an easy to use tool called WanaKiwi, which is based on Guinet’s findings, to simplify the entire process of decrypting the WannaCry encrypted files.

The tool works on Windows XP, Windows Vista, Windows 7, Windows Server 2003 and 2008.

 

WannaKey:
https://github.com/aguinet/wannakey

WanaKiwi:
https://github.com/gentilkiwi/wanakiwi

CryDecryptDecryptionEncryptionFreeRansomRansomwareSecurityToolWanaKiwiWannaWannaCryWannaKeyWareWindows
Previous

Android App: Road Trip Tracker

May 10, 2017
Next

KRACK Vulnerability makes WiFi insecure

October 17, 2017

Related posts

covid19
General,

Covid-19 / Coronavirus statistics scraper

by PieterMarch 21, 2020no comment
logo-small
General, Security,

KRACK Vulnerability makes WiFi insecure

by PieterOctober 17, 2017no comment
trackerearth
Android, General,

Android App: Road Trip Tracker

by PieterMay 10, 2017no comment
20170501172259_1
FSX, Games, General,

Dolna Banya airport for FSX / Prepar3D

by PieterMay 2, 2017no comment

© 2020 webXtend.be. All rights reserved.