---
title: "WannaCry / WannaCrypt ( ransomware ) : Le jour d’après …"
url: https://www.cyber-neurones.org/2017/05/wannacry-wannacrypt-ransomware-le-jour-dapres/
date: 2017-05-14
modified: 2017-05-15
author: "Frederic"
description: "Les dernières informations suite à mon précédent post : https://www.cyber-neurones.org/2017/05/wannacry-nouvelle-grosse-faille-de-securite-sous-windows/ . Le mot de passe du fichier ZIP serait WNcry@2ol7 (à vérifier). Kaspersky le détecte comme un rootkit :MEM:Trojan.Win64.EquationDrug.gen Il y a..."
categories:
  - "Windows"
tags:
  - "Linux"
  - "Wannacry"
  - "Windows"
word_count: 248
---

# WannaCry / WannaCrypt ( ransomware ) : Le jour d’après …

Les dernières informations suite à mon précédent post : [https://www.cyber-neurones.org/2017/05/wannacry-nouvelle-grosse-faille-de-securite-sous-windows/](https://www.cyber-neurones.org/2017/05/wannacry-nouvelle-grosse-faille-de-securite-sous-windows/) .

- Le mot de passe du fichier ZIP serait WNcry@2ol7 (à vérifier).
- Kaspersky le détecte comme un rootkit :MEM:Trojan.Win64.EquationDrug.gen
- Il y a eu plus de 100 paiements de raçons pour environ 26K $.
- Mieux comprendre le schéma d'infection :

[![](https://www.cyber-neurones.org/wp-content/uploads/2017/05/c_xxt-vxoaebwh7.jpg)](https://www.cyber-neurones.org/2017/05/wannacry-wannacrypt-ransomware-le-jour-dapres/c_xxt-vxoaebwh7/)

[![](https://www.cyber-neurones.org/wp-content/uploads/2017/05/c_2votlw0aahb2r.jpg)](https://www.cyber-neurones.org/2017/05/wannacry-wannacrypt-ransomware-le-jour-dapres/c_2votlw0aahb2r/)

- Un outil pour empêcher l'exécution de WannaCry : [https://www.ccn-cert.cni.es/en/updated-security/ccn-cert-statements/4485-nomorecry-tool-ccn-cert-s-tool-to-prevent-the-execution-of-the-ransomware-wannacry.html](https://www.ccn-cert.cni.es/en/updated-security/ccn-cert-statements/4485-nomorecry-tool-ccn-cert-s-tool-to-prevent-the-execution-of-the-ransomware-wannacry.html) .
- Documentation du CERT-FR : [http://cert.ssi.gouv.fr/site/CERTFR-2017-ALE-010/index.html ](http://cert.ssi.gouv.fr/site/CERTFR-2017-ALE-010/index.html)
- Désactivation SMB Manuelle :

[![](https://www.cyber-neurones.org/wp-content/uploads/2017/05/c_yqrqtxyaamwud.jpg)](https://www.cyber-neurones.org/2017/05/wannacry-wannacrypt-ransomware-le-jour-dapres/c_yqrqtxyaamwud/)

- Les hashtags sur Twitters : #WannaCry #WannaCrypt #CyberAttaque #Ransomware #WannaCryp0r #WannaCryAttack

Maintenant il va falloir attendre lundi matin pour voir l'ampleur exacte des dégâts : [https://intel.malwaretech.com/botnet/wcrypt/?t=1h&bid=all ](https://intel.malwaretech.com/botnet/wcrypt/?t=1h&bid=all) [![](https://www.cyber-neurones.org/wp-content/uploads/2017/05/capture-decran-2017-05-14-a-09-03-06.png)](https://www.cyber-neurones.org/2017/05/wannacry-wannacrypt-ransomware-le-jour-dapres/capture-decran-2017-05-14-a-09-03-06/) [![](https://www.cyber-neurones.org/wp-content/uploads/2017/05/capture-decran-2017-05-14-a-09-02-55.png)](https://www.cyber-neurones.org/2017/05/wannacry-wannacrypt-ransomware-le-jour-dapres/capture-decran-2017-05-14-a-09-02-55/)   En résumé en France, d'un coté on à le FSB qui nous fait des fake news "Macron Leaks":
> La piste russe des «Macron Leaks» mène à un sous-traitant du FSB. [https://t.co/2sVVRVMSbT](https://t.co/2sVVRVMSbT)
>
>
>
> — Fabrice Arfi (@fabricearfi) [13 mai 2017](https://twitter.com/fabricearfi/status/863425188385488896)
Et de l'autre la NSA qui connait des failles et les gardes secrètes :
> When [@NSAGov](https://twitter.com/NSAGov)-enabled ransomware eats the internet, help comes from researchers, not spy agencies. Amazing story. [https://t.co/tNwXwJEy07](https://t.co/tNwXwJEy07)
>
>
>
> — Edward Snowden (@Snowden) [13 mai 2017](https://twitter.com/Snowden/status/863422022994481152)
On vit au pays de la sécurité informatique... ou des pigeons.
> [@EmmanuelMacron](https://twitter.com/EmmanuelMacron) [#wannacry](https://twitter.com/hashtag/wannacry?src=hash) relance le débat de mettre nos administrations sous Linux ! cc [@axellelemaire](https://twitter.com/axellelemaire) [@mounir](https://twitter.com/mounir) [@cashinvestigati](https://twitter.com/cashinvestigati)
>
>
>
> — CYBER NEURONES (@CYBERNEURONES) [13 mai 2017](https://twitter.com/CYBERNEURONES/status/863344585271103488)
[![](https://www.cyber-neurones.org/wp-content/uploads/2017/05/c_wz9h6wsaa2m4o-300x225.jpg)](https://www.cyber-neurones.org/2017/05/wannacry-wannacrypt-ransomware-le-jour-dapres/c_wz9h6wsaa2m4o/) Quelques articles :

- [http://www.getgnulinux.org/fr/windows/](http://www.getgnulinux.org/fr/windows/) :
-
> Et – surprise ! – les virus et logiciels espions n'ont pas d'effet sur les logiciels au code source ouvert. On n'y achète pas la "sécurité" en supplément. L'industrie du logiciel antivirus, dans laquelle on compte aujourd'hui Microsoft, préfère que vous utilisiez Windows.

-

Misère.