I was reading an article today about a Google researcher linking the WannaCry malware to the earlier malware Cantopee.
I had two primary questions based on the contents of the article.
I was reading an article today about a Google researcher linking the WannaCry malware to the earlier malware Cantopee.
I had two primary questions based on the contents of the article.
Check out reverseengineering.SE for all your RE questions.
The name of the tool being used is Hiew.
From WannaCry — Links to Lazarus Group:
Some code in WannaCry (9c7c7149387a1c79679a87dd1ba755bc) beginning at address 0x402560 is the same as some code in Contopee (ac21c8ad899727137c4b94458d7aa8d8) beginning at address 0x10004ba0. Same story for the next pair of addresses. In essence, both pieces of software share code.
This is what is depicted in picture 2 in the question, it is just a little hard to see. A bigger picture can be found in Dan Goodin's article Virulent WCry ransomware worm may have North Korea’s fingerprints on it (click to enlarge):