I was reading an article today about a Google researcher linking the WannaCry malware to the earlier malware Cantopee.
I had two primary questions based on the contents of the article.
I was reading an article today about a Google researcher linking the WannaCry malware to the earlier malware Cantopee.
I had two primary questions based on the contents of the article.
Check out reverseengineering.SE for all your RE questions.
The name of the tool being used is Hiew.
From WannaCry — Links to Lazarus Group:
Some code in WannaCry (9c7c7149387a1c79679a87dd1ba755bc
) beginning at address 0x402560
is the same as some code in Contopee (ac21c8ad899727137c4b94458d7aa8d8
) beginning at address 0x10004ba0
. Same story for the next pair of addresses. In essence, both pieces of software share code.
This is what is depicted in picture 2 in the question, it is just a little hard to see. A bigger picture can be found in Dan Goodin's article Virulent WCry ransomware worm may have North Korea’s fingerprints on it (click to enlarge):