{"id":49746,"date":"2017-06-28T12:55:20","date_gmt":"2017-06-28T07:25:20","guid":{"rendered":"https:\/\/www.vskills.in\/certification\/blog\/?p=49746"},"modified":"2024-04-03T13:24:31","modified_gmt":"2024-04-03T07:54:31","slug":"wannacry-ransomware-analysis","status":"publish","type":"post","link":"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/","title":{"rendered":"WannaCry Ransomware Analysis"},"content":{"rendered":"<h3>WannaCry Ransomware Analysis<\/h3>\n<p>WannaCry ransomware has been the most widespread ransomware. A ransomware is a type of malicious software designed to block access to a computer system until a sum of money is paid.<\/p>\n<p>It is worth noting that the first WannaCry infection was reported on February 10th then again on the 25th. We will refer to this as \u201cversion 1.\u201d This did not have a widespread impact.<\/p>\n<p>On the afternoon of Friday, May 12th 2017, what we will refer to as \u201cversion 2\u201d of WannaCry started to infect systems around the world. WannaCry quickly spread to affect organizations such as the UK\u2019s NHS. An example of the ransom demand can be seen below:<a ref=\"magnificPopup\" href=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-01.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-49750\" src=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-01.png\" alt=\"\" width=\"470\" height=\"354\" srcset=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-01.png 470w, https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-01-300x226.png 300w\" sizes=\"auto, (max-width: 470px) 100vw, 470px\" \/><\/a><\/p>\n<p style=\"text-align: center\">Figure 1: Example of WannaCry Ransomware Demand<\/p>\n<p>By around 4:00 PM on Friday, there were reportedly around 36,000 detections, which were spreading globally. There had been some conjecture on social media that a PDF was the cause of the infection, but this was found to be benign. Currently, there is speculation that the initial vector of the attack was through a phishing email. While this is a likely cause, this has not yet been confirmed, and it may take some time before the root of the infection comes to light.<\/p>\n<p>After numerous malware analysts around the world started to dissect WannaCry, it quickly came to light that WannaCry makes use of \u201cEternalBlue\u201d, the exploit, and \u201cDoublePulsar,\u201d the backdoor\/implant. The relevance of this finding is key, because back on the April 14th, a hacking group called \u201cShadow Brokers\u201d leaked a series of files that they claimed were stolen from the NSA.<\/p>\n<p>EternalBlue essentially is the exploit found in WannaCry that takes advantage of exploiting a core Windows networking protocol called Server Message Block (SMB). As SMB is so intertwined with numerous versions of Windows, this exploit can affect Windows XP up through Windows Server 2016.<\/p>\n<p>For reference, this vulnerability was addressed in Common Vulnerabilities and Exposures (CVE) ids CVE-2017-143 through 148. Microsoft did, in fact, release a patch for this vulnerability on March 14th (in Security Bulletin MS17-010); however, companies that did not apply this patch have been vulnerable ever since. Despite Windows XP being already past end\u2013of-life, Microsoft issued an emergency patch to address this vulnerability on Friday night. This was done as a good-will deed in order to help customers who are still running Windows XP to avoid the spread of WannaCry.<\/p>\n<p>By Friday night, the National Crime Agency, Interpol, and numerous other organizations around the world had issued statements to notify and warn businesses in their corresponding countries of the wide-scale attack. Below is a map of infections that had occurred between Saturday (May 13th) and Sunday (May 14th). By that time, around 60,000 computers in 74 countries were infected. Companies in many industries were affected including: global shipping, auto manufacturers, health care, and educational institutions.<\/p>\n<p><a ref=\"magnificPopup\" href=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-02.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-49754\" src=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-02.jpg\" alt=\"\" width=\"604\" height=\"389\" srcset=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-02.jpg 604w, https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-02-300x193.jpg 300w\" sizes=\"auto, (max-width: 604px) 100vw, 604px\" \/><\/a><\/p>\n<pre>Figure 2: A Map of WannaCry Infections as of Sunday, May 14th (via @malrhunterteam)<\/pre>\n<p>By Saturday afternoon, Edward Snowden had commented on the drama underway. Snowden made a clear statement about NSA involvement in the attack: \u201cDespite warnings, @NSAGov built dangerous attack tools that could target Western software. Today we see the cost.\u201d<\/p>\n<p>By Sunday evening, the BBC had reported that there are now more than 200,000 computers infected in over 150 countries, according to Europol. Microsoft later blamed WannaCry on \u201cNSA Vulnerability Hoarding Program.\u201d<\/p>\n<p>As of Monday morning, BlockChain reports the following statistics showing how many transactions and the resulting BitCoin balance for each of the three BitCoin addresses supplied within the malicious file. This translates to approximately $51,290 in revenue for attackers.<\/p>\n<p><a ref=\"magnificPopup\" href=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-03.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-49755\" src=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-03.jpg\" alt=\"\" width=\"619\" height=\"358\" srcset=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-03.jpg 619w, https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-03-300x174.jpg 300w\" sizes=\"auto, (max-width: 619px) 100vw, 619px\" \/><\/a><\/p>\n<p>Figure 3. Bitcoin Payments for WannaCry Ransom (via https:\/\/blockchain.info)<\/p>\n<h4><strong>High-Level Technical Overview<\/strong><\/h4>\n<p>When the malicious file is run, a number of things happen. First, a call is made to a host. If the connection is successful, the program exits. (Refer to the \u201cKill Switch\u201d section further down for more.) A Windows service called the \u201cWindows Security Center Service\u201d is created, and shadow copies (which are a snapshot\/backup technology built into Windows) are then deleted.<\/p>\n<pre style=\"text-align: center\">The malicious file then extracts numerous other files, which include multi-lingual files containing the ransom note in 28 different languages, a background display image which gets set as the background\/wallpaper for the infected system (shown below), and several other files which play a part in the encryption, communication and decryption stages.<br \/><a ref=\"magnificPopup\" href=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-04.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-49756\" src=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-04.png\" alt=\"\" width=\"470\" height=\"352\" srcset=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-04.png 470w, https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/WannaCry-Ransomware-Analysis-04-300x225.png 300w\" sizes=\"auto, (max-width: 470px) 100vw, 470px\" \/><\/a>Figure 4. Background Image Used for Infected Systems<\/pre>\n<p>There are notably three unique Bitcoin addresses, which are used to collect the ransom funds. The communication is first setup using Tor, which is a known program that helps achieve anonymity online.<\/p>\n<p>Files are then modified and all users are given full access rights, and then encrypted. Each file name is appended with the extension WNCRY. For example, if you have a Word document saved as \u201cfinance.docx,\u201d this would then be renamed and encrypted to become \u201cfinance.docx.wncry.\u201d<\/p>\n<p>As WannaCry uses Microsoft Enhanced RSA and AES cryptography, what this essentially means is that only after the ransom is paid (which is between $300 and $600), the files will then become decrypted and readable once more. Despite reclaiming files, the integrity of the system by this time would be severely impacted\u2014the user or company would still be looking to restore from backup, until such time that a decryption tool is released.<\/p>\n<h4><strong>The Kill Switch<\/strong><\/h4>\n<p>A researcher known as \u201cMalwareTech\u201d on Twitter discovered that the domain name that WannaCry tries to first connect to was unregistered. After researching further, he decided to register the domain name. This had a fast-acting impact, because doing so essentially stopped WannaCry from running any subsequent steps. The only caveat of the kill switch is that infected systems that connect through a proxy server out to the Internet are, in fact, still vulnerable.<\/p>\n<h4><strong>Advice for Defending Against WannaCry<\/strong><\/h4>\n<p>Due to the widespread impact and scale of this attack, it is advised that anyone running Windows XP through to Server 2012, apply the MS17-010 emergency patch issued on Friday.<\/p>\n<p>For Windows environments that are still utilizing the SMB networking protocol, it is strongly advised that you consider whether it is viable to disable SMB version 1 at the earliest opportunity. Caution should be taken as there may be legacy applications in the environment that depend on SMBv1.<\/p>\n<p>In addition, it is recommended that any hosts that are externally accessible over SMB have inbound traffic for ports 139 and 445 blocked, even at the host firewall level.<\/p>\n<p style=\"text-align: right\">&#8211; LogRhythm<\/p>\n<p>\u00a0<\/p>\n<p class=\"VSKILLbodytext\">Students or Professionals engaged in cyber security, can use the below links to be updated on Security related issues<\/p>\n<p class=\"VSKILLbodytext\"><a href=\"http:\/\/vskills.in\/certification\/tutorial\/legal\/cyber-security-certification\/\">Tutorials for Cyber Security<\/a><\/p>\n<p class=\"VSKILLbodytext\"><a href=\"http:\/\/www.vskills.in\/practice\/quiz\/cyber-security\">Practice Test on Cuber Security to assess your knowledge<\/a><\/p>\n<p class=\"VSKILLbodytext\"><a href=\"https:\/\/www.vskills.in\/certification\/security\/cyber-security-certification\">Certification Course on Cyber Security<\/a><\/p>\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WannaCry Ransomware Analysis WannaCry ransomware has been the most widespread ransomware. A ransomware is a type of malicious software designed to block access to a computer system until a sum of money is paid. It is worth noting that the first WannaCry infection was reported on February 10th then again on the 25th. We will&#8230;<\/p>\n","protected":false},"author":1,"featured_media":51577,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_joinchat":[],"footnotes":""},"categories":[1556],"tags":[919,6800,6799,6798],"class_list":["post-49746","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-2","tag-cyber-security","tag-ransomware","tag-wannacry","tag-wannacry-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>WannaCry Ransomware<\/title>\n<meta name=\"description\" content=\"An technical analysis of WannaCry ransomware, which has affected computer networks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WannaCry Ransomware\" \/>\n<meta property=\"og:description\" content=\"An technical analysis of WannaCry ransomware, which has affected computer networks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/\" \/>\n<meta property=\"og:site_name\" content=\"Vskills Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/vskills.in\" \/>\n<meta property=\"article:published_time\" content=\"2017-06-28T07:25:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-03T07:54:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/15_WannaCry-Ransomware-Analysis.gif\" \/>\n\t<meta property=\"og:image:width\" content=\"750\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/gif\" \/>\n<meta name=\"author\" content=\"teamvskills\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"teamvskills\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/\",\"url\":\"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/\",\"name\":\"WannaCry Ransomware\",\"isPartOf\":{\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/15_WannaCry-Ransomware-Analysis.gif\",\"datePublished\":\"2017-06-28T07:25:20+00:00\",\"dateModified\":\"2024-04-03T07:54:31+00:00\",\"author\":{\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/#\/schema\/person\/db89ed45879ddc5d130a8aae4309d90a\"},\"description\":\"An technical analysis of WannaCry ransomware, which has affected computer networks.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/#primaryimage\",\"url\":\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/15_WannaCry-Ransomware-Analysis.gif\",\"contentUrl\":\"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/15_WannaCry-Ransomware-Analysis.gif\",\"width\":750,\"height\":400,\"caption\":\"WannaCry Ransomware Analysis\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.vskills.in\/certification\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WannaCry Ransomware Analysis\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/#website\",\"url\":\"https:\/\/www.vskills.in\/certification\/blog\/\",\"name\":\"Vskills Blog\",\"description\":\"Vskills - A Initiative in Assessment to Enhance Employability\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.vskills.in\/certification\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/#\/schema\/person\/db89ed45879ddc5d130a8aae4309d90a\",\"name\":\"teamvskills\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.vskills.in\/certification\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b622f2772f7029565ef961f615b0727ed219929be1c95fa7aeda53560feec085?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b622f2772f7029565ef961f615b0727ed219929be1c95fa7aeda53560feec085?s=96&d=mm&r=g\",\"caption\":\"teamvskills\"},\"url\":\"https:\/\/www.vskills.in\/certification\/blog\/author\/teamvskills\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WannaCry Ransomware","description":"An technical analysis of WannaCry ransomware, which has affected computer networks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/","og_locale":"en_US","og_type":"article","og_title":"WannaCry Ransomware","og_description":"An technical analysis of WannaCry ransomware, which has affected computer networks.","og_url":"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/","og_site_name":"Vskills Blog","article_publisher":"https:\/\/www.facebook.com\/vskills.in","article_published_time":"2017-06-28T07:25:20+00:00","article_modified_time":"2024-04-03T07:54:31+00:00","og_image":[{"width":750,"height":400,"url":"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/15_WannaCry-Ransomware-Analysis.gif","type":"image\/gif"}],"author":"teamvskills","twitter_misc":{"Written by":"teamvskills","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/","url":"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/","name":"WannaCry Ransomware","isPartOf":{"@id":"https:\/\/www.vskills.in\/certification\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/#primaryimage"},"image":{"@id":"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/#primaryimage"},"thumbnailUrl":"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/15_WannaCry-Ransomware-Analysis.gif","datePublished":"2017-06-28T07:25:20+00:00","dateModified":"2024-04-03T07:54:31+00:00","author":{"@id":"https:\/\/www.vskills.in\/certification\/blog\/#\/schema\/person\/db89ed45879ddc5d130a8aae4309d90a"},"description":"An technical analysis of WannaCry ransomware, which has affected computer networks.","breadcrumb":{"@id":"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/#primaryimage","url":"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/15_WannaCry-Ransomware-Analysis.gif","contentUrl":"https:\/\/www.vskills.in\/certification\/blog\/wp-content\/uploads\/2017\/06\/15_WannaCry-Ransomware-Analysis.gif","width":750,"height":400,"caption":"WannaCry Ransomware Analysis"},{"@type":"BreadcrumbList","@id":"https:\/\/www.vskills.in\/certification\/blog\/wannacry-ransomware-analysis\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.vskills.in\/certification\/blog\/"},{"@type":"ListItem","position":2,"name":"WannaCry Ransomware Analysis"}]},{"@type":"WebSite","@id":"https:\/\/www.vskills.in\/certification\/blog\/#website","url":"https:\/\/www.vskills.in\/certification\/blog\/","name":"Vskills Blog","description":"Vskills - A Initiative in Assessment to Enhance Employability","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.vskills.in\/certification\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.vskills.in\/certification\/blog\/#\/schema\/person\/db89ed45879ddc5d130a8aae4309d90a","name":"teamvskills","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.vskills.in\/certification\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b622f2772f7029565ef961f615b0727ed219929be1c95fa7aeda53560feec085?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b622f2772f7029565ef961f615b0727ed219929be1c95fa7aeda53560feec085?s=96&d=mm&r=g","caption":"teamvskills"},"url":"https:\/\/www.vskills.in\/certification\/blog\/author\/teamvskills\/"}]}},"_links":{"self":[{"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/posts\/49746","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/comments?post=49746"}],"version-history":[{"count":6,"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/posts\/49746\/revisions"}],"predecessor-version":[{"id":75622,"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/posts\/49746\/revisions\/75622"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/media\/51577"}],"wp:attachment":[{"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/media?parent=49746"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/categories?post=49746"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.vskills.in\/certification\/blog\/wp-json\/wp\/v2\/tags?post=49746"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}