« 2017 »

97 reports

2017-05-23 • Fireeye

FireEye describes WannaCry, also called WCry or WanaCryptor, as a self-propagating ransomware family that spread internally and across the internet by exploiting the MS17-010 SMB vulnerability with EternalBlue. The malware combined a ransomware component …

#WannaCry
2017-05-19 • Comae

Comae described WanaKiwi, a WannaCry recovery tool by Benjamin Delpy that builds on Adrien Guinet's Wannakey method for recovering RSA prime numbers from memory. The technique targets infected Windows systems that have not been rebooted and depends on the…

#WannaCry
2017-05-18 • Threatdown

Malwarebytes assessed that WannaCry spread as a self-propagating ransomworm rather than through a malicious email campaign. The infection path centered on scanning vulnerable public-facing SMB services, exploiting EternalBlue over TCP port 445, and using …

#WannaCry
2017-05-17 • Somansa

WannaCry is analyzed as ransomware that spread globally from 12 May 2017 by abusing Windows SMB vulnerabilities on unpatched systems. The infection chain includes malicious email or websites as initial delivery, then worm-like propagation across local and…

#WannaCry
2017-05-16 • Bae Systems

BAE Systems analyzed WanaCrypt0r as a ransomware worm that spread globally after the ETERNALBLUE SMB exploit became publicly available. The executable checked a hard-coded domain before launching its payload, registered itself as a service, and used worm …

#WannaCry
2017-05-15 • Comae

Comae examined reported code similarities between a February 2017 WannaCry sample and a 2015 Contopee sample that Symantec had previously attributed to Lazarus Group. The excerpt cites Neel Mehta's initial comparison, Kaspersky's shared suspicion, and Sym…

#WannaCry #Lazarus
2017-05-15 • Issuemakers Lab

Operation GoldenAxe describes suspected North Korean activity from June 2016 to May 2017 that compromised more than ten South Korean organization websites tied to diplomacy, aviation, North Korea affairs, unification, parliament, labor, and finance. The a…

#GoldenAxe #MAYDAY
2017-05-14 • Comae

Comae analyzed WannaCry variants that appeared after the initial outbreak, including one live sample seen in the wild and one no-kill-switch sample that Kaspersky recovered from VirusTotal. The live variant used the kill-switch domain ifferfsodp9ifjaposdf…

#WannaCry
2017-05-12 • ESTSecurity

ESTsecurity analyzed the Arabian Night operation using a malicious Word document named Hanssak System that relied on social engineering to prompt macro execution. When macros ran, the document XOR-decoded and dropped a decoy Kuipernet installation survey …

#ArabianNight #IsOne