17/05/2017
A major ransomware attack broke on Friday May 12, affecting many organizations the world over, reportedly including major Telco’s, hospital systems and transportation providers. The attack has purportedly spread to some 150 countries around the world. This is the first ransomware worm to ever be seen. The malware responsible for this attack is a ransomware variant known as 'WannaCry'.
On March 14, Microsoft released a security update to patch this vulnerability. While this protected newer Windows computers that had Windows Update enabled, many computers remained unpatched globally. This is particularly true of Win XP computers and Win 2003 Servers which are no longer supported by Microsoft, as well as the millions of computers globally running pirated software, which are (obviously) not automatically upgraded.
In a bid to ensure our network isn’t at risk, our approach is a defence-in-depth strategy following best practices recommended to combat attacks based on Microsoft SMB. We are already taking necessary steps to ensure all Windows machines on the LAN are fully patched with the security update from Microsoft and also ensure external intrusion is inaccessible through the TCP ports (139, 445).
PLEASE DO NOT OPEN any attached file from an untrusted source or any executable file name “tasksche.exe” as this file checks for disk drives including network shares and removable storage devices mapped to any letter. It then checks for files with a file extension and after compromising the host computer, it encrypts files on the local directory thus denying access to your files, and then demanding a ransom payment in the form of Bitcoin.
Read more http://blog.talosintelligence.com/2017/05/wannacry.html
A blog about the world class Intelligence Group, Talos, Cisco's Intelligence Group