gshaw Posted May 12, 2017 Posted May 12, 2017 (edited) Had an email on one of my tech lists doing a bit of a sales pitch for Sophos Intercept X as this was happening. Very nice to know it helped prevent infections in this case (although as we've seen from some people's testing on here it's far from bulletproof) but it still annoys me that the security companies are trying to make a pretty sizeable profit line out of this. Basically their AV products aren't fit for purpose for evolving threats so rather than providing value to the product you pay good money for they hit you for another additional subscription to plug the gap. People will then ask why the NHS didn't have this in place, I can imagine full well why in some places... "we need to address the ransomware threat" "what's that?" "tech explains the threat" "what do you need to prevent it" "an extra piece of software at £x per machine" "can't the current AV do it" "no" "sorry no budget, just tell the users not to open attachments" Extra layers of protection like the honeypot files and early warning scripts we have on here can help but it is a constantly evolving threat coming at a time when resources are getting cut that are required to deal with it. Edited May 12, 2017 by gshaw
googlemad Posted May 12, 2017 Posted May 12, 2017 We have McAfee which is AWFUL! I was never a huge fan of Sophos in my previous job but give me that back any day!
Tefters Posted May 12, 2017 Posted May 12, 2017 Sad incident, very much doubt it was a targeted attack as that's too much effort and doesn't add up with the reports of who has been affected. One thing I will say from this, hopefully it's time the government and NHS will wake up and realize a serious overhaul in their IT infrastructure is required... Windows XP machines still a plenty along with however much outdated software and patching. Now I'm just waiting for the news leak in the coming days when we find out the backup/DR systems don't work correctly or some well worded executive spin off of that, then the real fun begins for the media!
JRA Posted May 12, 2017 Posted May 12, 2017 (edited) So, been trawling some links and gotten this, but it's a bit over my head: https://blogs.technet.microsoft.com/ralphkyttle/2017/04/07/discover-smb1-in-your-environment-with-dscea/ Is there any easy way to determine if you're a) vulnerable and b) protected? Guh? :/ Edited May 12, 2017 by JRA 1
Andycat Posted May 12, 2017 Posted May 12, 2017 I've just checked and I think if you have the March security updates (MS17-010) relevant to you (2012R2 for us, so 4012216) you should sleep a bit easier. https://technet.microsoft.com/en-us/library/security/ms17-010.aspx 1
gh5000 Posted May 12, 2017 Posted May 12, 2017 This site has the updates listed. Think it's one of the three depending on the OS. There's also the point about disabling smb1 via add/remove features which is covered in the technet blog http://www.angleseycomputersolutions.co.uk/uncategorized/are-you-vulnerable-to-the-nhscyberattack/
Homer Posted May 12, 2017 Posted May 12, 2017 I'm guessing if you don't have SMBv1 enabled you're ok from this vuln?
spacebar Posted May 12, 2017 Posted May 12, 2017 The GOV had a deal with MS until 2015 for Windows XP (I assume server 2003 also) updates, so nearly two years have passed and XP computers are still in use. Not good.
caffrey Posted May 12, 2017 Posted May 12, 2017 I'm thinking it might be a good time to email all staff telling them to be extra vigilant and cite current events, one thing that may come of this mess is people are a lot more aware (Although I'm not holding my breath)
smurfomatic Posted May 12, 2017 Posted May 12, 2017 I'm thinking it might be a good time to email all staff telling them to be extra vigilant and cite current events, one thing that may come of this mess is people are a lot more aware (Although I'm not holding my breath) Did that not long after the news broke, we've had a (minor) ransomware problem before. One person opened a dodgy attachment and it spread to the network drives. Fortunately it was picked up fairly quickly but involved pulling the plug on the server and disinfecting it...
gh5000 Posted May 12, 2017 Posted May 12, 2017 I'm guessing if you don't have SMBv1 enabled you're ok from this vuln? That's the impression I get but it is still enabled by default on a 2016 server I recently installed.
JRA Posted May 12, 2017 Posted May 12, 2017 I've just checked and I think if you have the March security updates (MS17-010) relevant to you (2012R2 for us, so 4012216) you should sleep a bit easier. https://technet.microsoft.com/en-us/library/security/ms17-010.aspx Lovely, thanks for that. From that link (and another previously) then, I've got a batch file thus: Wmic qfe list > C:\updatelist.txt Spits out a text file with a list of updates in it to that text file on the root of C: . According to the above link, ctrl+f that file for the following and if they appear, you're protected: Windows 7x64 - 4012212 and/or 4012215 Server 2008r2x64sp1 - 4012212 and/or 4012215 ... etc ... That sound right?
FN-GM Posted May 12, 2017 Posted May 12, 2017 That's the impression I get but it is still enabled by default on a 2016 server I recently installed. I also find this very bizarre!
chinesewhispers Posted May 12, 2017 Posted May 12, 2017 Any idea how it is spreading yet? Is it a specific email pattern that we can block in our Google domains?
ITGURU Posted May 12, 2017 Posted May 12, 2017 McAfee are aware of it already , just received an email If your running McAfee with EPO preventative measure listed here: https://kc.mcafee.com/corporate/index?page=content&id=KB89335&elqTrackId=080d6d6426f34a2fb9b7fae0ca16d59a&elq=3d5138920ef74ddb92416987b1588a80&elqaid=7257&elqat=1&elqCampaignId=4054 1
ellsandell Posted May 12, 2017 Posted May 12, 2017 A good information sheet here: https://gist.github.com/rain-1/989428fa5504f378b993ee6efbc0b168
rrrrr Posted May 12, 2017 Posted May 12, 2017 (edited) It can come in over the internet by a number of means, most likely phishing emails. Once in it is spreading around network by the exploit in smbv1 ms17-010. This was patched by microsoft around march time. Below is some of the inbuilt C2 hosts. http://gx7ekbenv2riucmf.onion http://57g7spgrzlojinas.onion http://xxlvbrloxvriy2c5.onion http://76jdd2ir2embyv47.onion http://cwwnhwhlz52maqm7.onion Below is filetypes it hunts for and encrypts Edited May 12, 2017 by rrrrr
gh5000 Posted May 12, 2017 Posted May 12, 2017 Apparently Windows 10 isn't vulnerable Again, I disabled SMB1 on my Windows 10 laptop just to be safe!
rrrrr Posted May 12, 2017 Posted May 12, 2017 Apparently Windows 10 isn't vulnerable 2003 onwards is affected including 10
ellsandell Posted May 12, 2017 Posted May 12, 2017 WCRY has multiple vectors. But the one I can help you with is around ancient SMB1:1. Block 445 inbound2. Install MS10-0173. Remove SMB1 https://twitter.com/NerdPyle/status/863146760822181889
gh5000 Posted May 12, 2017 Posted May 12, 2017 I've just checked and I think if you have the March security updates (MS17-010) relevant to you (2012R2 for us, so 4012216) you should sleep a bit easier. https://technet.microsoft.com/en-us/library/security/ms17-010.aspx Is the way that Windows Updates now work that if you install the May security updates that will incorporate anything from April, March etc as well? Also is it right that 4012216 is showing as bulletin MS17-008 in SCCM (same in two schools)? See pic ->
googlemad Posted May 12, 2017 Posted May 12, 2017 Updates are all well and good but to put things into perspective our Trust alone has 4000 odd workstations and 300-400 servers so a patch going to every single device, installing successfully and then having a reboot just to be sure is pretty much nigh on impossible and it only takes one!
DrCheese Posted May 12, 2017 Posted May 12, 2017 Which is why I should imagine Sophos will make a lot of money over the next few days... Intercept X would have stopped this regardless of patch level (Unless it's XP, then y'all doomed ) https://community.sophos.com/kb/en-us/126733
MS2011 Posted May 12, 2017 Posted May 12, 2017 What will happen if you are syncing your file server files and folders to onedrive and you hit by ransomware
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now