Jump to content

Recommended Posts

Posted (edited)

Had an email on one of my tech lists doing a bit of a sales pitch for Sophos Intercept X as this was happening. Very nice to know it helped prevent infections in this case (although as we've seen from some people's testing on here it's far from bulletproof) but it still annoys me that the security companies are trying to make a pretty sizeable profit line out of this. Basically their AV products aren't fit for purpose for evolving threats so rather than providing value to the product you pay good money for they hit you for another additional subscription to plug the gap.

 

People will then ask why the NHS didn't have this in place, I can imagine full well why in some places...

 

"we need to address the ransomware threat"

"what's that?"

"tech explains the threat"

"what do you need to prevent it"

"an extra piece of software at £x per machine"

"can't the current AV do it"

"no"

"sorry no budget, just tell the users not to open attachments"

 

Extra layers of protection like the honeypot files and early warning scripts we have on here can help but it is a constantly evolving threat coming at a time when resources are getting cut that are required to deal with it.

Edited by gshaw
Posted

Sad incident, very much doubt it was a targeted attack as that's too much effort and doesn't add up with the reports of who has been affected.

 

One thing I will say from this, hopefully it's time the government and NHS will wake up and realize a serious overhaul in their IT infrastructure is required... Windows XP machines still a plenty along with however much outdated software and patching.

Now I'm just waiting for the news leak in the coming days when we find out the backup/DR systems don't work correctly or some well worded executive spin off of that, then the real fun begins for the media!

Posted
The GOV had a deal with MS until 2015 for Windows XP (I assume server 2003 also) updates, so nearly two years have passed and XP computers are still in use. Not good.
Posted
I'm thinking it might be a good time to email all staff telling them to be extra vigilant and cite current events, one thing that may come of this mess is people are a lot more aware (Although I'm not holding my breath)
Posted
I'm thinking it might be a good time to email all staff telling them to be extra vigilant and cite current events, one thing that may come of this mess is people are a lot more aware (Although I'm not holding my breath)

 

Did that not long after the news broke, we've had a (minor) ransomware problem before. One person opened a dodgy attachment and it spread to the network drives. Fortunately it was picked up fairly quickly but involved pulling the plug on the server and disinfecting it...

Posted
I'm guessing if you don't have SMBv1 enabled you're ok from this vuln?

That's the impression I get but it is still enabled by default on a 2016 server I recently installed.

Posted
I've just checked and I think if you have the March security updates (MS17-010) relevant to you (2012R2 for us, so 4012216) you should sleep a bit easier.

 

https://technet.microsoft.com/en-us/library/security/ms17-010.aspx

 

Lovely, thanks for that.

 

From that link (and another previously) then, I've got a batch file thus:

 

Wmic qfe list > C:\updatelist.txt

Spits out a text file with a list of updates in it to that text file on the root of C: . According to the above link, ctrl+f that file for the following and if they appear, you're protected:

 

Windows 7x64 - 4012212 and/or 4012215

Server 2008r2x64sp1 - 4012212 and/or 4012215

... etc ...

 

That sound right?

Posted
That's the impression I get but it is still enabled by default on a 2016 server I recently installed.

 

I also find this very bizarre!

Posted (edited)

It can come in over the internet by a number of means, most likely phishing emails. Once in it is spreading around network by the exploit in smbv1 ms17-010. This was patched by microsoft around march time.

Below is some of the inbuilt C2 hosts.

 

http://gx7ekbenv2riucmf.onion

http://57g7spgrzlojinas.onion

http://xxlvbrloxvriy2c5.onion

http://76jdd2ir2embyv47.onion

http://cwwnhwhlz52maqm7.onion

 

Below is filetypes it hunts for and encrypts

IMG_2856.JPG

Edited by rrrrr
Posted
I've just checked and I think if you have the March security updates (MS17-010) relevant to you (2012R2 for us, so 4012216) you should sleep a bit easier.

 

https://technet.microsoft.com/en-us/library/security/ms17-010.aspx

 

Is the way that Windows Updates now work that if you install the May security updates that will incorporate anything from April, March etc as well?

 

Also is it right that 4012216 is showing as bulletin MS17-008 in SCCM (same in two schools)?

 

See pic -> sccm.png

Posted
Updates are all well and good but to put things into perspective our Trust alone has 4000 odd workstations and 300-400 servers so a patch going to every single device, installing successfully and then having a reboot just to be sure is pretty much nigh on impossible and it only takes one!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...