Jump to content

Recommended Posts

Posted
Either it'll sync the encrypted files up or MS will detect it's infected & block it. I believe both onedrive/google docs have versioning, so you can just pull back old versions pre encryption
Posted
I believe that if you get hit you can raise a ticket with MS who will help roll back entire O365 OneDrive/Sharepoint Document libraries.
Posted

^ This tweet was deleted. Here's a new link...

 

https://twitter.com/NerdPyle/status/863169891863375872

 

gR2K9W.png

 

Microsoft have been recommending disabling/removing SMB1 for ages.

 

http://aka.ms/stopusingsmb1 & https://support.microsoft.com/en-us/help/2696547/

 

Hi folks, Ned here again and today’s topic is short and sweet:

 

Stop using SMB1. Stop using SMB1. STOP USING SMB1!

 

Earlier this week we released MS16-114, a security update that prevents denial of service and remote code execution. If you need this security patch, you already have a much bigger problem: you are still running SMB1.

 

The original SMB1 protocol is nearly 30 years old, and like much of the software made in the 80’s, it was designed for a world that no longer exists. A world without malicious actors, without vast sets of important data, without near-universal computer usage. Frankly, its naivete is staggering when viewed though modern eyes. I blame the West Coast hippy lifestyle.

 

Let me explain why this protocol needs to hit the landfill.

 

A lot of people seems to have forgotten about the Badlock vulnerability early last year. That would have been a good time to stop using SMB1 if it wasn't already removed or disabled.

 

https://twitter.com/SwiftOnSecurity/status/719974066149457920

 

uZWMCL.png

Posted
Updates are all well and good but to put things into perspective our Trust alone has 4000 odd workstations and 300-400 servers so a patch going to every single device, installing successfully and then having a reboot just to be sure is pretty much nigh on impossible and it only takes one!

 

The patch had been out since march and would have been part of the windows update process.

 

Reporting of missing patches is made easy by wsus and sccm. Keeping on top of this is basic network management

 

It will be far easier making sure your devices are protected than dealing with the aftermath.

Posted
Updates are all well and good but to put things into perspective our Trust alone has 4000 odd workstations and 300-400 servers so a patch going to every single device, installing successfully and then having a reboot just to be sure is pretty much nigh on impossible and it only takes one!

What about simple things like blocking macros in Office documents originating from the Internet, making certain types of Windows scripts non-executable by associating them with Notepad (or disabling WSH completely), blocking PowerShell.exe, cmd.exe etc. from accessing the Internet and so on?

 

A lot of the macro-based ransomware that I have read about uses PowerShell to download additional files from the Internet. That seems such an easy thing to prevent.

 

https://www.fireeye.com/blog/threat-research/2016/07/cerber-ransomware-attack.html

 

PowerShell Abuse

When the victim opens the attached Word document, the malicious macro writes a small piece of VBScript into memory and executes it. This VBScript executes PowerShell to connect to an attacker-controlled server and download the ransomware (profilest.exe), as seen in Figure 1.

 

It has been increasingly common for threat actors to use malicious macros to infect users because the majority of organizations permit macros to run from Internet-sourced office documents.

 

In this case we observed the macrocode calling PowerShell to bypass execution policies – and run in hidden as well as encrypted mode – with the intention that PowerShell would download the ransomware and execute it without the knowledge of the victim.

 

OTzv9P.png

Posted (edited)

'Accidental hero' finds kill switch to stop spread of ransomware cyber-attack

 

An "accidental hero" has halted the global spread of the WannaCry ransomware, reportedly by spending a few dollars on registering a domain name hidden in the malware.

 

The ransomware has wreaked havoc on organizations including FedEx and Telefonica, as well as the UK’s National Health Service (NHS), where operations were cancelled, x-rays, test results and patient records became unavailable and phones did not work.

 

However, a UK cybersecurity researcher tweeting as @malwaretechblog, with the help of Darien Huss from security firm Proofpoint, found and activated a “kill switch” in the malicious software.

 

The switch was hardcoded into the malware in case the creator wanted to stop it spreading. This involved a very long nonsensical domain name that the malware makes a request to – just as if it was looking up any website – and if the request comes back and shows that the domain is live, the kill switch takes effect and the malware stops spreading.

 

“I saw it wasn’t registered and thought, ‘I think I’ll have that’,” he is reported as saying. The purchase cost him $10.69. Immediately, the domain name was registering thousands of connections every second.

 

https://twitter.com/MalwareTechBlog/status/863187104716685312

 

nCpjhZ.png

 

MalwareTech has a relatime infection tracker for WCrypt / WannaCrypt...

 

https://intel.malwaretech.com/botnet/wcrypt/?t=30m&bid=all

 

KX7nqY.png

 

f82pn4.png

Edited by Arthur
Posted (edited)

This is unexpected... :eek: :eek: :eek:

 

https://twitter.com/Microsoft/status/863286567137402880

 

1SuhTH.png

 

Customer Guidance for WannaCrypt attacks

 

Today many of our customers around the world and the critical systems they depend on were victims of malicious “WannaCrypt” software. Seeing businesses and individuals affected by cyberattacks, such as the ones reported today, was painful. Microsoft worked throughout the day to ensure we understood the attack and were taking all possible actions to protect our customers. This blog spells out the steps every individual and business should take to stay protected. Additionally, we are taking the highly unusual step of providing a security update for all customers to protect Windows platforms that are in custom support only, including Windows XP, Windows 8, and Windows Server 2003. Customers running Windows 10 were not targeted by the attack today.

 

Details are below.

 

  • In March, we released a security update which addresses the vulnerability that these attacks are exploiting. Those who have Windows Update enabled are protected against attacks on this vulnerability. For those organizations who have not yet applied the security update, we suggest you immediately deploy Microsoft Security Bulletin MS17-010.
  • For customers using Windows Defender, we released an update earlier today which detects this threat as Ransom:Win32/WannaCrypt. As an additional “defense-in-depth” measure, keep up-to-date anti-malware software installed on your machines. Customers running anti-malware software from any number of security companies can confirm with their provider, that they are protected.
  • This attack type may evolve over time, so any additional defense-in-depth strategies will provide additional protections. (For example, to further protect against SMBv1 attacks, customers should consider blocking legacy protocols on their networks).

We also know that some of our customers are running versions of Windows that no longer receive mainstream support. That means those customers will not have received the above mentioned Security Update released in March. Given the potential impact to customers and their businesses, we made the decision to make the Security Update for platforms in custom support only, Windows XP, Windows 8, and Windows Server 2003, broadly available for download here.

 

This decision was made based on an assessment of this situation, with the principle of protecting our customer ecosystem overall, firmly in mind.

 

Some of the observed attacks use common phishing tactics including malicious attachments. Customers should use vigilance when opening documents from untrusted or unknown sources. For Office 365 customers we are continually monitoring and updating to protect against these kinds of threats including Ransom:Win32/WannaCrypt. More information on the malware itself is available from the Microsoft Malware Protection Center on the Windows Security blog. For those new to the Microsoft Malware Protection Center, this is a technical discussion focused on providing the IT Security Professional with information to help further protect systems.

 

We are working with customers to provide additional assistance as this situation evolves, and will update this blog with details as appropriate.

 

Phillip Misner, Principal Security Group Manager Microsoft Security Response Center

 

WannaCrypt ransomware worm targets out-of-date systems

 

On 12 May 2017 we detected a new ransomware that spreads like a worm by leveraging vulnerabilities that have been previously fixed. While security updates are automatically applied in most computers, some users and enterprises may delay deployment of patches. Unfortunately, the malware, known as WannaCrypt, appears to have affected computers that have not applied the patch for these vulnerabilities. While the attack is unfolding, we remind users to install MS17-010 if they have not already done so.

 

Microsoft antimalware telemetry immediately picked up signs of this campaign. Our expert systems gave us visibility and context into this new attack as it happened, allowing Windows Defender Antivirus to deliver real-time defense. Through automated analysis, machine learning, and predictive modeling, we were able to rapidly protect against this malware.

 

In this blog, we provide an early analysis of the end-to-end ransomware attack. Please note this threat is still under investigation. The attack is still active, and there is a possibility that the attacker will attempt to achieve persistence by reacting to our detection response.

 

[...]

 

Dropper

The threat arrives as a dropper Trojan that has the following two components:

 

a. A component that tries to exploit the SMB EternalBlue vulnerability in other computers

b. Ransomware known as WannaCrypt

 

The dropper tries to connect the following domain using the API InternetOpenUrlA():

 

[b]hxxp://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com[/b]

 

If connection is successful, the threat does not infect the system further with ransomware or try to exploit other systems to spread; it simply stops execution. However, if the connection fails, the dropper proceeds to drop the ransomware and creates a service on the system.

 

In other words, blocking the domain with firewall either at ISP or enterprise network level will cause the ransomware to continue spreading and encrypting files.

 

The threat creates a service named mssecsvc2.0, whose function is to exploit the SMB vulnerability in other computers accessible from the infected system:

Edited by Arthur
  • Thanks 1
Posted
Unusually wise decision by MS. While it may make some misguided users still stick with outdated OSs, it should help to mitigate the effects and relieve some hard-pressed support teams! My guess would be that back-porting the fix was straightforward and didn't take too much work, but credit to MS for doing it anyway. XP is now in excess of 16 years old - how many people would expect that length of support for any other frontline product?
Posted
Also is it right that 4012216 is showing as bulletin MS17-008 in SCCM (same in two schools)?

 

See pic -> [ATTACH=CONFIG]43181[/ATTACH]

 

Anyone seeing the same thing as me. Its the march update but showing as MS17-008. All posts say to patch MS17-010 but that isn't showing in SCCM. MS17-008 is showing as KB4012216.

 

Manually doing online checks for all windows updates just to be sure.

Posted
Anyone seeing the same thing as me. Its the march update but showing as MS17-008. All posts say to patch MS17-010 but that isn't showing in SCCM. MS17-008 is showing as KB4012216.

 

Manually doing online checks for all windows updates just to be sure.

 

This got me for a while, KB4012216 and a few others are the rollups containing the 17-010 update along with a few others:

 

 

This security update resolves the following vulnerabilities in Windows 8.1 and Windows Server 2012 R2:

MS17-022 Security update for Microsoft XML Core Services

MS17-021 Security update for DirectShow

MS17-019 Security update for Active Directory Federation Services

MS17-018 Security update for Windows Kernel-Mode Drivers

MS17-017 Security update for Windows Kernel

MS17-016 Security update for Internet Information Services

MS17-013 Security update for Microsoft Graphics Component

MS17-012 Security update for Microsoft Windows

MS17-011 Security update for Microsoft Uniscribe

MS17-010 Security update for Windows SMB Server

MS17-009 Security update for Microsoft Windows PDF Library

MS17-008 Security update for Windows Hyper-V

MS17-006 Cumulative security update for Internet Explorer

 

James

Posted

"The Tories cut security support for the NHS’s outdated computer system a year ago, despite warnings it would leave hospitals open to hackers , it was claimed.

 

The Government Digital Service, set up by David Cameron , decided not to extend a £5.5million one-year support deal with Microsoft for Windows XP."

 

http://www.mirror.co.uk/news/uk-news/tories-cut-security-support-outdated-10413160

 

🤦♂️ when will they learn? We don't point out risks and request money to update things for no reason?!!

Posted

Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well.

:)

Pete

Posted
Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well.

:)

Pete

 

Maybe, we did it last night!!

  • Thanks 1
Posted (edited)
Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well.

:)

Pete

 

Try from 10 last night until 2am this morning [emoji22] had the update applied but still wanted to be certain no further updates had been missed.

 

It's prompted me to resend a pretty stern email to a supplier who insists we can only run a specific version of .Net on two servers or our MIS system collapses!!! Add to that our "cloud" based finance software that relies so heavily on Java on the end device . Good job I restrict it to only the finance office PCs.

Edited by Asgard
  • Thanks 2
Posted
Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well.

 

haha, I may have spent most of yesterday evening from getting home until gone 1am rebooting servers that had missed the last patch window & forceably rebooting admin machines that were behind as well. Along with speeding up our Sophos Exploit protection rollout...

 

100% of our machines had the patch on to prevent it from spreading, but I figured it couldn't hurt to spend a few hours doing a tidy! Still remoted on now upgrading every piece of software I can get my hands on...

Posted
Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well.

:)

Pete

 

Maybe, we did it last night!!

 

No, that's what I'm doing as well. :)

 

For everyone doing this.... please, please make your SLT, non IT colleagues, etc know that you are/have been doing this ... in your own time ... proactively trying to protect everyone ... still need to be careful ...

 

Make sure they know that you deserve your halo polished...and that just because you have done this doesn't mean that they, or you, can relax.

Posted
Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well.

:)

Pete

 

Doing the same here... just don't tell my wife!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...