DrCheese Posted May 12, 2017 Posted May 12, 2017 Either it'll sync the encrypted files up or MS will detect it's infected & block it. I believe both onedrive/google docs have versioning, so you can just pull back old versions pre encryption
psydii Posted May 12, 2017 Posted May 12, 2017 I believe that if you get hit you can raise a ticket with MS who will help roll back entire O365 OneDrive/Sharepoint Document libraries.
Arthur Posted May 13, 2017 Posted May 13, 2017 https://twitter.com/NerdPyle/status/863146760822181889 ^ This tweet was deleted. Here's a new link... https://twitter.com/NerdPyle/status/863169891863375872 Microsoft have been recommending disabling/removing SMB1 for ages. http://aka.ms/stopusingsmb1 & https://support.microsoft.com/en-us/help/2696547/ Hi folks, Ned here again and today’s topic is short and sweet: Stop using SMB1. Stop using SMB1. STOP USING SMB1! Earlier this week we released MS16-114, a security update that prevents denial of service and remote code execution. If you need this security patch, you already have a much bigger problem: you are still running SMB1. The original SMB1 protocol is nearly 30 years old, and like much of the software made in the 80’s, it was designed for a world that no longer exists. A world without malicious actors, without vast sets of important data, without near-universal computer usage. Frankly, its naivete is staggering when viewed though modern eyes. I blame the West Coast hippy lifestyle. Let me explain why this protocol needs to hit the landfill. A lot of people seems to have forgotten about the Badlock vulnerability early last year. That would have been a good time to stop using SMB1 if it wasn't already removed or disabled. https://twitter.com/SwiftOnSecurity/status/719974066149457920
rrrrr Posted May 13, 2017 Posted May 13, 2017 Updates are all well and good but to put things into perspective our Trust alone has 4000 odd workstations and 300-400 servers so a patch going to every single device, installing successfully and then having a reboot just to be sure is pretty much nigh on impossible and it only takes one! The patch had been out since march and would have been part of the windows update process. Reporting of missing patches is made easy by wsus and sccm. Keeping on top of this is basic network management It will be far easier making sure your devices are protected than dealing with the aftermath.
free780 Posted May 13, 2017 Posted May 13, 2017 Technical details: https://securelist.com/blog/incidents/78351/wannacry-ransomware-used-in-widespread-attacks-all-over-the-world/ 1. Use applocker. Looks like vbs/exe/bat 2. Block the domains. 3. Block exe,vbs,bat 4. Block macros from the internet. 5. Run all users as std. Create separate admin accounts for IT Staff. 6. Disable SMB1. 1
Arthur Posted May 13, 2017 Posted May 13, 2017 Updates are all well and good but to put things into perspective our Trust alone has 4000 odd workstations and 300-400 servers so a patch going to every single device, installing successfully and then having a reboot just to be sure is pretty much nigh on impossible and it only takes one! What about simple things like blocking macros in Office documents originating from the Internet, making certain types of Windows scripts non-executable by associating them with Notepad (or disabling WSH completely), blocking PowerShell.exe, cmd.exe etc. from accessing the Internet and so on? A lot of the macro-based ransomware that I have read about uses PowerShell to download additional files from the Internet. That seems such an easy thing to prevent. https://www.fireeye.com/blog/threat-research/2016/07/cerber-ransomware-attack.html PowerShell Abuse When the victim opens the attached Word document, the malicious macro writes a small piece of VBScript into memory and executes it. This VBScript executes PowerShell to connect to an attacker-controlled server and download the ransomware (profilest.exe), as seen in Figure 1. It has been increasingly common for threat actors to use malicious macros to infect users because the majority of organizations permit macros to run from Internet-sourced office documents. In this case we observed the macrocode calling PowerShell to bypass execution policies – and run in hidden as well as encrypted mode – with the intention that PowerShell would download the ransomware and execute it without the knowledge of the victim.
Arthur Posted May 13, 2017 Posted May 13, 2017 (edited) 'Accidental hero' finds kill switch to stop spread of ransomware cyber-attack An "accidental hero" has halted the global spread of the WannaCry ransomware, reportedly by spending a few dollars on registering a domain name hidden in the malware. The ransomware has wreaked havoc on organizations including FedEx and Telefonica, as well as the UK’s National Health Service (NHS), where operations were cancelled, x-rays, test results and patient records became unavailable and phones did not work. However, a UK cybersecurity researcher tweeting as @malwaretechblog, with the help of Darien Huss from security firm Proofpoint, found and activated a “kill switch” in the malicious software. The switch was hardcoded into the malware in case the creator wanted to stop it spreading. This involved a very long nonsensical domain name that the malware makes a request to – just as if it was looking up any website – and if the request comes back and shows that the domain is live, the kill switch takes effect and the malware stops spreading. “I saw it wasn’t registered and thought, ‘I think I’ll have that’,” he is reported as saying. The purchase cost him $10.69. Immediately, the domain name was registering thousands of connections every second. https://twitter.com/MalwareTechBlog/status/863187104716685312 MalwareTech has a relatime infection tracker for WCrypt / WannaCrypt... https://intel.malwaretech.com/botnet/wcrypt/?t=30m&bid=all Edited May 13, 2017 by Arthur
snagrat Posted May 13, 2017 Posted May 13, 2017 'Accidental hero' finds kill switch to stop spread of ransomware cyber-attack https://twitter.com/MalwareTechBlog/status/863187104716685312 MalwareTech has a relatime infection tracker for WCrypt / WannaCrypt... https://intel.malwaretech.com/botnet/wcrypt/?t=30m&bid=all So if I read that right it means the ransomware no longer works?
Arthur Posted May 13, 2017 Posted May 13, 2017 (edited) So if I read that right it means the ransomware no longer works? Correct. https://twitter.com/MalwareTechBlog/status/863189077843116032 Whoever created WannaCrypt is probably working on v3.0 right now however. Edited May 13, 2017 by Arthur
Arthur Posted May 13, 2017 Posted May 13, 2017 (edited) This is unexpected... :eek: https://twitter.com/Microsoft/status/863286567137402880 Customer Guidance for WannaCrypt attacks Today many of our customers around the world and the critical systems they depend on were victims of malicious “WannaCrypt” software. Seeing businesses and individuals affected by cyberattacks, such as the ones reported today, was painful. Microsoft worked throughout the day to ensure we understood the attack and were taking all possible actions to protect our customers. This blog spells out the steps every individual and business should take to stay protected. Additionally, we are taking the highly unusual step of providing a security update for all customers to protect Windows platforms that are in custom support only, including Windows XP, Windows 8, and Windows Server 2003. Customers running Windows 10 were not targeted by the attack today. Details are below. In March, we released a security update which addresses the vulnerability that these attacks are exploiting. Those who have Windows Update enabled are protected against attacks on this vulnerability. For those organizations who have not yet applied the security update, we suggest you immediately deploy Microsoft Security Bulletin MS17-010. For customers using Windows Defender, we released an update earlier today which detects this threat as Ransom:Win32/WannaCrypt. As an additional “defense-in-depth” measure, keep up-to-date anti-malware software installed on your machines. Customers running anti-malware software from any number of security companies can confirm with their provider, that they are protected. This attack type may evolve over time, so any additional defense-in-depth strategies will provide additional protections. (For example, to further protect against SMBv1 attacks, customers should consider blocking legacy protocols on their networks). We also know that some of our customers are running versions of Windows that no longer receive mainstream support. That means those customers will not have received the above mentioned Security Update released in March. Given the potential impact to customers and their businesses, we made the decision to make the Security Update for platforms in custom support only, Windows XP, Windows 8, and Windows Server 2003, broadly available for download here. This decision was made based on an assessment of this situation, with the principle of protecting our customer ecosystem overall, firmly in mind. Some of the observed attacks use common phishing tactics including malicious attachments. Customers should use vigilance when opening documents from untrusted or unknown sources. For Office 365 customers we are continually monitoring and updating to protect against these kinds of threats including Ransom:Win32/WannaCrypt. More information on the malware itself is available from the Microsoft Malware Protection Center on the Windows Security blog. For those new to the Microsoft Malware Protection Center, this is a technical discussion focused on providing the IT Security Professional with information to help further protect systems. We are working with customers to provide additional assistance as this situation evolves, and will update this blog with details as appropriate. Phillip Misner, Principal Security Group Manager Microsoft Security Response Center WannaCrypt ransomware worm targets out-of-date systems On 12 May 2017 we detected a new ransomware that spreads like a worm by leveraging vulnerabilities that have been previously fixed. While security updates are automatically applied in most computers, some users and enterprises may delay deployment of patches. Unfortunately, the malware, known as WannaCrypt, appears to have affected computers that have not applied the patch for these vulnerabilities. While the attack is unfolding, we remind users to install MS17-010 if they have not already done so. Microsoft antimalware telemetry immediately picked up signs of this campaign. Our expert systems gave us visibility and context into this new attack as it happened, allowing Windows Defender Antivirus to deliver real-time defense. Through automated analysis, machine learning, and predictive modeling, we were able to rapidly protect against this malware. In this blog, we provide an early analysis of the end-to-end ransomware attack. Please note this threat is still under investigation. The attack is still active, and there is a possibility that the attacker will attempt to achieve persistence by reacting to our detection response. [...] Dropper The threat arrives as a dropper Trojan that has the following two components: a. A component that tries to exploit the SMB EternalBlue vulnerability in other computers b. Ransomware known as WannaCrypt The dropper tries to connect the following domain using the API InternetOpenUrlA(): [b]hxxp://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com[/b] If connection is successful, the threat does not infect the system further with ransomware or try to exploit other systems to spread; it simply stops execution. However, if the connection fails, the dropper proceeds to drop the ransomware and creates a service on the system. In other words, blocking the domain with firewall either at ISP or enterprise network level will cause the ransomware to continue spreading and encrypting files. The threat creates a service named mssecsvc2.0, whose function is to exploit the SMB vulnerability in other computers accessible from the infected system: Edited May 13, 2017 by Arthur 1
rrrrr Posted May 13, 2017 Posted May 13, 2017 When they Windows 10 Do they also mean Server 2016? https://technet.microsoft.com/en-us/library/security/ms17-010.aspx
free780 Posted May 13, 2017 Posted May 13, 2017 In other words upgrade to Windows 10 but due to the outbreak here's a patch.
3s-gtech Posted May 13, 2017 Posted May 13, 2017 Unusually wise decision by MS. While it may make some misguided users still stick with outdated OSs, it should help to mitigate the effects and relieve some hard-pressed support teams! My guess would be that back-porting the fix was straightforward and didn't take too much work, but credit to MS for doing it anyway. XP is now in excess of 16 years old - how many people would expect that length of support for any other frontline product?
gh5000 Posted May 13, 2017 Posted May 13, 2017 Also is it right that 4012216 is showing as bulletin MS17-008 in SCCM (same in two schools)? See pic -> [ATTACH=CONFIG]43181[/ATTACH] Anyone seeing the same thing as me. Its the march update but showing as MS17-008. All posts say to patch MS17-010 but that isn't showing in SCCM. MS17-008 is showing as KB4012216. Manually doing online checks for all windows updates just to be sure.
Jamman960 Posted May 13, 2017 Posted May 13, 2017 Anyone seeing the same thing as me. Its the march update but showing as MS17-008. All posts say to patch MS17-010 but that isn't showing in SCCM. MS17-008 is showing as KB4012216. Manually doing online checks for all windows updates just to be sure. This got me for a while, KB4012216 and a few others are the rollups containing the 17-010 update along with a few others: This security update resolves the following vulnerabilities in Windows 8.1 and Windows Server 2012 R2: MS17-022 Security update for Microsoft XML Core Services MS17-021 Security update for DirectShow MS17-019 Security update for Active Directory Federation Services MS17-018 Security update for Windows Kernel-Mode Drivers MS17-017 Security update for Windows Kernel MS17-016 Security update for Internet Information Services MS17-013 Security update for Microsoft Graphics Component MS17-012 Security update for Microsoft Windows MS17-011 Security update for Microsoft Uniscribe MS17-010 Security update for Windows SMB Server MS17-009 Security update for Microsoft Windows PDF Library MS17-008 Security update for Windows Hyper-V MS17-006 Cumulative security update for Internet Explorer James
tj2419 Posted May 13, 2017 Posted May 13, 2017 "The Tories cut security support for the NHS’s outdated computer system a year ago, despite warnings it would leave hospitals open to hackers , it was claimed. The Government Digital Service, set up by David Cameron , decided not to extend a £5.5million one-year support deal with Microsoft for Windows XP." http://www.mirror.co.uk/news/uk-news/tories-cut-security-support-outdated-10413160 🤦♂️ when will they learn? We don't point out risks and request money to update things for no reason?!!
FragglePete Posted May 13, 2017 Posted May 13, 2017 Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well. Pete
Andycat Posted May 13, 2017 Posted May 13, 2017 Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well. Pete Maybe, we did it last night!! 1
Asgard Posted May 13, 2017 Posted May 13, 2017 (edited) Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well. Pete Try from 10 last night until 2am this morning [emoji22] had the update applied but still wanted to be certain no further updates had been missed. It's prompted me to resend a pretty stern email to a supplier who insists we can only run a specific version of .Net on two servers or our MIS system collapses!!! Add to that our "cloud" based finance software that relies so heavily on Java on the end device . Good job I restrict it to only the finance office PCs. Edited May 13, 2017 by Asgard 2
DrCheese Posted May 13, 2017 Posted May 13, 2017 Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well. haha, I may have spent most of yesterday evening from getting home until gone 1am rebooting servers that had missed the last patch window & forceably rebooting admin machines that were behind as well. Along with speeding up our Sophos Exploit protection rollout... 100% of our machines had the patch on to prevent it from spreading, but I figured it couldn't hurt to spend a few hours doing a tidy! Still remoted on now upgrading every piece of software I can get my hands on...
elsiegee40 Posted May 13, 2017 Posted May 13, 2017 Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well. Pete Maybe, we did it last night!! No, that's what I'm doing as well. For everyone doing this.... please, please make your SLT, non IT colleagues, etc know that you are/have been doing this ... in your own time ... proactively trying to protect everyone ... still need to be careful ... Make sure they know that you deserve your halo polished...and that just because you have done this doesn't mean that they, or you, can relax.
Jamman960 Posted May 13, 2017 Posted May 13, 2017 Am I the only one today (Saturday morning) remoting into my network and checking, updating & patching servers after hearing about this? Also turning off SMB1 support as well. Pete Doing the same here... just don't tell my wife!
caffrey Posted May 13, 2017 Posted May 13, 2017 Me too, stupid file server didn't come backup though - luckily it's open day so I got in early (It was stuck on the bios screen)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now