Showing posts with label ms17-010. Show all posts
Showing posts with label ms17-010. Show all posts
Monday, 15 May 2017
WannaCry 2.0: Indicators of Compromise
WannaCry (WannaCryptor) is becoming probably the most popular cryptolocker in the history of ransomware. It has nothing new in terms of files encryption (RSA + AES using MS CryptoAPI) but uses MS17-010 (a.k.a. ETERNALBLUE named by NSA) vulnerability to propagate itself through local networks using the Server Message Block (SMB) protocol as a network worm resulting in thousands of infections of Windows machines that have not been updated so far.
Subscribe to:
Posts (Atom)
