Ransomware are causing major disruptions in recent years.
Recently leaked dump of NSA EternalBlue exploit is used by cybercriminals to spread WannaCry ransomware worldwide. Dump of MS-17-010 Windows OS Vulnerability was made public by the notorious Shadow Broker group on 14th April, 2017. This vulnerability affects most of the desktop and server editions Microsoft Windows and Microsoft has released patch for the same in March, 2017. However, systems that have not applied this patch are affected by the WannaCry ransomware which uses wormlike behavior to affect vulnerable system on the network.
WannaCry Creating Havoc Worldwide
This ransomware has already affected high profile organizations in Spain, UK, China and other countries including India. These organizations include clinics and hospitals in UK, telecom, gas, electricity and other utility providers. Many universities in China have also been targeted.
In Quick Heal Security Labs, till now 3000+ WannaCry ransomware attacks are detected out which around 2450 are from India. Quick Heal has successfully defended these cases of attacks from compromise and data encryption.
How WannaCry Ransomware works?
Attack is carried when systems are connected to network using SMB services. These services are attacked and exploited by “EternalBlue” exploit, planting WannaCry Ransomware causing the file encryption after successful execution. When files are encrypted, it appends “.WNCRY” extension to all encrypted files.
Image 1: WannaCry Ransomware Encrypted files
After successful exploitation, it adds the below files to the system:- C:\ProgramData\
\@WanaDecryptor@.exe - C:\ProgramData\
\tasksche.exe - C:\ProgramData\
\taskdl.exe - C:\ProgramData\
\taskse.exe
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- “xwjfzbtm432″=”\”C:\\ProgramData\\
\\tasksche.exe\“”
Image 2: WannaCry Ransomware Warning Message
How Quick Heal protects against WannaCry Ransomware?Quick Heal Virus Protection successfully detects and cleans malicious file responsible for file encryption as “TrojanRansom.Wanna”
Image 3: Quick Heal Virus Protection Warning Message
Quick Heal Advanced Behavior Detection System
proactively detects this ransomware activity successfully based on its
behavior. User needs to click on BLOCK button in this situation to stop
encryption activity.
Image 4: Quick Heal Advanced Behavior Based Detection Prompt
Quick Heal Anti-ransomware technology also successfully detects file encryption activity of WannaCry Ransomware:
Image 5: Quick Heal Anti-ransomware detects encryption activity
Recommendations to reduce ransomware attacks:
Quick Heal Security Labs highly recommends taking the following measures to reduce the risk of infection by WannaCry Ransomware:
- Apply Patch for vulnerabilities used by this ransomware from Microsoft
- Take regular back up of your important data and periodically check the backup restoration process to make sure files are getting properly restored.
- Ensure that security solutions are switched on all nodes of the network.
- Always keep installed security software up-to-date with latest signature updates.
- Perform Full System Scan using installed security software.
- Avoid clicking on links and opening attachment in emails from unknown and suspicious sources.
Acknowledgement:
Subject matter experts –
Quick Heal Security Labs
For Further Details Kindly Contact me Ritesh Ritro Jain
Email ~ ritesh1988007@gmail.com
Amazing facts you have discussed in your article. thank you and update more informations
ReplyDeletePython Training in Chennai
Python course in Chennai
Big data training in chennai
JAVA Training in Chennai
Selenium Training in Chennai
Python Training in Chennai
Python Course in Chennai
Indeed an informative post! Thank you for giving us a way to get rid of Wannacry ransomware. However, I have read about wannacry ransomware attack on other sites. Is it a big threat?
ReplyDeleteOk, hope this one really works. Protection against ransomware looks like a myth now. Backups are better ;)
ReplyDeletethis is very helpful content for all people you can visit my website and my blog যে ৪ শ্রেণীর মানুষের ঘরে রহমতের ফেরেশতা আসে না!
ReplyDelete