All about WannaCry and Jaff Ransomware
本帖最後由 samiux 於 2017-5-16 18:23 編輯
To all sysadmins and Windows users,
Talos conducts a research on WannaCry Ransomware and there are some hints for preventing the attack even your system is infected the malware.
Player 3 Has Entered the Game: Say Hello to 'WannaCry'
Meanwhile, there is another ransomware namely, Jaff which is also in the wild.
Jaff Ransomware: Player 2 Has Entered The Game
Please read the above links carefully if you have Windows boxes in your network.
Hope this may help.
Samiux
Update news about WannaCry on 2017-05-14 :
It's Not Over, WannaCry 2.0 Ransomware Just Arrived With No 'Kill-Switch'
Update about WannaCry Variants on 2017-5-15 :
The latest news about WannaCry in Hong Kong yesterday night advising your systems to disconnect to the internet is in question.
Beware that when your systems are already infected with WannaCry or its variants, you should allow the systems to connect to internet in order to communicate with the kill-switches that are registered by the Infosec Researchers. When your infected systems can communicate with the kill-switch domains, the malware will be quited and the encryption stopped.
Update about WannaCry on 2017-05-15 Part 2 :
It seems WannaCry and its variants are under control. Thanks for the 2 outstanding Infosec Researchers to discover the hidden domains and registered the kill-switch domains as well as allows all users in the world to connect to in order to sinkhole it. Thanks again. :D
When your system or network can access the following 2 domains (at the moment), the malware will quit and do not encrypt your box, they are :
iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.com
or
www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
www.ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.com
If your system cannot access internet, you can create a website internally and allows port 80 to be accessed on the said domains.
By the way, even if your systems and network do not seem to be affected, make sure to update your systems with Microsoft patches.
Update about WannaCry on 2017-05-16 :
The third sinkhole domain is :
ayylmaotjhsstasdfasdfasdfasdfasdfasdfasdf.com
or
www.ayylmaotjhsstasdfasdfasdfasdfasdfasdfasdf.com
Make sure the above said 3 domains are not being blocked.
Update Reason :
- Update News of WannaCry |
|
|