Windows 10: New global ransomware attack hits East Europe and spreading

Discus and support New global ransomware attack hits East Europe and spreading in AntiVirus, Firewalls and System Security to solve the problem; Is this and issue: [img] I'd think that this speaks for itself. Stop using SMB1 | Storage at Microsoft It's not a secure protocol and the only... Discussion in 'AntiVirus, Firewalls and System Security' started by AndreTen, Jun 26, 2017.

  1. Hydrate Win User

    New global ransomware attack hits East Europe and spreading


    I'd think that this speaks for itself. Stop using SMB1 | Storage at Microsoft

    It's not a secure protocol and the only reasons you should be running it is for Windows XP, compatibility reasons across different devices such as old printers.

    So, disable it otherwise or patch your system from Petya's known attack vectors such as using WUSA for an update, MBAM, Perfmon, AppLocker, the list goes on.
     
    Hydrate, Jun 29, 2017
    #76
  2. AndreTen Win User

    What is the most fascinating @Wynona, malware did have strict policy to stay undisclosed. If certain AV solution was present on infected computer it went straight to destroying of file system, otherwise it went for compromising computer and checked the network for further vulnerabilities.

    In my opinion, main target was collecting of credentials, or just make as much mess as they could.
     
    AndreTen, Jun 29, 2017
    #77
  3. f14tomcat Win User
    Thanks, I have uninstalled that feature. The only reason I asked was this was a clean install about a month ago, and it was enabled by default. I did not proactively enable the feature. Not running XP. And don't have an old printer. That is odd to me.
     
    f14tomcat, Jun 29, 2017
    #78
  4. AndreTen Win User

    New global ransomware attack hits East Europe and spreading

    Guys, don't worry so much about SMBv1 for home networks (OK, it's not something you really need), unless you have some irresponsible admin user in your network. This is not 1st line of attack. Any router will block this.

    Main danger for home users is still phishing with attachments and browsing on internet.
     
    AndreTen, Jun 29, 2017
    #79
  5. f14tomcat Win User
    Wasn't worried about anything. Just curious why it was enabled by default. Haven't had any problems, and don't intend to.

    And the only admin user on this box is me........
     
    f14tomcat, Jun 30, 2017
    #80
  6. AndreTen Win User
    Exactly. *Cool
    MS will disable it in the next builds, at least that is what they told..
     
    AndreTen, Jun 30, 2017
    #81
  7. bro67 Win User
    AndreTen, I think that we can at least now state to enable Firewall protection full time on any system, whether it is running Linux, Mac OS or Windows. When troubleshooting problems, we are all going to have to remember to address the issue of if a person has a firewall enabled and make sure that everyone asks what security software they are running also. The fact that if someone blocks or disables Netbios and/or SMB ports, it will break the system.
     
    bro67, Jun 30, 2017
    #82
  8. Hydrate Win User

    New global ransomware attack hits East Europe and spreading

    I have extremely strict firewall rules that disables NetBIOS and SMB completely, I absolutely agree. I don't use those protocols and it's not necessary.

    f14tomcat, I legitimately thought you were trying to be a smarty pants and prove me wrong otherwise and I mistakened it for not being a genuine advice based question. *chuckle


    You dismiss Petya's attack vector too simply.

    If there is an admin with admin$ shares enabled, connected to other clients or hosts OR SMB v1 enabled AND OR NetBIOS enabled, petya will have a feast on the network and scan for lateral infection. Anyone with a share is a possible target from a PSEXEC remote file execution and infecting the system (target user needs administrative privileges). Windows Management Instrumentation command-line is also a method used to propagate itself on the local network as well if PSEXEC fails.

    Petya utilizes ports 137, 138, 139 and 445 being outbound and inbound on another local, outbound connections must be blocked or restricted to by application demand.

    Then you have nothing to worry about, regardless of having a router with basic set up.

    Shares will be accessed, so it is a pertinent threat to home users once infected.
     
    Hydrate, Jun 30, 2017
    #83
  9. Wynona Win User
    I've seen quotes here and there that SMB1 was no longer enabled since March, but when I went in to check, it was enabled in my machine and I had to manually disable it. So, someone must have gotten the wrong information . . .

    Whoops! Gotta check out both of the Laptops and the other partition on this desktop. I'm pretty sure they'll have SMB1 enabled too. *Sad
     
    Wynona, Jun 30, 2017
    #84
  10. Wynona Win User
    Thanks, Hydrate! Alls I can say is that it's a good thing I don't have to do anything; otherwise I'd prolly be a goner! *Sad
     
    Wynona, Jun 30, 2017
    #85
  11. Wynona Win User
    I don't know if anyone has thought about this one, or if it could present a problem, so I'll just throw it out here to see what y'all think about it . . .


    New global ransomware attack hits East Europe and spreading [​IMG]
     
    Wynona, Jun 30, 2017
    #86
  12. Tony K Win User
    I have mine set on and "PCs on my local network, and PCs on the Internet" on my Insider builds only, for I have no personal files there. I set it to off on my CU partition. I'll wait a bit longer for that to update to the next OEM Fall release. Although, they state that it's safe, I don't trust hackers so far as my CU is concerned.

    Windows Update Delivery Optimization: FAQ
     
    Tony K, Jun 30, 2017
    #87
  13. Steve C Win User

    New global ransomware attack hits East Europe and spreading

    Should home users be blocking those ports and NetBios and if so, what's the best way of doing this?
     
    Steve C, Jun 30, 2017
    #88
  14. Steve C Win User
    SMB 1.0 was on by default on all three W10 PCs I have.
     
    Steve C, Jun 30, 2017
    #89
  15. Tony K Win User
    You mean to say it was an Accounting Software Company in Ukraine, yes? At least that was in the articles linked in the OP. Have you found otherwise?

    So far as accusations that Russians being a “big state sponsors of cyberattacks”; Not doubting that, but how about our own government with possible attacks and proven hacking to spy on we citizens? Or any country for that matter. Isn’t that an attack on our privacy? That’s the whole motive using EternalBlue and other spyware. Thank our government for their insecure systems to ultimately give these idiots the tools they needed.

    Anywho, here’s a report from MS:

    New ransomware, old techniques: Petya adds worm capabilities Windows Security
     
    Tony K, Jun 30, 2017
    #90
Thema:

New global ransomware attack hits East Europe and spreading

Loading...
  1. New global ransomware attack hits East Europe and spreading - Similar Threads - global ransomware attack

  2. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Ransomware attack on my pc. All my files such as photos, videos, apps, xlxs, pdf and every thing are encrypted. every file extension shown as *YGKZ format and could not open anything. ID appears to be an online ID encryption. how do i resolve this....
  3. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: I downloaded one file which was containing viruses and now all my Data is encrypted with .omfl extension and i have very important files on my pc. how to recover all file https://answers.microsoft.com/en-us/windows/forum/all/ransomware-attack/305c4fbf-4a2e-4293-9c35-a3bf07f3602d
  4. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Ransomware has attacked my pc. I cant do anything.please help https://answers.microsoft.com/en-us/protect/forum/all/ransomware-attack/f0b64b4b-ea69-4af7-bb37-4f5e4a9ce363
  5. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: I have been attacked by ransomware. Is there any way to remove and decrypt the files? Or I have to completely format my hard drive? Seeking attention to Microsoft community. I have attached some screen shots. I am not sure about the ransom type yet. [IMG] [IMG]...
  6. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Hello guys, i have a problem and i need help. to cut the long story short, my computer is infected with a ransomware (with ''nelasod'' extension on all docx, xlx, ppt and videos files). This has made it difficult to open any of my document in my external hard drive. It seems...
  7. Ransomware Attack ( .TRO)

    in AntiVirus, Firewalls and System Security
    Ransomware Attack ( .TRO): Hi all, I have a few questions regarding the ransomware attack. Most of my files format were changed to (.tro), is there a way to decrypted the files back to their original format? if possible then can anyone share how to do it? Thanks in advance for your response....
  8. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: Hello Dear all hope that you all doing well. Somone just hacked my pc.my all files stored on hard drive is converted to PPTX.how can i fix it. https://answers.microsoft.com/en-us/protect/forum/all/ransomware-attack/659f8e54-0800-4449-95f0-94604fae69f6
  9. New Ransomware attack

    in AntiVirus, Firewalls and System Security
    New Ransomware attack: Only 5 days out and Win10 being screwed with. This link was in an E-Mail today: New Windows 10 scam will encrypt your files for ransom | ZDNet 12608
  10. Bad Rabbit ransomware: A new variant of Petya is spreading

    in Windows 10 News
    Bad Rabbit ransomware: A new variant of Petya is spreading: Bad Rabbit, a ransomware infection thought to be a new variant of Petya, has apparently hit a number of organisations in Russia and Ukraine. In a tweet, Russian cybersecurity firm Group-IB said that at least three media organisations in the country have been hit by...