Top Banner
Ransomware wannacry Mikel Solabarrieta
19

Ransomware: Wannacry

Jan 22, 2018

Download

Technology

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Ransomware: Wannacry

Ransomwarewannacry

Mikel Solabarrieta

Page 2: Ransomware: Wannacry

RansomwareIt is a type of malicious software that will take your important

files, encrypt them and then it will blackmailing you to pay for get them back.

- this is the new oil, for the bad guys -

Page 3: Ransomware: Wannacry

Very nice business

Page 4: Ransomware: Wannacry

Wannacry

● Affected more than 150 countries.

● Infected major businesses and organizations.

● More than 200,000 systems around the world are believed to be infected

Black Friday - May 12, 2017

Page 5: Ransomware: Wannacry

Which organizations were affected?

Page 6: Ransomware: Wannacry

Some epic images

Page 7: Ransomware: Wannacry

How much money wannacry ask you?

● Between the first three days = $300 ● Between the next three days (extra chance) = $600

- After seven days without payment, the malware will delete all of the encrypted files and all data will be lost. -

Page 8: Ransomware: Wannacry

How does wannacry’s message look like?

Page 9: Ransomware: Wannacry

How does it get to you?

● Hosts can get infected downloading for example PDFs or any kind of other files that hide the malware. Normally those are sent via email or accessing to a url.

● Another host in the same network can exploit a vulnerability (SMBv1) and install the malware on it.

Page 10: Ransomware: Wannacry

Hard to reach the first one, then easy to reach hundreds...

● NSA leakage on April, 17 2017.● The Shadow Brokers.● Some exploits unknown until that time.● Ethernalblue. SMBv1 (Microsoft Server Message Block 1.0)

Page 11: Ransomware: Wannacry

The cure… before the disease

Recall, NSA leakage on April 17, 2017

Microsoft solution on March 14, 2017

Page 12: Ransomware: Wannacry

Wannacry is using Ethernalblue

Page 13: Ransomware: Wannacry

How do prevent it?

● Install the security patch MS17-010.

● Monitor traffic over port 445 in the firewall.

● Block the port 445 (SMBv1) by host.

● Keep your system up-to-date.

Page 14: Ransomware: Wannacry

The kill switchTwo britain guy were “The accidental heroes”

Page 15: Ransomware: Wannacry

What about the money?

Page 16: Ransomware: Wannacry

What about the money?

Page 17: Ransomware: Wannacry

What about the money?

Page 18: Ransomware: Wannacry

What about the money?

91.901,43 USD in one week

Page 19: Ransomware: Wannacry

Thanks