ZeroHour
Security Affairspublished ()ingested @securityaffairs

Wannacry, the hybrid malware that brought the world to its knees. Let’s not forget!

highMalwareimportance 47CVE-2017-0144

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-0144
Remote Code Execution in Microsoft SMBv1 (EternalBlue) affecting Windows and Siemens devices

CVE-2017-0144 is a remote code execution flaw in the SMBv1 server component of Microsoft Windows, commonly known as EternalBlue, and one of the SMB flaws fixed by Microsoft in the March 2017 MS17-010 bulletin. An attacker who can reach the SMB service over the network sends specially crafted packets that trigger memory corruption in the SMBv1 implementation, gaining the ability to execute arbitrary code on the target without user interaction. Successful exploitation yields full system compromise and has been heavily weaponized for wormable spread and ransomware delivery, notably via the leaked NSA exploit and in the WannaCry/NotPetya-era outbreaks, and the flaw has repeatedly been bundled into botnets and ransomware tooling since. Anyone running unpatched Windows Vista SP2 through Windows 10 1607 / Windows Server 2016 with SMBv1 enabled is affected, as are Siemens medical and laboratory devices (ACUSON ultrasound, syngo SC2000, Tissue Preparation System, VERSANT kPCR systems) whose firmware depends on SMBv1. Exploitation is actively ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-10) with known ransomware use, carries a 99.2% EPSS exploitation probability (100th percentile), and multiple public exploits and PoCs are available.

Do: Apply the Microsoft MS17-010 (March 2017) security updates on every listed Windows version and the corresponding Siemens firmware updates for ACUSON, syngo SC2000, Tissue Preparation System, and VERSANT kPCR devices, per CISA's required action to apply vendor updates. Where patching is not yet possible, disable SMBv1 or block inbound TCP 445 (and UDP 137/138) at network boundaries and isolate legacy/medical systems from the internet. Sweep exposed and legacy hosts for compromise indicators, including DOUBLEPULSAR implants delivered over SMB, as public tooling for detecting and neutralizing this implant is available.

8.899% KEV ransomware PoC ×6
  • microsoft Windows SMBv1 server (Server Message Block) Windows Vista SP2; Windows Server 2008 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012; Windows Server 2012 R2; Windows RT 8.1;
  • siemens ACUSON P300 firmware
  • siemens ACUSON P500 firmware
  • +6 more
massorder of hundreds of thousands of internet-exposed SMB endpoints, and millions of unpatched Windows systems when internal enterprise and medical-device…

Indicators of compromiseAll →

TypeIndicatorContext
domainwww.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.comrified that a public site was in fact non-existent: “hxxp://www[.]iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com” Only the registration of this domain subsequently crea
urlhttp://www[was verified that a public site was in fact non-existent: “hxxp://www[.]iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com” Only the
Full article1,054 words · extracted from securityaffairs.com · click to collapse

Reflecting on the Wannacry ransomware attack, which is the lesson learnt e why most organizations are still ignoring it.

In the early afternoon of Friday 12 May 2017, the media broke the news of a global computer security attack carried out through a malicious code capable of encrypting data residing in information systems and demanding a ransom in cryptocurrency to restore them, the Wannacry ransomware.

Italy was also marginally affected by the attack and the case was dealt with by the Computer Crime Operations Centre of the Postal Police (CNAIPIC) https://www.commissariatodips.it/profilo/cnaipic/index.html, which promptly issued an alert https://www.commissariatodips.it/notizie/articolo/attenzione-false-e-mailmessaggi-relativi-ad-assunzioni-in-enel-green-power/index.html on the very day of the event, recommending some useful actions also to prevent further possible propagation.

The ransomware, as reported in the Microsoft bulletin https://www.microsoft.com/en-us/security/blog/2017/05/12/wannacrypt-ransomware-worm-targets-out-of-date-systems/, once transmitted by e-mail using phishing and social engineering methods or directly from the public network by exploiting a protocol flaw in the connected devices, proceeded:

  • encrypt computer data, using RSA public key asymmetric encryption techniques;
  • multiply in the affected network, through an NSA code called EternalBlue, which exploited a vulnerability in the network file sharing protocol SMB (Server Message Block) used by Microsoft Windows systems.

The infection chain

The infection chain was divided into four stages:

  1. The malware was installed through a dropper, a program executed by opening an attachment to a deceptive e-mail, probably a fake pdf or doc file, or executed directly from the Internet, without user interaction, exploiting the exploit described in the point 4.
  2. The dropper, once copied on the computer, attempted to connect to a site and only if the connection failed, proceeded to install two components, a cryptolocker and an exploit.
  3. The cryptolocker had the task of encrypting the data of the affected system;
  4. The exploit was to infect the victim’s local network, if not properly updated, through the SMB protocol vulnerability.

Cryptolocker and exploit components

The encryption scheme implemented by WannaCry used an asymmetric encryption mechanism based on a public and private key pair generated using two prime numbers. The public key was used to encrypt the data of the affected system, while the private key was the object of the blackmail.

The operating algorithm was RSA. Its effectiveness was basedis based on the mathematical principle according to which it is easy to calculate the product of two even very large prime numbers, but the reverse process, i.e. decomposing the product to find which two prime numbers are used as factors, is much more difficult.

In order to spread the ransomware within the victim’s network, the exploit component exploited a flaw in version 1 of the SMB (Server Message Block) protocol used in some Microsoft operating systems and intended to provide shared access to files, printers, serial ports and various communications between network nodes. In this way, Wannacry spread over the affected networks in the same way as a worm does:

  • In fact, the first phase of the infection was conducted via an executable that scanned the network on TCP port 445 of the SMB protocol for vulnerable Windows systems.
  • In the second phase, once access was gained to a computer, the malware would create and execute a copy of itself on the system.In the second phase, once access is gained to a machine, the malware creates and executes a copy of itself on the system.

Since the SMB protocol flaw, catalogued by the Common Vulnerabilities and Exposures under the number CVE-2017-0144, allowed the execution of arbitrary code by remote users locally, if the operating system in question had not been updated with the Microsoft security patch MS17-010 https://learn.microsoft.com/en-us/security-updates/SecurityBulletins/2017/ms17-010?redirectedfrom=MSDN , the success of the attack was achieved precisely because the affected operating systems had not been updated beforehand.

Why did the creators of Wannacry choose bitcoin for the ransom payment?

For the ransom payment, Wannacry required the use of the cryptocurrency bitcoin. In fact, the familiar red lock screen launched by the @[email protected] program and appearing on the monitors of infected PCs showed a detailed guide on how to make the payment transaction on the wallet, identified by a string of 34 alphanumeric characters.

https://www.blockchain.com/btc/address/13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94

https://www.blockchain.com/btc/address/12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw

https://www.blockchain.com/btc/address/115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn

Although this transaction was absolutely transparent and traceable, it did not allow the account holder to be traced, precisely because of the typical peculiarities of digital currency: anonymity, transparency, speed and non-repudiation.

How did the contagion stop?

The malicious code only proliferated if it was verified that a public site was in fact non-existent:

“hxxp://www[.]iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com”

Only the registration of this domain subsequently created the condition (kill swich) for the malware to stop spreading.

The spread of this ransomware was considered to be the worst cyber attack in terms of contamination rate and scope, putting public offices and companies (especially healthcare facilities) out of operation.

What should we learn from this?

In order to mitigate the risk of exposure to malware threats and improve security, it would be advisable, at all levels, to adopt a policy of precautionary behaviour, to ensure the periodic patching of computer systems, but above all to share with everyone the information that has come to light. Indeed, every discovery is worthless if it is not made available to others.

Certainly Wannacry, with its global spread, marked a breaking point by laying the foundations for a new way of conceiving what would be future ransomware attacks.

Unfortunately, contemporary events seem to confirm this.

To restore functionality without having to decrypt files and pay a possible ransom (not recommended), it is always advisable to adequately safeguard backups, adopting backup strategies according to the 3-2-1 rule: keep at least 3 copies of company data in 2 different formats, with 1 copy offline and located off-site.

To try and prevent cyber attacks including ransomware, it is always a good idea to keep systems up-to-date, activate 2FA authentication for access, use reliable antivirus software and always keep your guard up (awareness).

About the author: Salvatore Lombardo

Electronics engineer and Clusit member, for some time now, espousing the principle of conscious education, he has been writing for several online magazine on information security. He is also the author of the book “La Gestione della Cyber Security nella Pubblica Amministrazione”. “Education improves awareness” is his slogan.

Twitter @Slvlombardo

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Wannacry)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/137894/cyber-crime/wannacry-hybrid-malware.html