You are on page 1of 3

WannaCry Ransomeware

WannaCry Ransomeware
WannaCry 12
Ransomware

( 300 )
.


)Server message Block( SMBv2
( )MS17-010 14 .2017
WannaCry Ransomware
:

.1
( )MS17-010 :
https://technet.microsoft.com/en-us/library/security/ms17-010.aspx
.2
.
Ransom.cryptXXX
WannaCry Ransomeware
Trojan.Gen.8!cloud
Trojan.Gen.2
Ransom.WannaCry

.1 Firewall ( Port UDP 137, 138 and TCP


.)139, 445
.2 RDP- Remote Desktop Protocol .
.3 SMBv1
( )MS17-010
:
https://support.microsoft.com/en-us/help/2696547
.4 Signature ( )IPS
:
)21179 (OS Attack: Microsoft Windows SMB Remote Code Execution 3
)23737 (Attack: Shellcode Download Activity
)30018 (OS Attack: MSRPC Remote Management Interface Bind
)23624 (OS Attack: Microsoft Windows SMB Remote Code Execution 2
)23862 (OS Attack: Microsoft Windows SMB Remote Code Execution
)30010 (OS Attack: Microsoft Windows SMB RCE CVE-2017-0144
)22534 (System Infected: Malicious Payload Activity 9
)23875 (OS Attack: Microsoft SMB MS17-010 Disclosure Attempt
( 36195 System Infected: Ransom.Ransom32 Activity

:

.
.
.
.

:
NCSC@CITRA.GOV.KW

You might also like