Massive outbreak of ransomware variant infects large amounts of computers around the world
ID: 69798d0b-46fa-5755-b217-911a32bfc397
STIX ID: report--69798d0b-46fa-5755-b217-911a32bfc397
Feed Name: Fox-IT blog
On May 12, 2017 a global WannaCry ransomware campaign exploited the Windows SMB vulnerability (MS17-010/ETERNALBLUE) to self-propagate and encrypt files across internal networks; the report documents the large-scale impact, discovery of a hardcoded kill-switch domain that temporarily halted execution, Tor-based C2 onion addresses, Snort detection rules, recommended mitigations (apply MS17-010, disable SMBv1, isolate unpatched systems, verify backups), and other IoCs and behavioral details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
