WannaCry 2.0 ransomware attacks continue...
ID: 627917e5-7c24-5982-b827-dd7400baaaf3
STIX ID: report--627917e5-7c24-5982-b827-dd7400baaaf3
Feed Name: Zscaler Security Research Blog
Threat Score
This Zscaler ThreatLabZ report analyzes the WannaCry (WannaCrypt) 2017 ransomware outbreak: initial droppers that check killswitch domains, network propagation using the MS17-010/ETERNALBLUE SMB exploit, embedded WannaCry 2.0 payloads that install as services and encrypt user files (appending .wnry), and observed downloader variants hosted on compromised servers; it provides IoCs (MD5 hashes, domains, URLs), installation/config details, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
