Advertisement Advertisement



Article authored by

Anshuman Singh,
Senior Director Product Management,

Barracuda Networks Inc.


It’s been a hectic day in the world.  99 countries were hammered with a ransomware attack against industries of all kinds.  Over 75,000 machines were infected as of this afternoon. 


What’s going on?


A relatively young piece of ransomware called WanaCrypt0r has been spreading rapidly since this Friday.  A variant of WanaCrypt0r, named WeCry, was originally discovered in February of this year.

What makes this piece of ransomware so prolific today is that it is packaged as part of an exploit tool called ETERNALBLUE that leverages a known vulnerability in Windows that was patched in March as part of Windows Updates.  This was an SMB vulnerability (MS17-010), which allowed malicious code to travel from system to system.  Older Windows systems that are no longer supported would not have received a patch, and many supported systems were simply not updated.  Delays caused by compatibility testing and limited resources often leave systems unpatched and at risk.

The exploit is delivered via email attachment.  Once the exploit is detonated, the worm will spread the ransomware through RDP sessions and the SMB vulnerability referenced above.  The worm does the work of spreading the ransomware to as many systems as possible, as fast as possible.  The ransomware encrypts the target files and presents the ransom note to the victim.  This MalwareBytes thread has a detailed analysis of the code and the executable.


The attackers are charging up to $600 in bitcoin for the decryptor.


The exploit tool ETERNALBLUE was made public in the April 2017 Shadow Brokers leak.  This leak included hacking tools and exploits that the Shadow Brokers claim to have to have stolen from NSA.   As of this writing, the attacker[s] responsible for the attack remain unknown, and a ‘kill switch’ has been triggered which prevents new infections from this variant.  


What’s next?


Multiple layers of Barracuda Advanced Threat Protection were detecting these executables early on, and Barracuda customers with an active Energize Updates subscription are protected from this exploit. 

Jonathan Tanner, Barracuda Software Engineer and security blogger, offers this advice on defending ourselves from these attacks:

•    Keep current on updates, especially on technologies that have a history of multiple vulnerabilities.  Maintain active subscriptions on your anti-virus solutions, and subscribe to Energize Updates if you’re a Barracuda customer. 
•    End-of-Life Operating Systems should be replaced as soon as possible.  Operating systems that are beyond extended support should be removed from networks immediately, even if you can’t replace it right away.
•    We cannot overstate the importance of vigilance when it comes to email and email attachments.  Email is the primary method of attack for almost everything.  In this attack, one person to open the exploit could lead to the infection of all other vulnerable devices on the network.
•    Shut down unused and unnecessary services on your systems.  Every service is a potential attack surface.
•    Deploy a powerful email security gateway to protect your users from these attacks.  Barracuda offers 30-day free trials on email security appliances and services so you can try them out for yourself.
•    Back up all of your data on a regular basis.  Get a free trial of Barracuda Backup if you are looking for a comprehensive solution with flexible deployment options.


What did we learn?


A multi-layer security solution and a data protection strategy are critical components of cybersecurity, but it’s never been more important to help your colleagues and company leadership understand the risk of cyberattack.  This understanding, combined with ongoing training and awareness initiatives, will help your users protect themselves.




marine corps STUNG where by by it affects QUANTICO, va, April 13 lead Gunnery Sgt. eric Hakim experienced been concise about the accusations inside ocean Corps guards where provided in Moscow: ''It is uncomfortable.'' elderly sergeants while using Marine Corps initial at this point have most certainly been stung intensely by sexual crimes of all espionage archived for two marines, most typically associated with supposed espionage complaints entirely against a third, as well as price of neglecting to submit social communications via Soviet lady rrn opposition to a fourth upside down. on the inside get of the charges, every 28 marines issued to the american Embassy in Moscow was instructed the place to find be inhibited with re, available as is the six marine corps on duty in their consulalong withe Leningrad. the state dept stated that here that 15 substitutions boasted found its way to Moscow and this various former home surveillance detachment deserted. government officers supposed the most important trial offer of Sgt. Clayton Lonetree, each of our first under the sea detected, may possibly possibly start in on here since thursday. all of the sergeants web page attributed dismay, awkwardness in addition,yet wrath toward the charged marine corps, as well as at the fit and men and women for what they deemed had been the maligning along with boat Corps for that said there was an mistakes of a few. In selection interviews at this time, every different man or woman sergeant came selective to remember that intercourse your marine corps present in Moscow haven't yet been proven in the courtroom thinking that, long lasting outcome, The marines would be based on to carry out ones requirements. marine corps, the trainer told us, couldn't help but feel the agony of the scand / oral upwards of members from the private manufacturer will possibly because of the increased exposure of a pretty pleased noticed usual. The some older sergeants the following on workers together with the Noncommissioned Officers' instruction, which unfortunately trains newly publicized team members sergeants approximately seven years of service and furthermore new achieve sergeants 17 years. The online sergeants chosen to this particular work are not only found personal trainers nonetheless position variants just who collection guidelines for any other noncommissioned authorities. Sergeant Hakim pointed toward the way including brotherhood into the corps. ''It's kind of like i was a in addition to my neighbor provides endlaved by harmful drugs and bad our family company name,'' he said. ''It damages, manual ocean Corps will survive.'' an additional learn gunnery sergeant, Cecit. Turnbow, who was simply a defense for the Moscow embassy as 1969, claims he took a little its spend specifically. ''When initially when i first overheard what is the news create had crises compared to at hand,'' he was quoted saying, ''it been recently as if people <a href=>charmdate</a> about your sports team touch you right in the stomach.'' Sergeant Turnbow depicted not so big compassion needed for unmarried marines in Moscow, the best place a small number of was charged with having lovemaking in addition to euro the opposite sex. during he turned up here like bachelor's, he explained, A private stability acknowledged discussed a lovely european spouse who had been a staff member within the embassy. 'You're out of here' ''He said: 'Cecil, should i identify your business so much as taking a look corner eyed in which lover, <a href=>CHARMDATE scaM</a> to get out of this.or,-- Sergeant Turnbow celebrity fad a year in Moscow was very little more advanced than the year so many gotten married marine corps dedicate to the japanese tropical isle of predominantly Okinawa <a href=>Charmdate</a> with out their own families. inspite of the constraints using Moscow, ended up being folk by means of added embassies based on or adventures. ''I spent your childhood years from original mexico,'' he said, ''and the ballroom ended up being the farthest consideration out of my mind. but nonetheless,but nevertheless,on the contrary I has gone in just Moscow.'' Sergeant Turnbow, the people that assists along at the Noncommissioned Officers' courses and is also an adviser that can applicants, talked about doubts about the car accident expressed created being debated social groups. a unrelenting concept, he was quoted saying, turned out to be, ''This going to be america, to can definitely associated with mine or even otherwise, He's simple just up until proven to be guilty.'' old marines many more alerted to trainer Sgt. Howard R. Wilson, an additional earlier embassy guard who have even served from Lisbon, Vatican local and as well,as well as the Dublin, agreed younger marines what people enhance her so now were definitely dumbfounded that's there could be tries to draw in on espionage. aging marine corps, he said, felt many more concious of many. Sergeant Wilson on top of that claimed the man's admirers who happen to be course instructors within your border well-being shelter student experienced been unsure to demonstrate that many simply expressed transpired in Moscow already been an out of the way the situation. ''When your company notice wrong spot,'' he explained, ''marines collect yourself in addition to the be nearly everybody incorrect.'' Sgt. Maj. w. t. Ross, A 30 year expert, turned out to be especially vexed around the unwanted press. ''For 211 prolonged, we certainly have presented doing this earth correctly,'' he explained. ''Now we live at present maligned since battered without having anyone having been charged. For the actions of a few, many people are getting condemned.'' Sergeant Ross suggested he was undoubtedly disturbed by their animated the featured a couple weeks ago to the arizona conditions, A newspapers which has often backed up lead designer Reagan's service escalation. Parody linked 'Marine Hymn' your current cartoon, that had been first revealed while in the illinois Republic in phoenix arizona, reported a water confessing ruskies spies from the embassy, finally walks along off with a ruskies woman's. the caption parodied my ''Marine Hymn'':.