Security Alert: Uiwix Ransomware Is Here and It Can Be Worse Than Wannacry

Discussion in 'malware problems & news' started by itman, May 14, 2017.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    WannaCry copycat.
    https://heimdalsecurity.com/blog/security-alert-uiwix-ransomware/#
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Just saw that. Here goes round 2
     
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Also, scroll down in the Heimdal Security link for instructions on how to disable SMB v1 in Windows. Only SMB v1 is installed on Win client versions. -EDIT- That is accessible via Control Panel -> Uninstall Programs -> Windows Features.
     
    Last edited: May 14, 2017
  4. clubhouse1

    clubhouse1 Registered Member

    Joined:
    Sep 26, 2013
    Posts:
    1,124
    Location:
    UK
    Reflects the warning by INTERPOL.
     
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
  6. clubhouse1

    clubhouse1 Registered Member

    Joined:
    Sep 26, 2013
    Posts:
    1,124
    Location:
    UK
  7. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
  8. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,010
    Location:
    U.S.A.
  9. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
  10. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    "...Later edit [May 16, 2017, 12 AM EST]:

    For the moment, we will not be adding further technical details to this article. Our researchers (as well as others) have spotted the Uiwix sample in the wild and, as a consequence, we felt the responsible thing to do is to alert users that this strain is in circulation, so they can take preemptive measures, like we advised in this guide. Our efforts to obtain and fully analyze a sample after an attack have not been successful. Should anything change, we will properly update this alert to correspond the context. The title was also edited (originally called “Security Alert: Uiwix Ransomware Is Here and It Can Be Worse Than Wannacry”).

    What’s more, researchers have already uncovered a WannaCry strain that also doesn’t include the kill switch domain.
    Also, Europol has also confirmed that the threat is escalating and the number of infections is growing. It has now affected “more than 200,000 victims in 150 countries...”

    https://heimdalsecurity.com/blog/security-alert-uiwix-ransomware/

    Now included in OP, but posted here for those who read OP before the Update.
     
  11. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Lastest on this SMB exploit ransomware:
    https://www.bleepingcomputer.com/ne...ng-eternalblue-smb-exploit-to-infect-victims/
     
  12. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,507
  13. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
  14. clubhouse1

    clubhouse1 Registered Member

    Joined:
    Sep 26, 2013
    Posts:
    1,124
    Location:
    UK
    Windows 10 Ransomware Escalation Prevention Script v1.0



    Windows 10 Ransomware Escalation Prevention Script v1.0

    This script will prevent further escalation for those who'm do not have Endpoint Protection enabled in their organization.

    Off course Windows Defender in Windows 10 can protect some, but certainly not all threats.

    # Before everything - TEST, TEST, TEST and if you alter something, TEST, TEST, TEST!!!


    https://gallery.technet.microsoft.com/Windows-10-Ransomware-ccceeb71
     
  15. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
  16. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    According to the Trend Micro analysis here: https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/Ransom_UIWIX.A , it arrives via exploit and thereafter download a .zip containing the rest of the files it needs. Appears .dll used is SQLite which most security setups would allow.
     
  17. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    MZWritescanner, makes no judgement about good or bad. It alerts that something new was dropped and blocks it until the log is cleared
     
  18. guest

    guest Guest

    Because some use it.

    Because admins are supposed to do their job aka securing their networks via applocker and GP.

    problem is most admins are total noobs in term of security...
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.