Executive Summary

The WannaCry cyberattack is one of the largest on record, where organizations in more than 99 countries have been infected with a ransomware variant that spread via the EternalBlue exploit which was patched (MS17-010) in March of this year.

This attack was not sophisticated or elaborate as the media showcases. Analysis entails that the attackers were amateurs that used a publicly available exploit kit affiliated with the latest NSA hack by The Shadow Brokers. The attackers do not seem to target a specific entity. Instead, every target seems valid as it appears to be an attempt to make use of the leaked exploits in order to generate profit.

Report Recommendations

  • All Windows machines must apply the latest security updates provided by Microsoft.
  • Brief company employees regarding e-mail attachments.
  • Block access to port 445 from the WAN to your organization’s internal network.
  • Disable the SMBV1 Protocol.
  • Remove/Disconnect vulnerable and infected machines from the network.
