ISC StormCast for Monday, May 15th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 May 2017
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, Main 15th, 2017 edition of the Sansandet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from San Diego, California. |
| 0:12.5 | On Friday, the ransomware warm Wanna Cry or Wanakrip started to spread rapidly across some large organizations worldwide. |
| 0:23.6 | It is unclear if it originally was ceded to these organizations via email, |
| 0:29.6 | or if it just spread using the S&B version, One Eternal Plurul vulnerability. |
| 0:36.6 | But either way, it's rapid propagation inside corporate networks |
| 0:42.1 | can be attributed to the use of the Eternal Blue exploit. |
| 0:46.7 | This exploit was released mid-April by Shadowbroker, |
| 0:51.3 | who allegedly stole the exploit from the NSA. |
| 0:56.0 | Microsoft had originally released a patch for this vulnerability in March as MS-1710 |
| 1:03.0 | for currently supported versions of Windows. |
| 1:07.0 | On Friday, however, Microsoft also released a patch for older versions of Windows going back to Windows XP and 2003 server. |
| 1:17.6 | We also saw a significant increase in Port 445 scanning around the time the ransomware started to spread, but it isn't really clear if this was the cause or the effect of the warm spreading. |
| 1:34.3 | Just like other ransomware, Wanna Cry will encrypt files and display a screen instructing users to pay a ransom via Bitcoin, encrypted files will use the extension WN |
| 1:47.8 | Cry, which led to the Malaver being named with Wanna Cry or Wanna Crypt. |
| 1:55.8 | In addition to encrypting files, the Malver then spreads to other systems using either the S&P version 1 vulnerability |
| 2:03.8 | or existing remote desktop connections. The malware also installs a double pulsar backdoor, |
| 2:12.3 | which was also included in this shadow broker release from April. |
| 2:23.5 | Ransom demands start at $300 and increase after a few days to $600. |
| 2:29.5 | It is not clear if ransom payments will result in obtaining a decryption key. |
| 2:33.2 | The process is somewhat manual and convoluted. |
| 2:42.1 | After paying the ransom, the victim has to contact the miscarience during limited business hours and to request a key. |
| 2:46.1 | The key is then handed to the victim once payment is confirmed. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

