Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Ad icon
Sell your Land, House on idamata.lk for FREE
sajith.xp.pk
Updated:
Yesterday at 9:03 AM
Handmade Character Soft Toys
anil1961
Updated:
Tuesday at 2:11 PM
Bodim.lk out now !
Manoj Suranga Bandara
Updated:
Sunday at 3:05 AM
Power Lifting Lever Belt
SkullVamp
Updated:
Jun 13, 2026
Ad icon
port.lk Domain for sale
Lankan-Tech
Updated:
Jun 13, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
Wanna Cry Rasomware
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="pereramauk" data-source="post: 21632901" data-attributes="member: 559770"><p><span style="font-size: 18px"><strong>Wanna Cry Rasomware</strong></span></p><p><span style="font-size: 18px">Since 12th Apr 2017, a Ransomware exploiting MS17-010 has been wreaking havoc worldwide.</span></p><p><span style="font-size: 18px"><span style="color: DarkOrange">Precautions to be taken</span></span></p><p><span style="font-size: 18px"><strong><span style="color: Red">1 - Patch Management</span></strong></span></p><p><span style="font-size: 18px">Ensure all Workstations and Servers have the latest Microsoft patches, especially the ones related to MS17-010.</span></p><p><span style="font-size: 18px"><strong><span style="color: red">2 - Antivirus</span></strong></span></p><p><span style="font-size: 18px">Ensure AV signatures are updated on all assets. Identify critical assets and target them first. Block IOCs on AV solution.</span></p><p><span style="font-size: 18px">Get the details with regards to the name of the malware and verify if this malware has been detected in the logs for last 1 week.</span></p><p><span style="font-size: 18px"><strong><span style="color: red">3 - IPS</span></strong></span></p><p><span style="font-size: 18px">Ensure IPS signatures are updated. Verify if the signature that can detect this vulnerability / exploit attempt is enabled and is in blocking mode.</span></p><p><span style="font-size: 18px">Get the details with regards to the name of the Signature and verify if this Signature has been detected in the logs for last 1 week.</span></p><p><span style="font-size: 18px"><strong><span style="color: red">4 - eMail Gateway</span></strong></span></p><p><span style="font-size: 18px">Ensure eMail Gateway solutions has all relevant updates for detecting possible mails that may bring the Trojan in the environment.</span></p><p><span style="font-size: 18px"><strong><span style="color: red">5 - Proxy</span></strong></span></p><p><span style="font-size: 18px">Ensure Proxy solution has updated database. Block IOCs for IP Address and Domain names on the Proxy.</span></p><p><span style="font-size: 18px">Verify last one week logs for the IOCs on Proxy and take action on sources of infection.</span></p><p><span style="font-size: 18px"><strong><span style="color: red">6 - Firewall</span></strong></span></p><p><span style="font-size: 18px">Block the IP addresses on Perimeter Firewall.</span></p><p><span style="font-size: 18px">Verify logs for last one week.</span></p><p><span style="font-size: 18px"><strong><span style="color: red">7 - Anti - APT Solutions (FireEye, Trend Micro)</span></strong></span></p><p><span style="font-size: 18px">Ensure signatures are up to date.</span></p><p><span style="font-size: 18px">Check for possible internal sources of infection and take actions.</span></p><p><span style="font-size: 18px"><strong><span style="color: red">8 - SIEM</span></strong></span></p><p><span style="font-size: 18px">Check logs to verify if any of the IOCs have been detected in 1 week logs.</span></p></blockquote><p></p>
[QUOTE="pereramauk, post: 21632901, member: 559770"] [SIZE="5"][B]Wanna Cry Rasomware[/B] Since 12th Apr 2017, a Ransomware exploiting MS17-010 has been wreaking havoc worldwide. [COLOR="DarkOrange"]Precautions to be taken[/COLOR] [B][COLOR="Red"]1 - Patch Management[/COLOR][/B] Ensure all Workstations and Servers have the latest Microsoft patches, especially the ones related to MS17-010. [B][COLOR="red"]2 - Antivirus[/COLOR][/B] Ensure AV signatures are updated on all assets. Identify critical assets and target them first. Block IOCs on AV solution. Get the details with regards to the name of the malware and verify if this malware has been detected in the logs for last 1 week. [B][COLOR="red"]3 - IPS[/COLOR][/B] Ensure IPS signatures are updated. Verify if the signature that can detect this vulnerability / exploit attempt is enabled and is in blocking mode. Get the details with regards to the name of the Signature and verify if this Signature has been detected in the logs for last 1 week. [B][COLOR="red"]4 - eMail Gateway[/COLOR][/B] Ensure eMail Gateway solutions has all relevant updates for detecting possible mails that may bring the Trojan in the environment. [B][COLOR="red"]5 - Proxy[/COLOR][/B] Ensure Proxy solution has updated database. Block IOCs for IP Address and Domain names on the Proxy. Verify last one week logs for the IOCs on Proxy and take action on sources of infection. [B][COLOR="red"]6 - Firewall[/COLOR][/B] Block the IP addresses on Perimeter Firewall. Verify logs for last one week. [B][COLOR="red"]7 - Anti - APT Solutions (FireEye, Trend Micro)[/COLOR][/B] Ensure signatures are up to date. Check for possible internal sources of infection and take actions. [B][COLOR="red"]8 - SIEM[/COLOR][/B] Check logs to verify if any of the IOCs have been detected in 1 week logs.[/SIZE] [/QUOTE]
Insert quotes…
Verification
Dawasata paya keeyak thibeda?
Post reply
Top
Bottom