Apprehended in the wild and scrutinized by members of Cisco’s industry leading Talos threat intelligence team, the early strain of WannaCry comprises a malware payload which depolys ransomware on an infested host computer. It scans comprehensively over TCP port 445 and can employ a susceptibility existing in some unpatched Windows OS running devices. WannaCry has the capability to spread all over a network, comparable to a worm, causing pervasive infestations.

This blog post outlines how clients can utilize Cisco security solutions to protect their company networks and devices against this malware and its probable alternatives that are anticipated in the near future.

Infection Identification 

The preliminary strain of WannaCry malware depends on on the Server Message Block (SMB) protocol to contaminate and proliferate devices operating MS Windows on the corporate network. By utilizing Cisco Stealthwatch, network operators can screen SMB movements inside the corporate network.  

  • Cisco Stealthwatch has built in reports which can specially track and provide reports on SMB traffic amongst in-house host computers and Internet-based hosts, which is a warning of systems infested with WannaCry.
  • WannaCry malware also employs SMB traffic to proliferate inside. SMB traffic in use by hosts on the same subnet is identified as a distrustful activity by Stealthwatch.
  • Stealthwatch has quite a few warnings based on doubtful SMB activity. To be exact, high SMB traffic and SMB connections to many dissimilar hosts. This gives a simple suggestion of hosts affected with WannaCry.
  • Stealthwatch also has the ability to find and report on connects to the TOR network, Bogon IP addresses, and the known command and control hosts. 
  • Host communications with the TOR network and Bogon IP addresses are identified by Stealthwatch based on the constantly updated threat intelligence feeds. This enables security personnel to find any in-house IP which is connecting to doubtful hosts on the Internet.

Propagation Identification  

The preliminary strain of WannaCry malware will attempt to proliferate inside the network laterally (from host to host) in an effort to infest as many hosts as it can. This proliferation action has been seen sometimes even before the malware has triggered its ransomware payload. Stealthwatch is intended to identify all such lateral movements, particularly amongst systems existing on the same subnet.

  • Any scouting and scanning activities, even amongst systems existing on the same subnet, is trackable by Stealthwatch.
  • The Stealthwatch Worm Propagation identification report tracks and associates scanning activities with effective connections to outside command and control hosts, which is in line with activities from WannaCry and other worms. 

Association  

Cisco Stealthwatch will associate dissimilar activities seen on a particular host computer and mark that IP as being suspect based on numerical scores connected to each scrutiny. Stealthwatch then accrues those scores under one index for each respective host IP address and raises a warning called Concern Index. The higher this concern index numerical value is, the more likely the host is participating in malevolent activities.

Scoping and Extenuation

Using the Cisco Stealthwatch Management Center and dashboards, you can simply create a report to list all systems which show suspicious activities and likely contamination. With Cisco Identity Services Engine (ISE) assimilation, you can then isolate suspected devices, stopping the further spread of WannaCry until the time when the threat has been fixed.

Halt the WannaCry Tears

WannaCry is causing chaos across the Internet, and we are likely to see variations for many years to come. Using the universal visibility and cutting-edge analytics of Stealthwatch, you can identify WannaCry activities in a timely manner and react to halt them from spreading all over your network.

To learn more about protecting your network from WannaCry, click here.

To speak with one of our Licensing Specialists, please click here.