My wife's hospital will be hitting the news shortly

Penner
Posts: 3350
Joined: Tue Nov 29, 2016 10:00 pm

Re: My wife's hospital will be hitting the news shortly

Post by Penner » Tue Jun 27, 2017 5:07 pm

Ph64 wrote:
SilverEagle wrote:My wife is a nurse at Heritage Valley Medical Center in Beaver PA. She just called and told me that their computer system was hacked and that its locked. That means there are no medial records available for the doctors and nurses. The hackers want $300 in bitcoin. I told my wife several years ago when they went all digital with their records that it was a mistake. These hackers need to be murdered because they are putting innocent lives at risk.
Given what happened in the UK, "hacked" isn't really the right term... Typically its some moron worker who gets an email with an attachment, from someone they don't know, and stupidly opens the attachment.

Then, of course, the UK one was probably older XP systems (unpatched) or they weren't up to date (common in the medical field because of all the HIPPA rules)... The idiots machine who ran the attachment then infects everything on the network it can, and files that are on shared drives are really easy (don't even to use the unlatched SMB share bugs for that)...

Its sad, but honestly true hacks from outside are fairly rare with good firewalls/security/design. Moron users from inside opening unknown email attachments, getting infected via websites, etc, is usually where stuff comes from.

It's actually called "RansomWare" because of what you describe above.
Image

User avatar
Speaker to Animals
Posts: 38685
Joined: Wed Nov 30, 2016 5:59 pm

Re: My wife's hospital will be hitting the news shortly

Post by Speaker to Animals » Tue Jun 27, 2017 5:11 pm

I thought this was an actual worm that propagated through unsecured ports in Windows machines.

Ph64
Posts: 2434
Joined: Wed Feb 08, 2017 10:34 pm

Re: My wife's hospital will be hitting the news shortly

Post by Ph64 » Wed Jun 28, 2017 11:55 am

Speaker to Animals wrote:I thought this was an actual worm that propagated through unsecured ports in Windows machines.
Both. Only a moron would have their machine/company not behind a firewall that blocks those ports from the outside world... But once it gets inside your network it can spread fast.

So typically its a "human engineering" scam - bulk email out some infected attachments (in this case one of the articles I posted mentioned word/excel documents with VB macros, but could be a lot of things with known vulnerabilities)... And once some user opens that attachment inside your network, well, you're fucked if the things/ports its trying to take advantage of are unpatched on your internal machines.

It almost always gets in by the ID10T method though. :evil:

User avatar
The Conservative
Posts: 14719
Joined: Wed Nov 30, 2016 9:43 am

Re: My wife's hospital will be hitting the news shortly

Post by The Conservative » Wed Jun 28, 2017 2:02 pm

Ph64 wrote:
Speaker to Animals wrote:I thought this was an actual worm that propagated through unsecured ports in Windows machines.
Both. Only a moron would have their machine/company not behind a firewall that blocks those ports from the outside world... But once it gets inside your network it can spread fast.

So typically its a "human engineering" scam - bulk email out some infected attachments (in this case one of the articles I posted mentioned word/excel documents with VB macros, but could be a lot of things with known vulnerabilities)... And once some user opens that attachment inside your network, well, you're fucked if the things/ports its trying to take advantage of are unpatched on your internal machines.

It almost always gets in by the ID10T method though. :evil:
If the firewall is put up right, it should never have allowed said attachments through in the first place.
#NotOneRedCent

Okeefenokee
Posts: 12950
Joined: Wed Nov 30, 2016 10:27 pm
Location: The Great Place

Re: My wife's hospital will be hitting the news shortly

Post by Okeefenokee » Wed Jun 28, 2017 10:56 pm

IT dropped the ball?

Image
GrumpyCatFace wrote:Dumb slut partied too hard and woke up in a weird house. Ran out the door, weeping for her failed life choices, concerned townsfolk notes her appearance and alerted the fuzz.

viewtopic.php?p=60751#p60751

User avatar
The Conservative
Posts: 14719
Joined: Wed Nov 30, 2016 9:43 am

Re: My wife's hospital will be hitting the news shortly

Post by The Conservative » Thu Jun 29, 2017 3:47 am

Okeefenokee wrote:IT dropped the ball?

Image
Pfft, I wish... I've spent 9 months fixing the shit that the old IT screwed up.

By august everything will be exactly where I need it to be. No more BS, and chances of this shit happening.
#NotOneRedCent

3knuckleshuffle
Posts: 47
Joined: Thu Dec 08, 2016 3:54 pm

Re: My wife's hospital will be hitting the news shortly

Post by 3knuckleshuffle » Thu Jun 29, 2017 4:03 am

This one doesn't appear to be spreading via attachments (this is from our internal security center, so take with a grain of salt, but we are a huge retailer, so they have a lot of people following it):
Using a tweaked version of Mimicats (security auditing tool), which is able to obtain hashed credentials from RAM, the ransomware was able to spread via PSEXEC and WMIC laterally within a network along with exploiting the MS17-010 (ETERNALBLUE) SMB vulnerability.
At this time, there is no proof this was spread by phishing emails and/or with attached Word documents.
· This isn’t ‘Petya’ or ‘Petyawrap’ ransomware; a new variant called ‘NotPetya’ which utilizes different encryption and attack methods but uses similar base code
Luckily, it is super easy to vaccinate, as long as you can distribute files easily:
The ransomware includes a "vaccine" where it looks for the presence of a file named, "C:\Windows\perfc" and if it is present, it exits instead of proceeding with the infection. Creating this file will prevent infection even on systems that would otherwise be vulnerable.

User avatar
The Conservative
Posts: 14719
Joined: Wed Nov 30, 2016 9:43 am

Re: My wife's hospital will be hitting the news shortly

Post by The Conservative » Thu Jun 29, 2017 7:12 am

3knuckleshuffle wrote:This one doesn't appear to be spreading via attachments (this is from our internal security center, so take with a grain of salt, but we are a huge retailer, so they have a lot of people following it):
Using a tweaked version of Mimicats (security auditing tool), which is able to obtain hashed credentials from RAM, the ransomware was able to spread via PSEXEC and WMIC laterally within a network along with exploiting the MS17-010 (ETERNALBLUE) SMB vulnerability.
At this time, there is no proof this was spread by phishing emails and/or with attached Word documents.
· This isn’t ‘Petya’ or ‘Petyawrap’ ransomware; a new variant called ‘NotPetya’ which utilizes different encryption and attack methods but uses similar base code
Luckily, it is super easy to vaccinate, as long as you can distribute files easily:
The ransomware includes a "vaccine" where it looks for the presence of a file named, "C:\Windows\perfc" and if it is present, it exits instead of proceeding with the infection. Creating this file will prevent infection even on systems that would otherwise be vulnerable.

Fire their asses....

MS17-010 (ETERNALBLUE) SMB vulnerability was a known issue March 14, 2017. The fact this wasn't patched when it was found out, my god... what the hell were they waiting for... oh wait... it happened.

https://technet.microsoft.com/en-us/lib ... 7-010.aspx
#NotOneRedCent

User avatar
Speaker to Animals
Posts: 38685
Joined: Wed Nov 30, 2016 5:59 pm

Re: My wife's hospital will be hitting the news shortly

Post by Speaker to Animals » Thu Jun 29, 2017 7:13 am

This is what happens when you don't maintain a strict regime over your IT slaves.

It usually happens if there are not enough software engineers in the company to explain to management how to properly manage these knuckle draggers.

User avatar
Speaker to Animals
Posts: 38685
Joined: Wed Nov 30, 2016 5:59 pm

Re: My wife's hospital will be hitting the news shortly

Post by Speaker to Animals » Thu Jun 29, 2017 7:15 am

Okeefenokee wrote:IT dropped the ball?

Image
Image