Endpoint Protection

 View Only
Expand all | Collapse all

NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

  • 1.  NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 20, 2017 04:37 AM

    Hi experts,

     

    Below information was found during I check the NTP attack.

    It looks like Microsoft SMB MS17-010 is not patch on the machine.

    But, something make me more interested is traffic has been blocked for this application is avast antivirus, so the attack actually is blocked by Symantec? or Avast?

    I believe that this computer may have avast installed, which I have no verify yet as the machine locate at different timezone from me.

    2017-06-20 16_29_43-C__Users_loh.chee_.siong_Documents_Symantec NTP_eln057 OS attack SMB ms17-010.png

     

    I'm sorry for my broken english.

     

    best regards,

    Loh



  • 2.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 20, 2017 05:30 AM

    Hi 

    It was blocked by SEP. This is a detection for attacks  against the smb protocol. The same vulnerability used by wannacry.

    You should investigate the remote IP adress. 

    My guess is that avast works as a proxy for smb traffic so SEPs logs the traffic with avast as application instead of the OS.



  • 3.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 20, 2017 05:48 AM

    Hi TORB,

    Thanks for your reply.

    I'm quickly check the remote IP address, and actually it is same for the machine itself base on logs.

    Properly full scan, patch MS, remove avast, block 445 port is the next action I should do?

     



  • 4.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 20, 2017 06:40 AM

    If you've confirmed the machine is patched than it is not vulnerable. Also, what is that remote IP? iI's an internal machie on your network so what is it doing?



  • 5.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 20, 2017 06:54 AM

    Hi Brian,

    I think the machine is not patch from what I can see in the list missing MS17-010 patch list.

    From the detection info above, the machine IP and the remote IP show the same, that's strange.

     

    The machine is a notebook, so it was use by a user for sure.



  • 6.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 20, 2017 07:03 AM

    Then I'd get a hold of it and get it patched or have it removed from the network until it can be.



  • 7.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 20, 2017 08:56 AM

    Hi Loh,

    Definitely get that computer pacthed and secured!  Just adding some information about Wannacry, which exploits that vulnreability:

    WannaCry Ransomware
    https://www.symantec.com/outbreak/?id=wannacry

    Please do keep this thread up to date with your progress!

     



  • 8.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 21, 2017 12:37 AM

    thanks for your suggestion. I will make sure get it patch.



  • 9.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 21, 2017 12:37 AM

    Hi Mick,

    Thanks for more great info sharing.



  • 10.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 27, 2017 08:57 PM
      |   view attached

    Hi Expert,

    I'm sorry for late reply, I'm away for few days.

    Status update:

    MS17-010 was patched, but still show some outbound TCP. And, Avast is confirmed install on this machine.

    I have request to uninstall it since all the outbound TCP means the attack is from this machine by Avast. But, this need to see how the local admin to contact that user as his feedback is use Avast to scan industry machine computer.

    I'm interested that why Symantec can't do the same job, hope that we have the feedback from the users.

     

    By the way, do you guys think this is very critical? Because from the severity level, it is marked critical.

    What else I should do if this user refuse to uninstall Avast? Please advise if something I can do?

     

    I'm sorry for the bad english.

    Best regards,

    Loh

     



  • 11.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 27, 2017 09:03 PM

    Hi Mick,

    I just read the info you sharing.

    It looks like with just Endpoint Protection, it is not enough to protect the corporate network to prevent the cyber security attack?



  • 12.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 27, 2017 09:42 PM

    So is SEP blocking this? I can't see from the screenshot.



  • 13.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 28, 2017 05:56 AM

    hi Brian,

    Yes, from the main post attachment. It show blocked by SEP.



  • 14.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 28, 2017 06:44 AM

    I'm confused on what the issue is? SEP is doing its job.



  • 15.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 28, 2017 08:14 PM

    Yes, SEP doing the good job.

    But, this attack keep flag everyday. So, I wish to solve it and avoid this client have chances to effect the network.



  • 16.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 28, 2017 08:18 PM

    Has the offending machine been removed from the network and addressed or re-imaged? That's the problem.



  • 17.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 30, 2017 12:33 AM

    Hi Brian,

    The computer is not remove from the network or re-image, because I think could be remove Avast maybe will fix the problem.

    So, I request to remove Avast, and my colleague is in progress working with the user.

    Do you think this is a very critical? So, I should report to my IT Manager for fast action like what you say at least remove from the network?



  • 18.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt
    Best Answer

    Posted Jun 30, 2017 07:31 AM

    SEP is doing it's job by blocking the attack so you're good here. But you need to get the malicious machine off the network.



  • 19.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 30, 2017 08:15 AM

    Hi Brian,

    Thanks for your advise. I will quickly write to check how the status in progress.



  • 20.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 30, 2017 08:18 AM

    By the way, may I know how to mark the problem solve?

    I'm sorry I can't find any.



  • 21.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jun 30, 2017 08:20 AM

    You're welcome. Let me know if you have additional questions.

    You can click the 'Mark as Solution' link on the post you want to mark as the solution.



  • 22.  RE: NTP: OS Attack: Microsoft SMB MS17-010 Disclosure Attempt

    Posted Jul 02, 2017 09:37 PM

    Hi Brian,

    Thanks, I can see the mark as Solution button now.