Koozali.org: home of the SME Server

Hash/SHA256 based attachment filter - catched WannaCry

Offline warren

  • *
  • 293
  • +0/-0
Re: Hash/SHA256 based attachment filter - catched WannaCry
« Reply #30 on: June 21, 2017, 04:54:38 PM »
@Knuddi
will this also catch the Erebus Linux Ransomware http://blog.trendmicro.com/trendlabs-security-intelligence/erebus-resurfaces-as-linux-ransomware/

Seems Virust Total Has some hashes for it :
SHA256 detected as RANSOM_ELFEREBUS.A:

    0b7996bca486575be15e68dba7cbd802b1e5f90436ba23f802da66292c8a055f
    d889734783273b7158deeae6cf804a6be99c3a5353d94225a4dbe92caf3a3d48

Offline Knuddi

  • *
  • 540
  • +0/-0
    • http://www.scanmailx.com
Re: Hash/SHA256 based attachment filter - catched WannaCry
« Reply #31 on: June 21, 2017, 06:07:54 PM »
No these SHA256 are not currently registered in the DB which means no one has seen them yet. As of right now the community part has found and added 238 different signatures that will be rejected.

I will look into a model to add "preventive" SHAs to the DB.

guest22

Re: Hash/SHA256 based attachment filter - catched WannaCry
« Reply #32 on: June 27, 2017, 04:03:40 PM »
Heads-up, it seems there is another attack under way (June 27, 2017).


@Knuddi, any prove of this in your monitoring systems please?

Offline Knuddi

  • *
  • 540
  • +0/-0
    • http://www.scanmailx.com
Re: Hash/SHA256 based attachment filter - catched WannaCry
« Reply #33 on: June 27, 2017, 05:55:05 PM »
I cannot see any specific patterns that are unusual today or yesterday. The community has provided 9 attachments with bad stuff (trojans, virus, etc.) and most of these are zip attachments with a few Java variants (jar).

A good example of the many caught:
https://virustotal.com/en/file/79d5ae8f94e5320458f3ba5f7556590b7d3366ebd9eda21a77289b07687deba1/analysis/

« Last Edit: June 27, 2017, 06:00:38 PM by Knuddi »

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Hash/SHA256 based attachment filter - catched WannaCry
« Reply #34 on: July 02, 2017, 12:24:43 PM »
SMEOptimizer reports from a wrong public IP. How can this be fixed? IP was changed in a static one, it seems that it's still the old dynamic IP.

Regards,
stefan
And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

Offline Knuddi

  • *
  • 540
  • +0/-0
    • http://www.scanmailx.com
Re: Hash/SHA256 based attachment filter - catched WannaCry
« Reply #35 on: July 03, 2017, 08:45:24 AM »
@Stefan,

SMEOptimizer just uses a stamdard HTTPS connection from your SME server towards the smeoptimizer.com server. So whatever IP your server uses it will use. Why do you think it uses a wrong IP and what is the problem with that?

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Hash/SHA256 based attachment filter - catched WannaCry
« Reply #36 on: July 03, 2017, 09:28:42 AM »
@Knuddi,

Blacklist warning for your SME Server von SMEOptimizer Alert:

Your SME server with public IP address 84.130.159.73 has been listed in international blacklist databases.

This is not the public server IP.

Regards,
stefan

And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Hash/SHA256 based attachment filter - catched WannaCry
« Reply #37 on: July 09, 2017, 10:28:04 AM »
@Knuddi,

today I'm receiving again this email:

Your SME server with public IP address 84.130.159.73 has been listed in international blacklist databases. It has been observed registered now 21 day(s) in this database(s). This blacklist registration very often means that the emails sent from will not successfully reach their intended destination.

We assume that you are not a spammer and suggest that you right away initiate actions to identify the reasons for the listing. This could require security updates of client PCs in your organization including checks for virus and botnets and potentially, the reconfiguration of your mail server.


Blacklist    Reason    Return code
pbl.spamhaus.org    https://www.spamhaus.org/query/ip/84.130.159.73
   127.0.0.10


Best regards,
SME Optimizer

My public IP is a different one. I assume this IP was formerly the dynamic public IP and it's obviously still in the database of SME Optimizer. Do I have to re-register with my new static IP or how is this going to be updated?

Regards,
stefan
And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Hash/SHA256 based attachment filter - catched WannaCry
« Reply #38 on: July 16, 2017, 11:47:33 AM »
And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

Offline Knuddi

  • *
  • 540
  • +0/-0
    • http://www.scanmailx.com
Re: Hash/SHA256 based attachment filter - catched WannaCry
« Reply #39 on: July 17, 2017, 04:01:35 PM »
@Stefan,

Thanks for opening a bug, this makes it much easier to track and follow for me. Do not get to the forums that often :-)

The problem that you have reported has now been resolved.

Enjoy,
Jesper