Of the five most affected countries, only the United States (fourth most affected, with approximately 8% of the global tally) was outside of the Asia-Pacific region. To enter a system, the malware uses the Eternal Blue vulnerability – MS17-010.The combination of fileless WMI scripts and Eternal Blue makes this threat extremely stealthy and persistent.It checks what Windows event in __Event Filter will be executed together with the script in __Active Script Event Consumer." There are two areas where IT administrators can learn from this attack and improve their defenses. It requires administrator rights to be used on a system.Granting access only to specific groups of administrator accounts that need to use WMI would help reduce risk of WMI attacks. If a machine does not need access to WMI, disable it to eliminate the risk.We recently found a new cryptocurrency miner (which we detect as TROJ64_COINMINER. We first saw this particular variant affecting the Asia-Pacific region in July.

It completes the cycle by relating the class instances with each other.The infection flow of this cryptocurrency miner malware has several stages.The infection flow starts with MS17-010; the vulnerability is used to drop and run a backdoor on the system (BKDR_FORSHARE. These scripts then connect to its C&C servers to get instructions and download the cryptocurrency miner malware together with its components.SMBv1 can also be disabled to reduce the risk to users.The entry point of this attack was Eternal Blue, for which a patch has been available since March 2017.