{"id":1656,"date":"2017-05-15T14:24:26","date_gmt":"2017-05-15T14:24:26","guid":{"rendered":"https:\/\/antivirus.comodo.com\/blog\/?p=1656"},"modified":"2020-10-05T13:44:26","modified_gmt":"2020-10-05T08:14:26","slug":"wannacry-what-it-is-and-how-to-safe-from-all-ransomware","status":"publish","type":"post","link":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/","title":{"rendered":"The Wannacry Woes: What It Is and How to Be Safe from All Ransomware"},"content":{"rendered":"<p>We saw how Microsoft&#8217;s expressed relief headache ended as they released this statement &#8220;we fixed this vulnerability two months ago! If you all updated your security settings in Windows this wouldn&#8217;t be a problem!<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1678\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/05\/wannacry-ransomware.jpg\" alt=\"WannaCry Ransomware\" width=\"650\" height=\"300\" \/><\/p>\n<p>Last Friday this <a title=\"\u201dWhat is Ransomware?\" href=\"https:\/\/enterprise.comodo.com\/ransomware-attacks.php\" target=\"_blank\" rel=\"noopener\">ransomware<\/a> called &#8221; WannaCry&#8221; <strong>created havoc across thousands of computers around the world<\/strong>. Unfortunately, a lot of people didn&#8217;t update the patch and are now caught in trouble. A rough estimate shows that users in 150 countries were affected. Organizations of all sizes from Hospitals, railway system, FedEx, Russian <a href=\"https:\/\/www.comodo.com\/landing\/secure-government-institutions\/\" target=\"_blank\" rel=\"noopener\">government agencies<\/a>, manufacturing firms etc were caught unaware. They were cut off from their servers, their files ripped through, account seized and more. According to Europol, nearly 200,000 computers had been infected.<\/p>\n<p><strong>The WannaCry Modus Operandi<\/strong><\/p>\n<p>A virus or <a href=\"https:\/\/www.comodo.com\/landing\/wannacry-ransomware-endpoints-protection\/\" target=\"_blank\" rel=\"noopener\">ransomware<\/a> spreads when users unwittingly click on an unsafe link or email attachment that carries the malware. The creator of WannaCry, however, made use of an <strong>Microsoft\u2019s old Windows flaw<\/strong> (a hole in the code), which allowed them to remotely take control of \u00a0a computer and install Encryptor. So even if the user doesn\u2019t click on any link it will still find its way into your system.<\/p>\n<p>Users who didn\u2019t update their computer with Microsoft\u2019s <a href=\"https:\/\/www.itarian.com\/patch-management.php\" target=\"_blank\" rel=\"noopener\">latest patch<\/a> were booted out within seconds. The malware denied them any access and demanded $300 (in bitcoin) in exchange for getting\u00a0their computer and data back. The victim had three days to pay out and after that, the amount will be doubled to $600. Nevertheless, security experts say WannaCry could only fetch USD37,000 as ransom. According to Checkpoint Security points, victims have <strong>not been able to retrieve their files even after paying<\/strong>. This might not be a big money, but taking into account the havoc this malware has created, it looks like many more businesses might fall prey expecting data after paying money. Those behind WannaCry is not responding, and it\u2019s quite unlikely that they will decrypt anybody\u2019s files as promised, says Checkpoint.<\/p>\n<p><strong>Accidental Halt<\/strong><\/p>\n<p>Meanwhile a 22-year-old cybersecurity analyst in the UK \u201caccidentally\u201d managed to stop the spread of WannyCry when he unwittingly activated a \u201ckill switch\u201d in the malicious software. According to him, the malware was connecting to an unregistered domain with a long string of letters iuqerfsodp9ifjaposdfjhgosurijfaewrwergwe- a.com. He checked if the preposterous domain was registered or not, but it wasn\u2019t so he bought it for $10.69. It turns out that the domain was intended to be a backup plan for the<strong> malicious hackers<\/strong> in case they wanted to stop the spread of WannaCrypt. As soon as the domain was registered, thousands of connections a second began flooding in.<\/p>\n<p>He developed the \u201cKill Switch\u201d which was <strong>hardcoded into the malware<\/strong>. When the malware makes a request and shows the domain is live, the \u2018Kill Switch\u2019 will stop the spread.<\/p>\n<p>&#8220;It Will be Back&#8221;, said the 22-year old Malware Tech. \u201c<strong>This is not over<\/strong>. The attackers will realize how we stopped it, they\u2019ll change the code and then they\u2019ll start again. Enable windows update, update and then reboot.\u201d<\/p>\n<p><strong>How Does WannaCry Ransomware work?<\/strong><\/p>\n<p>Protect your organization with <strong>Containment Technology!<\/strong><\/p>\n<p>Your <strong>risk of infection<\/strong> depends on how adventurous you are, so how can you be sure that you are definitely not going to get Virus on your system. A <a href=\"https:\/\/antivirus.comodo.com\/free-antivirus.php\" target=\"_blank\" rel=\"noopener\">virus removal software<\/a> (<a href=\"https:\/\/www.comodo.com\/home\/internet-security\/antivirus.php\" target=\"_blank\" rel=\"noopener\">antivirus<\/a>) can help to a large extent, but more than that there is something called <a href=\"https:\/\/containment.comodo.com\/\" target=\"_blank\" rel=\"noopener\">Automatic Containment Technology<\/a> (ATS). This defeats <strong>zero-day attacks<\/strong> better than any other security.<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>When an <strong>unknown process<\/strong> gains access to user data, ACT takes the file and place it in a confined place in the system, where but it cannot access or damage user data.<\/li>\n<li>Whether the unknown files are malicious or safe, they run in the sandbox just as well as they would on the system.However, they cannot <strong>damage or infect<\/strong> the systems because they cannot access the underlying system.<\/li>\n<\/ul>\n<p>This allows<strong> safe applications<\/strong> the freedom to run as needed while denying malicious applications the system access they require to deliver their payloads. If the processes are determined to be good, they are automatically released out of the secure container, contingent upon the administrator\u2019s policy.<\/p>\n<p><a href=\"https:\/\/antivirus.comodo.com\/download\/thank-you.php?prod=cloud-antivirus&#038;track=16678&#038;af=16678\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2018\/04\/Comodo-Free-Antivirus.png\" alt=\"comodo antivirus\"\/><\/a><\/p>\n<p><a href=\"https:\/\/secure.nurd.com\/home\/purchase.php?pid=109&#038;af=16166\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2020\/08\/complete-antivirus.png\" alt=\"comodo antivirus\" width=\"650\" height=\"83\" \/><\/a><\/p>\n<p><strong><strong>Related Resources:<\/strong><\/p>\n<p><strong><a href=\"https:\/\/webinspector.com\/website-malware-scanner\/\" rel=\"noopener\" target=\"_blank\">Website Malware Scanner<\/a><\/strong><\/p>\n<p><strong><a href=\"https:\/\/webinspector.com\/\" rel=\"noopener\" target=\"_blank\">Website Malware Removal<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We saw how Microsoft&#8217;s expressed relief headache ended as they released this statement &#8220;we fixed this vulnerability two months ago! If you all updated your security settings in Windows this wouldn&#8217;t be a problem! Last Friday this ransomware called &#8221; WannaCry&#8221; created havoc across thousands of computers around the world. Unfortunately, a lot of people [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":1679,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[98,103,101,47,102,100,99],"class_list":["post-1656","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-computer-safety","tag-containment-technology","tag-cyber-attack-2017","tag-may","tag-ransomware","tag-ransomware-prevention","tag-wannacry","tag-wannacry-ransomware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What it is WannaCry and how to safe from all Ransomware<\/title>\n<meta name=\"description\" content=\"Learn about WannaCry Ransomware and find out the ways to stay protected against it using advanced security software. Stay protected now.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What it is WannaCry and how to safe from all Ransomware\" \/>\n<meta property=\"og:description\" content=\"Learn about WannaCry Ransomware and find out the ways to stay protected against it using advanced security software. Stay protected now.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/\" \/>\n<meta property=\"og:site_name\" content=\"Comodo Antivirus Blogs | Anti-Virus Software Updates\" \/>\n<meta property=\"article:published_time\" content=\"2017-05-15T14:24:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-10-05T08:14:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/04\/RF-10639_thb_2.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"225\" \/>\n\t<meta property=\"og:image:height\" content=\"170\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"seo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"seo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/\",\"name\":\"What it is WannaCry and how to safe from all Ransomware\",\"isPartOf\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/04\/RF-10639_thb_2.jpg\",\"datePublished\":\"2017-05-15T14:24:26+00:00\",\"dateModified\":\"2020-10-05T08:14:26+00:00\",\"author\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\"},\"description\":\"Learn about WannaCry Ransomware and find out the ways to stay protected against it using advanced security software. Stay protected now.\",\"breadcrumb\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/#primaryimage\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/04\/RF-10639_thb_2.jpg\",\"contentUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/04\/RF-10639_thb_2.jpg\",\"width\":225,\"height\":170,\"caption\":\"Petya Ransomware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/antivirus.comodo.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Wannacry Woes: What It Is and How to Be Safe from All Ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/\",\"name\":\"Comodo Antivirus Blogs | Anti-Virus Software Updates\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\",\"name\":\"seo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"caption\":\"seo\"},\"url\":\"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What it is WannaCry and how to safe from all Ransomware","description":"Learn about WannaCry Ransomware and find out the ways to stay protected against it using advanced security software. Stay protected now.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/","og_locale":"en_US","og_type":"article","og_title":"What it is WannaCry and how to safe from all Ransomware","og_description":"Learn about WannaCry Ransomware and find out the ways to stay protected against it using advanced security software. Stay protected now.","og_url":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/","og_site_name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","article_published_time":"2017-05-15T14:24:26+00:00","article_modified_time":"2020-10-05T08:14:26+00:00","og_image":[{"width":225,"height":170,"url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/04\/RF-10639_thb_2.jpg","type":"image\/jpeg"}],"author":"seo","twitter_card":"summary_large_image","twitter_misc":{"Written by":"seo","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/","url":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/","name":"What it is WannaCry and how to safe from all Ransomware","isPartOf":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/#primaryimage"},"image":{"@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/04\/RF-10639_thb_2.jpg","datePublished":"2017-05-15T14:24:26+00:00","dateModified":"2020-10-05T08:14:26+00:00","author":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462"},"description":"Learn about WannaCry Ransomware and find out the ways to stay protected against it using advanced security software. Stay protected now.","breadcrumb":{"@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/#primaryimage","url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/04\/RF-10639_thb_2.jpg","contentUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/04\/RF-10639_thb_2.jpg","width":225,"height":170,"caption":"Petya Ransomware"},{"@type":"BreadcrumbList","@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/wannacry-what-it-is-and-how-to-safe-from-all-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/antivirus.comodo.com\/blog\/"},{"@type":"ListItem","position":2,"name":"The Wannacry Woes: What It Is and How to Be Safe from All Ransomware"}]},{"@type":"WebSite","@id":"https:\/\/antivirus.comodo.com\/blog\/#website","url":"https:\/\/antivirus.comodo.com\/blog\/","name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462","name":"seo","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","caption":"seo"},"url":"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/"}]}},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1656","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/comments?post=1656"}],"version-history":[{"count":30,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1656\/revisions"}],"predecessor-version":[{"id":15560,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1656\/revisions\/15560"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media\/1679"}],"wp:attachment":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media?parent=1656"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/categories?post=1656"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/tags?post=1656"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}