
How is OpenDNS protecting our Practices?
Introduction
A major ransomware attack broke on Friday, May 12 2017, impacting many organizations throughout the world. The malware responsible for this attack is a ransomware variant known as ‘WannaCry’. This service notification explains how Umbrella is protecting its users from WannaCry.
Explanation
OpenDNS is blocking the domains that the WannaCry ransomware calls out to. All communications tied to this malware, including DGA domains and IP addresses, have been confirmed to be on our block list. We first observed requests for WannaCry’s kill switch/anti-sandbox domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com) starting at 07:24 UTC, and it was added to the Newly Seen Domains (NSD) security category. Umbrella customers blocking the NSD category were protected at the earliest possible point. At 10:12 UTC, the domain was categorized as malware and blocked for all users.
The malware author built in this kill switch in case they chose to stop the attack. By blocking this kill switch domain, OpenDNS prevents the ransomware from running on the machine. The malware makes a HTTP call to a specific domain before executing its payload, and if there is a response, the payload is disabled. With OpenDNS blocking the domain, the request is responded to with the IP of our block page rather than NXDOMAIN. This is enough to activate this kill switch and prevent the encryption from taking place.
However, as with any ransomware, the OpenDNS service cannot prevent encryption once the ransomware has already infected a system. The users still need to be vigilant, and not click on suspicious emails and pop up windows.

