{"id":3216,"date":"2021-07-05T23:05:32","date_gmt":"2021-07-06T04:05:32","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3216"},"modified":"2021-07-05T23:05:33","modified_gmt":"2021-07-06T04:05:33","slug":"indexsinas-smb-threat-for-windows-servers","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/","title":{"rendered":"Indexsinas SMB Threat for Windows servers"},"content":{"rendered":"\n<p>Researchers have warned that the Indexsinas SMB worm is looking for vulnerable environments in which to spread itself, with a particular focus on the healthcare, hospitality, education and telecommunications sectors. Their ultimate goal is to dump crypto miners on the compromised machines. Indexsinas, also known as NSABuffMiner, makes use of the old Equation Group arsenal, including the EternalBlue and EternalRomance exploits to invade Windows SMB shares, as well as the DoublePulsar backdoor.<\/p>\n\n\n\n<p>Propagation is achieved by combining an open source port scanner and three Equation Group Exploits: EternalBlue, DoublePulsar, and EternalRomance. These exploits are used to exploit new victim machines, gain privileged access and install back doors. These exploits appear to continue to have great success even though they were made public four years ago after their first appearance in the WannaCry and NotPetya cyberattacks. Indexsinas shows that networks today are vulnerable even to undirected opportunistic attack campaigns.<\/p>\n\n\n\n<p>The attacks originated from more than 1,300 different sources, with each machine responsible for only a few attack incidents. The source IPs, which are likely to be the victims of the attacks themselves, are primarily located in the US, Vietnam, and India.<\/p>\n\n\n\n<p>This is why it is so important to segment corporate networks as this not only prevents an attacker from moving sideways and reaching strategic assets and crown jewels on the network, it also helps to minimize damage (reduce blast radius). by creating boundaries between servers on the network and limiting network traffic between them.<\/p>\n\n\n\n<p>More reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/sasser-worm-the-virus-that-restarted-the-computer\/\">Sasser Worm \u2013 The virus that restarted the computer<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/\">ZLoader \u2013 A Dangerous malware Distributor<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers have warned that the Indexsinas SMB worm is looking for vulnerable environments in which to spread itself, with a particular focus on the healthcare, hospitality, education and telecommunications sectors. Their ultimate goal is to dump crypto miners on the compromised machines. Indexsinas, also known as NSABuffMiner, makes use of the old Equation Group arsenal, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3217,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36,195],"class_list":["post-3216","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-worm"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Indexsinas SMB Threat for Windows servers - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Cyber \u200b\u200bthreats are always active and today the leading role is taken by Indexsinas SMB which we will see how this threat acts......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Indexsinas SMB Threat for Windows servers - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Cyber \u200b\u200bthreats are always active and today the leading role is taken by Indexsinas SMB which we will see how this threat acts......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-06T04:05:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-07-06T04:05:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/worm.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"582\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Indexsinas SMB Threat for Windows servers\",\"datePublished\":\"2021-07-06T04:05:32+00:00\",\"dateModified\":\"2021-07-06T04:05:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/\"},\"wordCount\":264,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/worm.jpg\",\"keywords\":[\"Cybersecurity\",\"Worm\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/\",\"name\":\"Indexsinas SMB Threat for Windows servers - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/worm.jpg\",\"datePublished\":\"2021-07-06T04:05:32+00:00\",\"dateModified\":\"2021-07-06T04:05:33+00:00\",\"description\":\"Cyber \u200b\u200bthreats are always active and today the leading role is taken by Indexsinas SMB which we will see how this threat acts......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/worm.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/worm.jpg\",\"width\":800,\"height\":582},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/indexsinas-smb-threat-for-windows-servers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Indexsinas SMB Threat for Windows servers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Indexsinas SMB Threat for Windows servers - Truxgo Server Blog","description":"Cyber \u200b\u200bthreats are always active and today the leading role is taken by Indexsinas SMB which we will see how this threat acts......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/","og_locale":"es_MX","og_type":"article","og_title":"Indexsinas SMB Threat for Windows servers - Truxgo Server Blog","og_description":"Cyber \u200b\u200bthreats are always active and today the leading role is taken by Indexsinas SMB which we will see how this threat acts......","og_url":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-07-06T04:05:32+00:00","article_modified_time":"2021-07-06T04:05:33+00:00","og_image":[{"width":800,"height":582,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/worm.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Indexsinas SMB Threat for Windows servers","datePublished":"2021-07-06T04:05:32+00:00","dateModified":"2021-07-06T04:05:33+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/"},"wordCount":264,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/worm.jpg","keywords":["Cybersecurity","Worm"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/","url":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/","name":"Indexsinas SMB Threat for Windows servers - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/worm.jpg","datePublished":"2021-07-06T04:05:32+00:00","dateModified":"2021-07-06T04:05:33+00:00","description":"Cyber \u200b\u200bthreats are always active and today the leading role is taken by Indexsinas SMB which we will see how this threat acts......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/worm.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/worm.jpg","width":800,"height":582},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/indexsinas-smb-threat-for-windows-servers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Indexsinas SMB Threat for Windows servers"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3216"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3216\/revisions"}],"predecessor-version":[{"id":3228,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3216\/revisions\/3228"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3217"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3216"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}