The “EternalBlue” exploit ( href="https://technet.microsoft.com/en-us/library/security/ms17-010.aspx">MS017-010)
was initially used by WannaCry ransomware and Adylkuzz cryptocurrency
miner. Now more threat actors are leveraging the vulnerability in href="https://www.fireeye.com/blog/threat-research/2017/05/smb-exploited-wannacry-use-of-eternalblue.html">Microsoft
Server Message Block (SMB) protocol – this time to distribute
Backdoor.Nitol and Trojan Gh0st RAT.
FireEye Dynamic Threat Intelligence (DTI) has historically observed
similar payloads delivered via exploitation of CVE-2014-6332
vulnerability as well as in some email spam campaigns using href="https://www.fireeye.com/blog/threat-research/2016/09/hancitor_aka_chanit.html">powershell
commands. Specifically, Backdoor.Nitol has also been linked to
campaigns involving a remote code execution vulnerability using the
ADODB.Stream ActiveX Object that affects older versions of Internet
Explorer. Both payloads have previously been involved in targeted href="https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/ib-aerospace.pdf">cyber-attacks
against the aerospace and defense industry.
We observed lab machines vulnerable to SMB exploit were attacked by
a threat actor using the EternalBlue exploit to gain shell access to
the machine.
Figure 1 shows an EternalBlue exploitation attempt.

Figure 1. Network traffic showing EternalBlue
attack attempt
The initial exploit technique used at the href="https://www.fireeye.com/blog/threat-research/2017/05/smb-exploited-wannacry-use-of-eternalblue.html">SMB
level is similar to what we have been seen in href="https://www.fireeye.com/blog/threat-research/2017/05/wannacry-malware-profile.html">WannaCry
campaigns; however, once a machine is successfully infected, this
particular attack opens a shell to write instructions into a VBScript
file and then executes it to fetch the payload on another server.
We have observed the same EternalBlue and VBScript combination used
to distribute