WannaCry Factsheet (continuously updated) and Patches for Legacy Windows



This was a "cyber attack" like driving through a minefield is a "suicide bomb."

MS has issued emergency patches for unsupported versions of Windows.

Mitigations for WannaCry

Get your patch here if you need it.

MS Security Bulletin Details


  • Windows Server 2003 -> 2008
  • Windows XP -> Windows 8
  • Windows POSReady and WES09

If you have been affected

As of right now there is no way to decrypt your data and the perpetrators are apparently not able to hand out encryption keys even if you pay the ransom due to them not being able to track 'users' as it were and are unable to link keys to specific infection instances.

You will have to restore from backups.

Updated Wiki Gist

You can keep up with the latest developments covering WanaCrypt0r on this wiki gist now.
It's being updated as more developments come in. It's currently still just a fraction of what we expect to see.

Well written summary on WannaCrypt0r by Troy Hunt

Index of public servers affected by WCRY (as of yet ~11'200 results) some are just tips on how to google for affected servers

Microsoft just issued an update for Windows XP

"The Russian interior ministry says about 1,000 computers have been affected."



  1. Added google dork search for index of infected servers.
  2. No reports yet of anyone receiving the decryption key and successfully decrypting their files following ransom payment.
    • Strongly suspect the keys are simply thrown away. Only the master private key if recovered may be helpful in recovering the encrypted files.


Direct Links to Patches since windows update catalog was struggling with load.

Windows Server 2003 SP2 x64
Windows Server 2003 SP2 x86
Windows XP SP2 x64
Windows XP SP3 x86
Windows XP Embedded SP3 x86
Windows Vista
Windows Vista x64
Windows 8 x86
Windows 8 x64


Ok - I am asking, before reading all the information floating around, but does this malware connect to SMB? Why on earh is a) smb on the internet and b) soooo much of it.

Even a stupid soho router would stop that right? - I mean my external logs are full with declined requests to


SMB 1 yes

A lot of the spread is due to VPN connected shares and vulnerable servers that bridge networks.
Some of the initial attack also proceeded via standard malware delivery vectors (email,etc) but those details are less well researched.

Here's the diagram of the worm + malware so far.


OK, I need to ask, curiosity malware in my brain instructs me to do so: what is exact status of the Windows 7?
I do not see patch for it on the list, and on some lists of affected Windows it is absent. Was it simply patched already?


It was technically patched in March Already

Patches can be found here:

Windows 7 SP1



