Return-Path: <1921889-415-1022@be4.maropost.com>
Delivered-To: edward@transocean.com
Received: from vps.transocean.com
	by vps.transocean.com (Dovecot) with LMTP id 2bLKCUq2UlkKCQAAInt2oQ
	for <edward@transocean.com>; Tue, 27 Jun 2017 12:47:22 -0700
Return-path: <1921889-415-1022@be4.maropost.com>
Envelope-to: edward@transocean.com
Delivery-date: Tue, 27 Jun 2017 12:47:22 -0700
Received: from mta7165.mp2200.com ([162.247.117.165]:20919)
	by vps.transocean.com with esmtp (Exim 4.89)
	(envelope-from <1921889-415-1022@be4.maropost.com>)
	id 1dPwS6-0000gO-00
	for edward@transocean.com; Tue, 27 Jun 2017 12:47:22 -0700
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 s=default; d=knowbe4.com; t=1498592828; l=1; h=from:subject:date:to;
 bh=nR4OLZRZ0GUjrRPiikCTwjFrqv567Fsl8w66LhE1mcQ=;
 b=vZcShbGizAMbx/dPovxKX+fnjgBv6EtXQud4IoSRmwnFpKFAToB0diLaGJoqvOd6rBI2px
 1yCvDFVwqhKt6+q6oftMUCQ1FhEqWqPF2pR56RZvAnGpnnZNtQDSnqnmjiRMp3CNiu8wGf
 Cac3jXyBV1Y4c1BwIedjX3Gqr2VVTck=
Received: from [<1921889-415-1022@be4.maropost.com>] ([<1921889-415-1022@be4.maropost.com>] helo=) 
 by 649892-mailer2 (envelope-from 1921889-415-1022@be4.maropost.com)
 (Jetsend MTA 0.0.1 with ESMTP; Tue Jun 27 15:24:11 EDT 2017
Date: Tue, 27 Jun 2017 15:24:10 -0400
From: CyberheistNews Flash <feedback@knowbe4.com>
Reply-To: feedback@knowbe4.com
To: edward@transocean.com
Message-ID: <1e8fcbe0-3d9c-0135-21fc-0cdcd4b634c4@knowbe4.com>
Subject: [ALERT] Looks Like a New Worldwide Ransomware Outbreak
Mime-Version: 1.0
Content-Type: multipart/alternative;
 boundary="--==_mimepart_5952b0da41577_5c36c812ec65763542";
 charset=UTF-8
Content-Transfer-Encoding: 7bit
List-Unsubscribe: <mailto:1921889-415-1022-162.247.117.165-gmail@abuse.maropost.com>
X-CampaignID: 415
X-Campaign-ID: 415
X-ContactID: 1921889
X-AccountID: 1022
X-Binding: 162.247.117.165
X-DkimDomain: knowbe4.com
X-DkimSelector: default
X-Feedback-ID: 415:Maropost
X-Spam-Status: No, score=0.7
X-Spam-Score: 7
X-Spam-Bar: /
X-Ham-Report: Spam detection software, running on the system "vps.transocean.com",
 has NOT identified this incoming email as spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 
 Content preview:  If you are having trouble viewing this email, click here.
   http://newsletter.knowbe4.com/a/1022/preview/415/1921889/8cf382b0ef565552314b1cc272f5ebae982db169
    This email was sent to &amp;lt;b&amp;gt;edward@transocean.com&amp;lt;/b&amp;gt;
    by &amp;lt;b&amp;gt;feedback@knowbe4.com&amp;lt;/b&amp;gt; Manage Subscriptions
    http://newsletter.knowbe4.com/a/1022/unsubscribe/415/1921889/8cf382b0ef565552314b1cc272f5ebae982db169
    33 N Garden Ave, Suite 1200 Clearwater, FL 33755 USA Report Spam http://newsletter.knowbe4.com/a/1022/report_spam/415/1921889/8cf382b0ef565552314b1cc272f5ebae982db169
    [...] 
 
 Content analysis details:   (0.7 points, 3.0 required)
 
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was blocked.
                             See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URIs: transocean.com]
  0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
                             domains are different
  0.0 T_SPF_HELO_TEMPERROR   SPF: test of HELO record failed (temperror)
 -0.0 SPF_PASS               SPF: sender matches SPF record
  0.8 BAYES_50               BODY: Bayes spam probability is 40 to 60%
                             [score: 0.4933]
  0.0 HTML_FONT_SIZE_LARGE   BODY: HTML font size is large
  0.0 HTML_MESSAGE           BODY: HTML included in message
  0.0 T_KAM_HTML_FONT_INVALID BODY: Test for Invalidly Named or Formatted
                             Colors in HTML
  0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily valid
 -0.1 DKIM_VALID_AU          Message has a valid DKIM or DK signature from author's
                             domain
 -0.1 DKIM_VALID             Message has at least one valid DKIM or DK signature
  0.0 UNPARSEABLE_RELAY      Informational: message has unparseable relay lines
X-Spam-Flag: NO


----==_mimepart_5952b0da41577_5c36c812ec65763542
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

If you are having trouble viewing this email,
click here.
http://newsletter.knowbe4.com/a/1022/preview/415/1921889/8cf382b0ef565552314b1cc272f5ebae982db169
This email was sent to &amp;lt;b&amp;gt;edward@transocean.com&amp;lt;/b&amp;gt; by &amp;lt;b&amp;gt;feedback@knowbe4.com&amp;lt;/b&amp;gt;
Manage Subscriptions
http://newsletter.knowbe4.com/a/1022/unsubscribe/415/1921889/8cf382b0ef565552314b1cc272f5ebae982db169
33 N Garden Ave, Suite 1200 Clearwater, FL 33755 USA
Report Spam
http://newsletter.knowbe4.com/a/1022/report_spam/415/1921889/8cf382b0ef565552314b1cc272f5ebae982db169


----==_mimepart_5952b0da41577_5c36c812ec65763542
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: quoted-printable

  <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3=
.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
  <html xmlns=3D"http://www.w3.org/1999/xhtml">
    <head>
      <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DU=
TF-8">
      <meta name=3D"viewport" content=3D"width=3Ddevice-width, initial-sc=
ale=3D1.0">
      <title>[ALERT] Looks Like a New Worldwide Ransomware Outbreak</titl=
e>
    </head>
    <body>
      <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http=
://www.w3.org/TR/REC-html40/loose.dtd">
<html><body><table cellpadding=3D"0" cellspacing=3D"0" width=3D"100%">
<tr><td>
<img height=3D"1" width=3D"1" alt=3D"" style=3D"display:block;" src=3D"ht=
tp://newsletter.knowbe4.com/a/1022/open/415/1921889/8cf382b0ef565552314b1=
cc272f5ebae982db169">
<div align=3D"center" style=3D'font-size:8.0pt; font-family:"Arial","sans=
-serif"; color:#666666;margin-bottom:10px;display:block !important'>
If you are having trouble viewing this email,
<a style=3D"border:0px" class=3D"maro_no_record" href=3D"http://newslette=
r.knowbe4.com/a/1022/preview/415/1921889/8cf382b0ef565552314b1cc272f5ebae=
982db169?message_id=3DIjFlOGZjYmUwLTNkOWMtMDEzNS0yMWZjLTBjZGNkNGI2MzRjNEB=
rbm93YmU0LmNvbSI=3D">click here.</a>
</div>
</td></tr>
<tr><td>


<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF-8">=

<title></title>
<meta charset=3D"utf-8">
<meta name=3D"viewport" content=3D"width=3Ddevice-width, initial-scale=3D=
1">
<meta http-equiv=3D"X-UA-Compatible" content=3D"IE=3Dedge">
<link href=3D"https://fonts.googleapis.com/css?family=3DOpen+Sans:300,400=
,600,700,800" rel=3D"stylesheet">
<style type=3D"text/css">/* CLIENT-SPECIFIC STYLES */
    #outlook a{padding:0;} /* Force Outlook to provide a "view in browser=
" message */
    .ReadMsgBody{width:100%;} .ExternalClass{width:100%;} /* Force Hotmai=
l to display emails at full width */
    .ExternalClass, .ExternalClass p, .ExternalClass span, .ExternalClass=
 font, .ExternalClass td, .ExternalClass div {line-height: 100%;} /* Forc=
e Hotmail to display normal line spacing */
    body, table, td, a{-webkit-text-size-adjust:100%; -ms-text-size-adjus=
t:100%;} /* Prevent WebKit and Windows mobile changing default text sizes=
 */
    table, td{mso-table-lspace:0pt; mso-table-rspace:0pt;} /* Remove spac=
ing between tables in Outlook 2007 and up */
    img{-ms-interpolation-mode:bicubic;} /* Allow smoother rendering of r=
esized image in Internet Explorer */

    /* RESET STYLES */
    body{margin:0; padding:0; background-color:#ffffff;}
    img{border:0; height:auto; line-height:100%; outline:none; text-decor=
ation:none;}
    body{height:100% !important; margin:0; padding:0; width:100% !importa=
nt;}

    /* iOS BLUE LINKS */
    .appleBody a {color:#f16824; text-decoration: none;}
    .appleFooter a {color:#f16824; text-decoration: none;}

    /* MOBILE STYLES */
    @media screen and (max-width: 525px) {
</style>
<!--LOGO-->


<div style=3D"max-width:800px; margin:auto; padding: 40px 20px 20px 20px;=
 text-align:center;"><a href=3D"http://newsletter.knowbe4.com/a/1022/clic=
k/415/1921889/044ac0b3da603dc543019ea4b8f92228baf8fbe8/8cf382b0ef56555231=
4b1cc272f5ebae982db169" target=3D"_blank"><img align=3D"center" src=3D"ht=
tps://www.knowbe4.com/hubfs/CHN-LOGO-NF.jpg" style=3D"width:100%;"></a></=
div>
<!--/LOGO--><!--ISSUE & DATE-->

<div style=3D"max-width:800px; margin:auto; padding: 0px 20px 0px 20px; t=
ext-align:center;">
<hr style=3D"border: 0; height: 1px; background-image: linear-gradient(to=
 right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.25), rgba(0, 0, 0, 0));">
</div>
<!--/ISSUE & DATE--><!--MAIN STORY-->

<div style=3D"max-width:800px; margin:auto; padding: 20px 20px 40px 20px;=
">
<center><span style=3D"font-size: 24px; line-height:30px; font-family: 'O=
pen Sans', sans-serif; color: #f16622;">[ALERT] Looks Like A New Worldwid=
e Ransomware Outbreak</span></center>

<p><span style=3D"font-size:16px; line-height:22px; font-family: 'Open Sa=
ns', sans-serif; color: #333333;"><img align=3D"right" src=3D"https://blo=
g.knowbe4.com/hs-fs/hubfs/New_Attack.jpg?t=3D1498574606639&amp;width=3D32=
0&amp;name=3DNew_Attack.jpg" style=3D" padding: 20px 20px 20px 20px;" wid=
th=3D"320"></span></p>
<br>
<br>
<span style=3D"font-size:16px; line-height:22px; font-family: 'Open Sans'=
, sans-serif; color: #333333;">Motherboard reported: "A quickly-spreading=
, world-wide ransomware outbreak has reportedly hit targets in Spain, Fra=
nce, Ukraine, Russia, and other countries.<br>
<br>
On Tuesday, a wide range of private businesses reportedly suffered ransom=
ware attacks. Although it is not clear if every case is connected, at lea=
st several of them appear to be related to the same strain of malware."<b=
r>
<br>
Motherboard continued: "The attacks are similar to the recent WannaCry ou=
tbreak, and motherboard has seen several reports of infections shared by =
victims on Twitter. We were not able to immediately confirm the veracity =
of the reports, but several security researchers and firms also reported =
the attacks.<br>
<br>
"We are seeing several thousands of infection attempts at the moment, com=
parable in size to Wannacry's first hours," Costin Raiu, a security resea=
rcher at Kaspersky Lab, told Motherboard in an online chat.<br>
<br>
Judging by photos posted to Twitter and images provided by sources, many =
of the alleged attacks involved a piece of ransomware that displays red t=
ext on a black background, and demands $300 worth of bitcoin.<br>
<br>
"If you see this text, then your files are no longer accessible, because =
they are encrypted," the text reads, according to one of the photos. "Per=
haps you are busy looking for a way to recover your files, but don't wast=
e your time. Nobody can recover your files without our decryption service=
."<br>
<br>
Raiu believes the ransomware strain is known as Petya or Petrwrap, a high=
ly sophisticated Russian strain, withaout all the errors that WannaCry co=
ntained, and no kill-switch. According to a tweet from anti-virus company=
 Avira, the Petya attacks were taking advantage of the EternalBlue exploi=
t previously leaked by the group known as The Shadow Brokers (Motherboard=
 could not independently confirm this at the time of writing).<br>
<br>
EternalBlue is the same exploit used in the WannaCry attacks; it takes ad=
vantage of a vulnerability in the SMB data-transfer protocol, and Microso=
ft has since patched the issue. However, whether customers apply that pat=
ch is another matter.<br>
<br>
Security researchers from Kaspersky Lab reported that the ransomware hit =
Russia, Ukraine, Spain, France, among others. Several people on Twitter r=
eported witnessing or hearing reports of the outbreak in their respective=
 countries, and across a wide range of industries. Companies around the w=
orld also reported computer outages.<br>
<br>
<b>If You Have Not Done So Yet, Apply This Patch Immediately.</b><br>
<br>
From what we have been able to learn, this new worm spreads through SMB j=
ust like WannaCry so when we're talking about machines behind firewalls b=
eing impacted, it implies port 445 being open and at-risk hosts listening=
 to inbound connections. It'd only take one machine behind the firewall t=
o become infected to then put all other workstations and servers at risk =
due to it being a true worm.<br>
<br>
In the meantime, harden yourselves against this Windows Network Share vul=
nerability and ensure that all systems are fully patched with the "MS17-0=
10" security update (link below) and <b>remind all staff to Think Before =
They Click</b> when they receive any out of the ordinary emails.<br>
https://technet.microsoft.com/en-us/library/security/ms17-010.aspx<br>
<br>
Check the KnowBe4 blog for continuous updates:<br>
https://blog.knowbe4.com/alert-looks-like-a-new-worldwide-ransomware-outb=
reak </span><br>
=C2=A0
<hr style=3D"border: 0; height: 1px; background-image: linear-gradient(to=
 right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.25), rgba(0, 0, 0, 0));">
<span style=3D"font-size:16px; line-height:22px; font-family: 'Open Sans'=
, sans-serif; color: #333333;"> </span><br>
=C2=A0
<p><span style=3D"font-size:16px; line-height:22px; font-family: 'Open Sa=
ns', sans-serif; color: #333333;"><img align=3D"left" src=3D"https://blog=
.knowbe4.com/hs-fs/hubfs/RanSimFalPos.png?t=3D1498574606639&amp;width=3D2=
16&amp;name=3DRanSimFalPos.png" style=3D" padding: 0px 30px 0px 0px;" wid=
th=3D"216"></span></p>
<span style=3D"font-size:16px; line-height:22px; font-family: 'Open Sans'=
, sans-serif; color: #333333;"> <font size=3D"6">Free <b>Ransomware Simul=
ator Tool</b></font><br>
<br>
<font size=3D"5">How vulnerable is your network against a ransomware atta=
ck?</font><br>
<br>
Bad guys are constantly coming out with new strains to evade detection. I=
s your network effective in blocking all of them when employees fall for =
social engineering attacks?<br>
<br>
KnowBe4=E2=80=99s "RanSim" gives you a quick look at the effectiveness of=
 your existing network protection. RanSim will simulate 10 infection scen=
arios and show you if a workstation is vulnerable to infection.<br>
<br>
To download RanSim click or copy this link:<br>
https://info.knowbe4.com/ransomware-simulator-tool-1chn </span>

<p><span style=3D"font-size:16px; line-height:22px; font-family: 'Open Sa=
ns', sans-serif; color: #333333;"><img src=3D"http://cdn2.hubspot.net/hub=
fs/241394/CHN-STU-2017-1.png" style=3D" padding: 10px 0px 10px 0px;" widt=
h=3D"144"><br>
Warm Regards,<br>
Stu Sjouwerman<br>
Founder &amp; CEO<br>
KnowBe4, Inc.</span></p>
<span style=3D"font-size:16px; line-height:22px; font-family: 'Open Sans'=
, sans-serif; color: #333333;"> </span>
</div>
<!--/MAIN STORY--><!--SOCIAL & COPYRIGHT-->

<div style=3D"max-width:800px; margin:auto; padding: 20px 20px 20px 20px;=
">
<hr style=3D"border: 0; height: 1px; background-image: linear-gradient(to=
 right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.25), rgba(0, 0, 0, 0));">
<div style=3D"max-width:400px; margin:auto; padding: 0px 0px 0px 0px; flo=
at:left; text-align:left; line-height:12px;"><span style=3D"font-size:10p=
x; line-height:10px; font-family: 'Open Sans', sans-serif; color:#676767;=
">FOLLOW US ON: <a href=3D"http://newsletter.knowbe4.com/a/1022/click/415=
/1921889/12f6f18bb2280eb257fda0ee104ee0a8a9355394/8cf382b0ef565552314b1cc=
272f5ebae982db169" style=3D"color:#f16824; text-decoration:none;" target=3D=
"_blank">Twitter</a> | <a href=3D"http://newsletter.knowbe4.com/a/1022/cl=
ick/415/1921889/35c8d23f428e99808212e79c497c5c7904ccc19f/8cf382b0ef565552=
314b1cc272f5ebae982db169" style=3D"color:#f16824; text-decoration:none;" =
target=3D"_blank">LinkedIn</a> | <a href=3D"http://newsletter.knowbe4.com=
/a/1022/click/415/1921889/665fd8e8468a0fa0d279b30bd4c7ba97f04517dd/8cf382=
b0ef565552314b1cc272f5ebae982db169" style=3D"color:#f16824; text-decorati=
on:none;" target=3D"_blank">Google</a> | <a href=3D"http://newsletter.kno=
wbe4.com/a/1022/click/415/1921889/947165ed658284c668dbae4f407761b5796d074=
5/8cf382b0ef565552314b1cc272f5ebae982db169" style=3D"color:#f16824; text-=
decoration:none;" target=3D"_blank">YouTube</a></span></div>

<div style=3D"max-width:400px; margin:auto; padding: 0px 0px 0px 0px; flo=
at:right; text-align:right; line-height:12px;"><span style=3D"font-size:1=
0px; line-height:10px; font-family: 'Open Sans', sans-serif; color:#67676=
7;">Copyright =C2=A9 2014-2017 KnowBe4, Inc. All rights reserved.</span><=
/div>
</div>
<!--SOCIAL & COPYRIGHT-->


</td></tr>
<tr><td>
<div class=3D"footersp" style=3D"height:1px; width: 100%; margin-left: au=
to; margin-right: auto; background-color:black;display:block !important;"=
>=C2=A0</div>
=C2=A0

<div class=3D"footerco" style=3D"margin-left: auto; margin-right: auto; w=
idth: 100%; background-color:#ffffff !important; display:block !important=
;">
<table border=3D"0" cellpadding=3D"0" cellspacing=3D"0" style=3D"width:10=
0%; display:table !important;">
	<tbody>
		<tr style=3D"display:table-row !important;">
			<td style=3D"width:20%; display:table-cell !important;">=C2=A0</td>
			<td align=3D"center" style=3D"mso-table-lspace: 0pt;mso-table-rspace: =
0pt;-ms-text-size-adjust: 100%;-webkit-text-size-adjust: 100%;text-align:=
center;vertical-align:middle; display:table-cell !important;font-size:8.0=
pt; font-family:'Arial','sans-serif'; color:#666666;">This email was sent=
 to <b>edward@transocean.com</b> by <b>feedback@knowbe4.com</b><br>
			<br>
			33 N Garden Ave, Suite 1200 Clearwater, FL 33755 USA<br>
			=C2=A0
			<div style=3D"display:block"><a class=3D"maro_no_record" href=3D"http:=
//newsletter.knowbe4.com/a/1022/one_click_unsubscribe/415/1921889/8cf382b=
0ef565552314b1cc272f5ebae982db169" rel=3D"nofollow" style=3D"border:0px;c=
olor:#000;display:inline !important;">1-Click Unsubscribe</a></div>
			</td>
			<td align=3D"right" style=3D"text-align:right;mso-table-lspace: 0pt;ms=
o-table-rspace: 0pt;-ms-text-size-adjust: 100%;-webkit-text-size-adjust: =
100%;width:20%;vertical-align:middle; display:table-cell !important;font-=
size:8.0pt; font-family:'Arial','sans-serif'; color:#666666;" valign=3D"m=
iddle">=C2=A0</td>
		</tr>
	</tbody>
</table>
</div>
</td></tr>
</table></body></html>


    </body>
  </html>

----==_mimepart_5952b0da41577_5c36c812ec65763542--
