Netskope Threat Labs

EternalBlue

ATP Sandbox Adv. HeuristicsAV

EternalBlue (a.k.a. MS17-010) is an exploit targeting a vulnerability in the Windows Server Message Block protocol that lets cyberattackers execute code on vulnerable systems without credentials. Leaked from a state sponsored arsenal in 2017, it powered the WannaCry and NotPetya outbreaks and remains a fixture of criminal toolkits for spreading ransomware and other malware across networks. Patching remains essential because cyberattackers continue to scan and exploit unpatched Windows systems at scale.

First seen
July 2022
Last seen
September 2026
Alert Name
DeepScan:Generic.Exploit.EternalBlue.A.FFFFFFFE
Document-XML.Trojan.EternalBlue
Dump:Generic.Exploit.EternalBlue.A.FFFFFFFE
Generic.Exploit.EternalBlue.A.0036F9E9
Generic.Exploit.EternalBlue.A.0046563B
Generic.Exploit.EternalBlue.A.00AD492A
Generic.Exploit.EternalBlue.A.01889A11
Generic.Exploit.EternalBlue.A.01A7FDD0
Generic.Exploit.EternalBlue.A.01AD97AC
Generic.Exploit.EternalBlue.A.020EE81E