EternalRocks is a self-propagating worm first discovered on May 2, 2017, by security researcher Mi2g, who observed its rapid spread across the internet. The malware belongs to the network worm category, using a suite of seven exploits leaked from the NSA's Equation Group, including EternalBlue, EternalChampion, and EternalSynergy. No single threat actor has been publicly attributed to its creation; it is believed to have been built by an unknown individual or group as a proof-of-concept or initial access broker.
EternalRocks propagates by scanning the internet for vulnerable SMBv1 services on TCP port 445 and sequentially launching exploits from its arsenal—EternalBlue (CVE-2017-0144), EternalRomance (CVE-2017-0145), EternalChampion (CVE-2017-0146), EternalSynergy (CVE-2017-0147), Archipelago, SMBTouch, and ECLipsed. Once a host is compromised, it downloads a backdoor payload (gop.dl1) and executes a 24-hour sleep timer before activating, a technique that evades sandbox analysis. The worm uses a hardcoded domain (bwni.pw) as a kill switch; if the domain is unreachable, the malware remains dormant. No persistent C2 infrastructure has been identified; instead, the worm relies on Tor hidden services for command relay, making takedown difficult. It also disables the Windows Firewall and stops the Security Center service on infected systems.
EternalRocks emerged just weeks after the WannaCry ransomware outbreak, exploiting the same SMB vulnerabilities disclosed in the Shadow Brokers leak. The malware infected approximately 500 computers in its first few hours, according to researcher reports, but did not contain a destructive payload—it acted solely as a downloader for subsequent malware implants. No specific high-profile victims have been publicly named, but the worm’s ability to resurrect dormant exploits raised concerns about its use in future supply-chain attacks. No law enforcement actions have been reported against its operators.
Network detection can identify EternalRocks by SMBv1 exploitation attempts targeting multiple vulnerabilities in sequence and outbound connections to Tor exit nodes or the bwni.pw domain. Known file hashes include MD5: 4e6fa98b5b8e5b8e5b8e5b8e5b8e5b8e (placeholder—actual hash not widely published), but behavioral signatures include registry modifications to HKLMSYSTEMCurrentControlSetServicesSharedAccess to disable the firewall and creation of the mutex GlobalMSAccess for single-instance enforcement.
Because EternalRocks is a downloader, its primary risk lies in delivering secondary payloads such as ransomware, coin miners, or remote-access trojans. The worm can exfiltrate credentials from compromised machines and lateral move within internal networks, potentially leading to full domain compromise. Industries reliant on unpatched legacy Windows systems—such as healthcare, manufacturing, and education—face elevated exposure to subsequent attacks facilitated by EternalRocks.
Defenders should apply Microsoft security bulletin MS17-010 (patches for CVE-2017-0144 through CVE-2017-0147) to all Windows systems, block inbound TCP port 445 on perimeter firewalls, and deploy network intrusion signatures that detect sequential SMB exploit attempts. Endpoint detection and response (EDR) rules monitoring for firewall disablement and Tor connections can also flag EternalRocks activity.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.