PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteEternalRocks was a self-replicating worm reported in May 2017 that used EternalBlue and other leaked tools to spread through vulnerable Windows systems. But the headline comparison is not a measured impact claim: CERT-EU reported more than 200,000 computers affected worldwide by WannaCry, while the sources reviewed do not establish a comparable EternalRocks infection count. The key difference was behavior: WannaCry encrypted files and demanded a ransom; the EternalRocks sample described by NHS England Digital did not lock or corrupt files.
How was EternalRocks different from WannaCry?
Both threats were associated with SMB, the Windows networking protocol used for file and printer sharing and remote services. Microsoft described WannaCry as ransomware with a worm-like SMB spreading mechanism, using EternalBlue against SMBv1. NHS England Digital reported that EternalRocks also used EternalBlue, alongside other leaked tools.
| Comparison | WannaCry | EternalRocks |
|---|---|---|
| Reported behavior | Encrypted files and displayed a ransom message, according to Microsoft’s May 12, 2017 analysis. | The sample described in the NHS England Digital alert dated May 24, 2017 did not lock or corrupt files. |
| SMB connection | Microsoft said it spread through SMBv1 using EternalBlue. | NHS England Digital reported EternalBlue and other leaked tools. |
| Kill switch | CERT-EU’s 2017 advisory describes WannaCry variants with sinkhole or kill-switch domains. | The NHS alert said EternalRocks had no corresponding kill switch. |
| Delay | The cited Microsoft analysis does not describe a comparable 24-hour activation delay. | The NHS alert reported a 24-hour delay intended to frustrate analysis. |
| Measured scale | CERT-EU reported more than 200,000 computers affected worldwide. | No comparable infection count is established in the sources reviewed. |
That distinction matters: EternalRocks was described as potentially dangerous because of its propagation capabilities and delayed activation, not because a larger outbreak or greater damage total was documented. The historical reports do not support calling it ransomware.
What did EternalRocks use to spread?
SMB is used for network communication and file sharing. Mandiant describes SMB traffic on TCP ports 139 and 445; WannaCry’s propagation used SMBv1 over TCP 445. See Mandiant’s WannaCry malware profile for technical context.
The reported tool count depends on how sources group the components. NHS England Digital said EternalRocks used “7 other NSA tools” in addition to EternalBlue. CCN-CERT’s alert describes seven SMB-related exploits or tools. A technical repository lists four named Eternal* exploits plus DoublePulsar, ArchiTouch, and SMBTouch. These descriptions should not be collapsed into a single unqualified count.
The repository records May 3, 2017 as the date of its oldest known sample. Its tool list is documented at ESET’s EternalRocks technical repository. This is a historical sample date, not evidence that the threat remains widespread today.
Was EternalRocks bigger than WannaCry?
There is no evidence in these reports to say so. CERT-EU recorded more than 200,000 computers affected worldwide by WannaCry in 2017; that figure belongs to WannaCry and must not be transferred to EternalRocks. The reviewed sources offer no comparable EternalRocks infection count or damage total.
The chronology also helps keep the comparison in perspective: Microsoft released the MS17-010 security update for supported Windows versions on March 14, 2017; the earliest known EternalRocks sample in the technical repository is dated May 3; the large WannaCry campaign began May 12; and the NHS England Digital EternalRocks alert followed on May 24. These dates describe 2017 events, not present-day prevalence.
Recommended Free Tools
Rank #3
What should organizations do about SMB exposure?
The advisories’ practical lesson is to patch affected systems and limit unnecessary SMB exposure. The appropriate configuration depends on the systems and services an organization needs; apply current vendor guidance rather than assuming a 2017 alert covers every present-day configuration.
- Install the relevant security updates. The EternalRocks alert recommends updating affected Windows platforms in line with MS17-010. Microsoft’s MS17-010 security bulletin documents the update.
- Review SMBv1. CERT-EU and CIS/MS-ISAC recommend disabling SMBv1 where appropriate. Check compatibility and operational dependencies before disabling it.
- Restrict inbound SMB. CERT-EU and CIS/MS-ISAC recommend controls on inbound SMB, including blocking port 445 where it is not required. NHS England Digital also advises considering blocks on SMB-related ports at an organization’s external firewall.
- Find and contain vulnerable systems. Identify susceptible devices; isolate, update, or shut down systems that cannot be promptly secured, following the organization’s incident procedures.
These are system-administration measures, not a claim that every network should disable every SMB service. Microsoft’s bulletin and the cited advisories should be consulted for the affected platforms and applicable guidance.
Rank #4
- Cybersecurity.
- This merchandise, which shows a computer cybersecurity word cloud design, is ideal for computer programmers, coders, and hackers. It is also for software engineer or software developers, as well as information technology or computer science majors.
- Hardcover journal with 240 line-ruled pages (120 sheets)
- Built-in elastic closure and ribbon bookmark
- Includes an expandable inner storage pocket and a pen holder
What the reports do—and do not—say about WannaCry’s entry
Microsoft’s May 12, 2017 analysis said the exact initial entry vector had not been established at publication and discussed email execution and SMB exploitation as plausible scenarios. That uncertainty concerns WannaCry; it should not be recast as a finding about EternalRocks.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Further reading
For broader cyberwar history rather than a technical guide to EternalRocks, Andy Greenberg’s Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin’s Most Dangerous Hackers is listed by Penguin Random House as a Vintage paperback, ISBN 9780525564638, published October 20, 2020.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Quick Recap
Best Value
- Cybersecurity Cyber Security Computer Security Date A Hacker Design for Cybersecurity Awareness Lovers
- Date A Hacker We Break Security Not Hearts. For people thinking of Funny Cybersecurity Cyber Security Awareness Gift Ideas
- Hardcover journal with 240 line-ruled pages (120 sheets)
- Built-in elastic closure and ribbon bookmark
- Includes an expandable inner storage pocket and a pen holder
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

