This malware somehow got seeded, either by (1) direct scanning the internet for vulnerable systems, or (2) traditional "open-this-link / install-this-file" emails/downloads. Maybe that's why we see at least 3 bitcoin addresses: 3 different "seeding" groups.
Corp networks shouldn't be accepting outside SMB connections, and home routers will block them too, so that's where user-initiated emails/downloads come in (or someone connecting an outside laptop).
To mitigate, you can disable SMB1.0 with the following command. Make sure to run as administrator:
dism /online /norestart /disable-feature /featurename:SMB1Protocol
[0]: https://news.ycombinator.com/item?id=14335845Also note that only works on windows 7 and later, dism is not a tool for XP or Windows 2003 which seem to be the largest numbers hit by this since there is/was no patches for them
I'm all for recommending defence in depth, but please study changes like this before doing them.