General

  • Target

    2024-06-28_2269823ddbaf5ebd86c0fbf207e77653_wannacry

  • Size

    5.0MB

  • Sample

    240628-mym79svhph

  • MD5

    2269823ddbaf5ebd86c0fbf207e77653

  • SHA1

    cd47c213b9383cce9fb1b4588de3a7c04f7505d3

  • SHA256

    4b98d049a24ffe08bb06abed94fe29e2fa7ed7c277faf1725a49694b516f1b30

  • SHA512

    09389f6e170247221f24d29b4191e60ef29e1a512061d161c57b0143993686843ea0818e8be570bc42e60621089fe0b4e83010ffc45d920592f452d8f8582d42

  • SSDEEP

    98304:zDqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2H:zDqPe1Cxcxk3ZAEUadzR8yc4H

Malware Config

Targets

    • Target

      2024-06-28_2269823ddbaf5ebd86c0fbf207e77653_wannacry

    • Size

      5.0MB

    • MD5

      2269823ddbaf5ebd86c0fbf207e77653

    • SHA1

      cd47c213b9383cce9fb1b4588de3a7c04f7505d3

    • SHA256

      4b98d049a24ffe08bb06abed94fe29e2fa7ed7c277faf1725a49694b516f1b30

    • SHA512

      09389f6e170247221f24d29b4191e60ef29e1a512061d161c57b0143993686843ea0818e8be570bc42e60621089fe0b4e83010ffc45d920592f452d8f8582d42

    • SSDEEP

      98304:zDqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2H:zDqPe1Cxcxk3ZAEUadzR8yc4H

    • Modifies firewall policy service

    • Wannacry

      WannaCry is a ransomware cryptoworm.

    • Contacts a large (3225) amount of remote hosts

      This may indicate a network scan to discover remotely running services.

    • Creates a large amount of network flows

      This may indicate a network scan to discover remotely running services.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Defense Evasion

Modify Registry

1
T1112

Impair Defenses

1
T1562

Disable or Modify System Firewall

1
T1562.004

Discovery

Network Service Discovery

2
T1046

Tasks