General

  • Target

    2024-06-30_57dc0af3c047a9a921d83bf9bd29db24_wannacry

  • Size

    5.0MB

  • Sample

    240630-nrc96axbqa

  • MD5

    57dc0af3c047a9a921d83bf9bd29db24

  • SHA1

    99a1525142982223c94b6d31c73316066fd606a1

  • SHA256

    ab5e9eef3cb5bdc64e0b9a76ec07a61dab97f3bea60a586cc0a47cf2a4bbabf1

  • SHA512

    b1d8c98d6640d68b778eb4aaa65313b9c7ec9af0836a31831e1692fdd4149f4f2494b500b940c91fbc1f793d4ad68c9fce78b14d850b371558628d6bcef04692

  • SSDEEP

    98304:psqPoBhzhaRxcSUDk36SAEdhvxWa9P593R8yAVp2H:psqPehCxcxk3ZAEUadzR8yc4H

Malware Config

Targets

    • Target

      2024-06-30_57dc0af3c047a9a921d83bf9bd29db24_wannacry

    • Size

      5.0MB

    • MD5

      57dc0af3c047a9a921d83bf9bd29db24

    • SHA1

      99a1525142982223c94b6d31c73316066fd606a1

    • SHA256

      ab5e9eef3cb5bdc64e0b9a76ec07a61dab97f3bea60a586cc0a47cf2a4bbabf1

    • SHA512

      b1d8c98d6640d68b778eb4aaa65313b9c7ec9af0836a31831e1692fdd4149f4f2494b500b940c91fbc1f793d4ad68c9fce78b14d850b371558628d6bcef04692

    • SSDEEP

      98304:psqPoBhzhaRxcSUDk36SAEdhvxWa9P593R8yAVp2H:psqPehCxcxk3ZAEUadzR8yc4H

    • Wannacry

      WannaCry is a ransomware cryptoworm.

    • Contacts a large (3307) amount of remote hosts

      This may indicate a network scan to discover remotely running services.

    • Executes dropped EXE

    • Creates a large amount of network flows

      This may indicate a network scan to discover remotely running services.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Tasks