General

  • Target

    2024-07-01_ac9f9b8198c987fdd42bcecf80000616_wannacry

  • Size

    5.0MB

  • Sample

    240701-msc54sxama

  • MD5

    ac9f9b8198c987fdd42bcecf80000616

  • SHA1

    5ef02a59b486bf2493ec83f57019d6200a0d141e

  • SHA256

    7a380638ed5b5db29d1d25402fd213eb607b4efc923104eac65c86f223efd4bc

  • SHA512

    01408e9e2f2e3ca87cf1e252d3d84c4353cb2ae1c9dcdaecc16936ba57897e70ada5a458082ba67546eb1a36d76465f3262217908c43f921c724466f92d30062

  • SSDEEP

    98304:yDqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2:yDqPe1Cxcxk3ZAEUadzR8yc4

Malware Config

Targets

    • Target

      2024-07-01_ac9f9b8198c987fdd42bcecf80000616_wannacry

    • Size

      5.0MB

    • MD5

      ac9f9b8198c987fdd42bcecf80000616

    • SHA1

      5ef02a59b486bf2493ec83f57019d6200a0d141e

    • SHA256

      7a380638ed5b5db29d1d25402fd213eb607b4efc923104eac65c86f223efd4bc

    • SHA512

      01408e9e2f2e3ca87cf1e252d3d84c4353cb2ae1c9dcdaecc16936ba57897e70ada5a458082ba67546eb1a36d76465f3262217908c43f921c724466f92d30062

    • SSDEEP

      98304:yDqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2:yDqPe1Cxcxk3ZAEUadzR8yc4

    • Wannacry

      WannaCry is a ransomware cryptoworm.

    • Contacts a large (3093) amount of remote hosts

      This may indicate a network scan to discover remotely running services.

    • Executes dropped EXE

    • Creates a large amount of network flows

      This may indicate a network scan to discover remotely running services.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Tasks