General

  • Target

    2024-07-02_5e4141fca37ba4bf2597da77151260fd_wannacry

  • Size

    5.0MB

  • Sample

    240702-sh44qsxhqe

  • MD5

    5e4141fca37ba4bf2597da77151260fd

  • SHA1

    8461490ea75a3c63b18d941108a8d882770e27fe

  • SHA256

    9bcf631b31c8b3532b67a5541b103d4085f07f59fe00f125b909da725eb14843

  • SHA512

    771681b123fe13538c03723bcc9afd4b184cd1902fcf3696a71b21c563cf4e5f5909dde09df124f5d846683c4ac6ac8df9d1ba86b4fad209bd61574c89149a46

  • SSDEEP

    49152:2nAQqMSPbcBVQej/1INRx+TSqTdX1HkQo6SAARdhnvxJM0H9PAMEcaEa:yDqPoBhz1aRxcSUDk36SAEdhvxWa9P5

Malware Config

Targets

    • Target

      2024-07-02_5e4141fca37ba4bf2597da77151260fd_wannacry

    • Size

      5.0MB

    • MD5

      5e4141fca37ba4bf2597da77151260fd

    • SHA1

      8461490ea75a3c63b18d941108a8d882770e27fe

    • SHA256

      9bcf631b31c8b3532b67a5541b103d4085f07f59fe00f125b909da725eb14843

    • SHA512

      771681b123fe13538c03723bcc9afd4b184cd1902fcf3696a71b21c563cf4e5f5909dde09df124f5d846683c4ac6ac8df9d1ba86b4fad209bd61574c89149a46

    • SSDEEP

      49152:2nAQqMSPbcBVQej/1INRx+TSqTdX1HkQo6SAARdhnvxJM0H9PAMEcaEa:yDqPoBhz1aRxcSUDk36SAEdhvxWa9P5

    • Wannacry

      WannaCry is a ransomware cryptoworm.

    • Contacts a large (3357) amount of remote hosts

      This may indicate a network scan to discover remotely running services.

    • Executes dropped EXE

    • Creates a large amount of network flows

      This may indicate a network scan to discover remotely running services.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Tasks