General

  • Target

    a4bcdafc355b18a8284d808effda6f07556eccdb8e057a58e6a022ad6c59fb3b

  • Size

    5.0MB

  • Sample

    240702-ywq2xswhnb

  • MD5

    9a2cf2f27f17af69be38bc38c9a976b6

  • SHA1

    9b6d1038e67c1bd80fbff19d06d353a03975d3df

  • SHA256

    a4bcdafc355b18a8284d808effda6f07556eccdb8e057a58e6a022ad6c59fb3b

  • SHA512

    3134f0994d4e77c0e01f1998287d14d13db81a619d8fe64db6050cdfcde04bd20fc25858b1c81e01c1010664f01402d4b9705bceac700d7a9320228619f16026

  • SSDEEP

    49152:Sny21INRx+TSqTdX1HkQo6SAARdhnvxJM0H9PAMEcaEau3RCgHAD:+y21aRxcSUDk36SAEdhvxWa9P593R

Malware Config

Targets

    • Target

      a4bcdafc355b18a8284d808effda6f07556eccdb8e057a58e6a022ad6c59fb3b

    • Size

      5.0MB

    • MD5

      9a2cf2f27f17af69be38bc38c9a976b6

    • SHA1

      9b6d1038e67c1bd80fbff19d06d353a03975d3df

    • SHA256

      a4bcdafc355b18a8284d808effda6f07556eccdb8e057a58e6a022ad6c59fb3b

    • SHA512

      3134f0994d4e77c0e01f1998287d14d13db81a619d8fe64db6050cdfcde04bd20fc25858b1c81e01c1010664f01402d4b9705bceac700d7a9320228619f16026

    • SSDEEP

      49152:Sny21INRx+TSqTdX1HkQo6SAARdhnvxJM0H9PAMEcaEau3RCgHAD:+y21aRxcSUDk36SAEdhvxWa9P593R

    • Wannacry

      WannaCry is a ransomware cryptoworm.

    • Contacts a large (3074) amount of remote hosts

      This may indicate a network scan to discover remotely running services.

    • Executes dropped EXE

    • Creates a large amount of network flows

      This may indicate a network scan to discover remotely running services.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Tasks