General

  • Target

    2024-07-03_00a59dcbaba9677921dca2be0a253e53_wannacry

  • Size

    3.6MB

  • Sample

    240703-lc2m4azfpn

  • MD5

    00a59dcbaba9677921dca2be0a253e53

  • SHA1

    c508c275957ba4c5cbae3388ce00828ada7fa665

  • SHA256

    0734d5ab03a578e39f01af947cec5f76bdd3f491c64bfe7f1b83aec2afc36fd9

  • SHA512

    27e2a14b19bf8ce9ec41c879dff67b8cd006fcfe38bb5b16bfabc0de7c67f7b669a919da1749d42d0c31bdf1ca44fe3b27975b3f7d8f6d93bc1447f201b12651

  • SSDEEP

    98304:XDaiEkmnft4PdpR2j50Aj4Ouenmur2uuhQ2HI:XDa6mnft4FpR2j50AjKem/uuh/HI

Malware Config

Targets

    • Target

      2024-07-03_00a59dcbaba9677921dca2be0a253e53_wannacry

    • Size

      3.6MB

    • MD5

      00a59dcbaba9677921dca2be0a253e53

    • SHA1

      c508c275957ba4c5cbae3388ce00828ada7fa665

    • SHA256

      0734d5ab03a578e39f01af947cec5f76bdd3f491c64bfe7f1b83aec2afc36fd9

    • SHA512

      27e2a14b19bf8ce9ec41c879dff67b8cd006fcfe38bb5b16bfabc0de7c67f7b669a919da1749d42d0c31bdf1ca44fe3b27975b3f7d8f6d93bc1447f201b12651

    • SSDEEP

      98304:XDaiEkmnft4PdpR2j50Aj4Ouenmur2uuhQ2HI:XDa6mnft4FpR2j50AjKem/uuh/HI

    • Wannacry

      WannaCry is a ransomware cryptoworm.

    • Contacts a large (3346) amount of remote hosts

      This may indicate a network scan to discover remotely running services.

    • Executes dropped EXE

    • Creates a large amount of network flows

      This may indicate a network scan to discover remotely running services.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Tasks