General

  • Target

    2024070421dce6c905c9fbb2278e011ba90092f8wannacry

  • Size

    5.0MB

  • Sample

    240704-r2cyxszfkf

  • MD5

    21dce6c905c9fbb2278e011ba90092f8

  • SHA1

    2297f04e64d6ead232f94e8b72e6b0268c1aec23

  • SHA256

    04af15b0eeeca5310566b14c58ecf68d71be2f9803a8d4bf64a95fc477c414e8

  • SHA512

    a6978fea520676ed11b76d104aa13a0e412251c734a0fd0a1da0a1e7866f0423cbf9aae3a112b89b56cc699e8cee3b3040bc941aeec82b95c1df13203cb5f589

  • SSDEEP

    98304:DDqPoBhz1aRxcSUZk36SAEdhvxWa9P593R8yAVp2H:DDqPe1Cxc7k3ZAEUadzR8yc4H

Malware Config

Targets

    • Target

      2024070421dce6c905c9fbb2278e011ba90092f8wannacry

    • Size

      5.0MB

    • MD5

      21dce6c905c9fbb2278e011ba90092f8

    • SHA1

      2297f04e64d6ead232f94e8b72e6b0268c1aec23

    • SHA256

      04af15b0eeeca5310566b14c58ecf68d71be2f9803a8d4bf64a95fc477c414e8

    • SHA512

      a6978fea520676ed11b76d104aa13a0e412251c734a0fd0a1da0a1e7866f0423cbf9aae3a112b89b56cc699e8cee3b3040bc941aeec82b95c1df13203cb5f589

    • SSDEEP

      98304:DDqPoBhz1aRxcSUZk36SAEdhvxWa9P593R8yAVp2H:DDqPe1Cxc7k3ZAEUadzR8yc4H

    • Modifies firewall policy service

    • Wannacry

      WannaCry is a ransomware cryptoworm.

    • Contacts a large (3304) amount of remote hosts

      This may indicate a network scan to discover remotely running services.

    • Creates a large amount of network flows

      This may indicate a network scan to discover remotely running services.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Defense Evasion

Modify Registry

1
T1112

Impair Defenses

1
T1562

Disable or Modify System Firewall

1
T1562.004

Discovery

Network Service Discovery

2
T1046

Tasks