General

  • Target

    20240704f125b96600cc95e4d4f6e3fc4a6fff47wannacry

  • Size

    5.0MB

  • Sample

    240704-r6zcqayajk

  • MD5

    f125b96600cc95e4d4f6e3fc4a6fff47

  • SHA1

    b1ae7a28971dca3f3f1034c2471f797e5dfef6de

  • SHA256

    f9488380f518f065fceedc417885f79fa90fce648fb7d1e6684cc7c20d1ef97e

  • SHA512

    9f7a2d706f6c80f876684d50e72419e891130d25dd8f042a3f9b0ca370a6b1d96364ed14bb828c08f36b153df16160bef2e30215d2ee753047ee522e7b971330

  • SSDEEP

    49152:VnjQqMSPbcBVQej/1INRx+TSqTdX1HkQo6SAARdhnvxJM0H9:Z8qPoBhz1aRxcSUDk36SAEdhvxWa9

Malware Config

Targets

    • Target

      20240704f125b96600cc95e4d4f6e3fc4a6fff47wannacry

    • Size

      5.0MB

    • MD5

      f125b96600cc95e4d4f6e3fc4a6fff47

    • SHA1

      b1ae7a28971dca3f3f1034c2471f797e5dfef6de

    • SHA256

      f9488380f518f065fceedc417885f79fa90fce648fb7d1e6684cc7c20d1ef97e

    • SHA512

      9f7a2d706f6c80f876684d50e72419e891130d25dd8f042a3f9b0ca370a6b1d96364ed14bb828c08f36b153df16160bef2e30215d2ee753047ee522e7b971330

    • SSDEEP

      49152:VnjQqMSPbcBVQej/1INRx+TSqTdX1HkQo6SAARdhnvxJM0H9:Z8qPoBhz1aRxcSUDk36SAEdhvxWa9

    • Wannacry

      WannaCry is a ransomware cryptoworm.

    • Contacts a large (3076) amount of remote hosts

      This may indicate a network scan to discover remotely running services.

    • Executes dropped EXE

    • Creates a large amount of network flows

      This may indicate a network scan to discover remotely running services.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Tasks