mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
6ce7ebadf2
* Create malware-types.md * Update README.md added link to malware type table. * Update malware-types.md * Update malware-types.md * Update malware-types.md * Update malware-types.md * Update malware-types.md * Update malware-types.md * Update geneio.md * Update geneio.md * Update searchawesome.md * Update chopstick.md * Update cozycar.md * Update gobotkr.md * Update heriplor.md * Update hupigon.md * Update synful-knock.md * Update mebromi.md * Update blackenergy.md * Update cozycar.md * Update cozycar.md * Update drovorub.md * Update evilbunny.md * Update gamut.md * Update gobotkr.md * Update cozycar.md * Update kovter.md * Update kraken.md * Update mazarbot.md * Update blackenergy.md * Update matanbuchus.md * Update yispecter.md * Update cozycar.md * Update up007.md * Update teardrop.md * Update redhip.md * Update malware-types.md * Update rombertik.md * Update snake.md * Update snake.md * Update dark-comet.md * Update badusb.md * Update dyepack.md * Update conti.md * Update cryptolocker.md * Update cryptowall.md * Update locky-bart.md * Update netwalker.md * Update samsam.md * Update wannacry.md * Update adwind-jrat.md * Update electrorat.md * Update gravity-rat.md * Update poison-ivy.md * Update terminator.md * Update clipminer.md * Update webcobra.md * Update drovorub.md * Update dark-comet.md * Update attor.md * Update geneio.md * Update malware-types.md * Update trickbot.md * Update dark-comet.md * Update dnschanger.md * Update emotet.md * Update kovter.md * Update heriplor.md * Update trickbot.md * Update ursnif.md * Update mazarbot.md * Update shamoon.md * Update bagle.md * Update conficker.md * Update stuxnet.md * Update vobfus.md * Newsletter, editing E1510, E1560 (#137) (#138) * Adding Newsletter * Create 12182023.md * Update README.md --------- * Update e1510 (#134) * Update clipboard-modification.md Update to account for updates to T1115. * Update data-encrypted-for-impact.md fix parentheses * Update clipboard-modification.md * Update data-encrypted-for-impact.md * Update clipboard-modification.md * Moving Archive Collected Data to collection, some description updates * Updating Last Modified --------- Co-authored-by: Ryan Xu <ryanxu@wustl.edu> * Newsletter, editing E1510, E1560 (#137) (#139) * Adding Newsletter * Create 12182023.md * Update README.md --------- * Update e1510 (#134) * Update clipboard-modification.md Update to account for updates to T1115. * Update data-encrypted-for-impact.md fix parentheses * Update clipboard-modification.md * Update data-encrypted-for-impact.md * Update clipboard-modification.md * Moving Archive Collected Data to collection, some description updates * Updating Last Modified --------- Co-authored-by: Ryan Xu <ryanxu@wustl.edu> --------- Co-authored-by: Ryan Xu <ryanxu@wustl.edu>
2.2 KiB
2.2 KiB
| ID | X0043 |
| Type | Ransomware |
| Aliases | None |
| Platforms | Windows |
| Year | 2017 |
| Associated ATT&CK Software | WannaCry |
WannaCry
WannaCry is ransomware that was first seen in a global attack during May 2017, which affected more than 150 countries. It contains worm-like features to spread across a computer network using the SMBv1 exploit EternalBlue. [1]
ATT&CK Techniques
See ATT&CK: WannaCry - Techniques Used.
Enhanced ATT&CK Techniques
| Name | Use |
|---|---|
| Defense Evasion:: Hidden Files and Directories(F0005.003) | WannaCry uses the +h attribute to hide its files. [1] |
| Persistence::Registry Run Keys / Startup Folder (F0012) | WannaCry creates two registry run keys to ensure persistence. [1] |
| Defense-Evasion::Self Deletion (F0007) | WannaCry looks for a DNS entry and if the entry exists, it terminates and deletes itself. [1] |
| Impact::Data Encrypted for Impact (E1486) | WannaCry encrypts files for ransom. [1] |
MBC Behaviors
| Name | Use |
|---|---|
| Discovery::Self Discovery (B0038) | WannaCry checks the size of the file it loads into memory. [1] |
| Discovery::Self Discovery (B0038.002) | WannaCry checks a string, keylen and a magic number before decrypting a dll. [1] |
| Discovery::Self Discovery (B0038.003) | WannaCry checks the data lengh of a section before decypting a dll. [1] |
Indicators of Compromise
MD5 Hashes
- db349b97c37d22f5ea1d1841e3c89eb4
- 84c82835a5d21bbcf75a61706d8ab549
- f351e1fcca0c4ea05fc44d15a17f8b36
- 7bf2b57f2a205768755c07f238fb32cc
References
[1] https://www.mandiant.com/resources/blog/wannacry-malware-profile