ATT&CKReferencesFireEye WannaCry 2017

FireEye WannaCry 2017

Berry, A., Homan, J., and Eitzman, R. (2017, May 23). WannaCry Malware Profile. Retrieved March 15, 2019.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareWannaCry

WannaCry utilizes wmic to delete shadow copies.

T1083
File and Directory Discovery
MalwareWannaCry

WannaCry searches for variety of user files by file extension before encrypting them using RSA and AES, including Office, PDF, image, audio, video, source code, archive/compression format, and key and certificate files.

T1120
Peripheral Device Discovery
MalwareWannaCry

WannaCry contains a thread that will attempt to scan for new attached drives every few seconds. If one is identified, it will encrypt the files on the attached device.

T1210
Exploitation of Remote Services
MalwareWannaCry

WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network.

T1486
Data Encrypted for Impact
MalwareWannaCry

WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files.

T1489
Service Stop
MalwareWannaCry

WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores.

T1490
Inhibit System Recovery
MalwareWannaCry

WannaCry uses vssadmin, wbadmin, bcdedit, and wmic to delete and disable operating system recovery features.

T1543.003
Windows Service
MalwareWannaCry

WannaCry creates the service "mssecsvc2.0" with the display name "Microsoft Security Center (2.0) Service."

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.