Counter Threat Unit Research Team. (2017, May 18). WCry Ransomware Analysis. Retrieved March 26, 2019.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareWannaCry | WannaCry will attempt to determine the local network segment it is a part of. |
| T1018 Remote System Discovery |
MalwareWannaCry | WannaCry scans its local network segment for remote systems to try to exploit and copy itself to. |
| T1047 Windows Management Instrumentation |
MalwareWannaCry | WannaCry utilizes |
| T1090.003 Multi-hop Proxy |
MalwareWannaCry | |
| T1486 Data Encrypted for Impact |
MalwareWannaCry | WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files. |
| T1489 Service Stop |
MalwareWannaCry | WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores. |
| T1490 Inhibit System Recovery |
MalwareWannaCry | WannaCry uses |
| T1573.002 Asymmetric Cryptography |
MalwareWannaCry | WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.