ATT&CKReferencesSecureWorks WannaCry Analysis

SecureWorks WannaCry Analysis

Counter Threat Unit Research Team. (2017, May 18). WCry Ransomware Analysis. Retrieved March 26, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareWannaCry

WannaCry will attempt to determine the local network segment it is a part of.

T1018
Remote System Discovery
MalwareWannaCry

WannaCry scans its local network segment for remote systems to try to exploit and copy itself to.

T1047
Windows Management Instrumentation
MalwareWannaCry

WannaCry utilizes wmic to delete shadow copies.

T1090.003
Multi-hop Proxy
MalwareWannaCry

WannaCry uses Tor for command and control traffic.

T1486
Data Encrypted for Impact
MalwareWannaCry

WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files.

T1489
Service Stop
MalwareWannaCry

WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores.

T1490
Inhibit System Recovery
MalwareWannaCry

WannaCry uses vssadmin, wbadmin, bcdedit, and wmic to delete and disable operating system recovery features.

T1573.002
Asymmetric Cryptography
MalwareWannaCry

WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.