Malware.View on attack.mitre.org
WannaCry is ransomware that was first seen in a global attack during May 2017, which affected more than 150 countries. It contains worm-like features to spread itself across a computer network using the SMBv1 exploit EternalBlue.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
WannaCry will attempt to determine the local network segment it is a part of. |
| T1018 Remote System Discovery |
WannaCry scans its local network segment for remote systems to try to exploit and copy itself to. |
| T1047 Windows Management Instrumentation |
WannaCry utilizes |
| T1083 File and Directory Discovery |
WannaCry searches for variety of user files by file extension before encrypting them using RSA and AES, including Office, PDF, image, audio, video, source code, archive/compression format, and key and certificate files. |
| T1090.003 Multi-hop Proxy |
|
| T1120 Peripheral Device Discovery |
WannaCry contains a thread that will attempt to scan for new attached drives every few seconds. If one is identified, it will encrypt the files on the attached device. |
| T1210 Exploitation of Remote Services |
WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network. |
| T1222.001 Windows Permissions |
WannaCry uses |
| T1486 Data Encrypted for Impact |
WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files. |
| T1489 Service Stop |
WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores. |
| T1490 Inhibit System Recovery |
WannaCry uses |
| T1543.003 Windows Service |
WannaCry creates the service "mssecsvc2.0" with the display name "Microsoft Security Center (2.0) Service." |
| T1563.002 RDP Hijacking |
WannaCry enumerates current remote desktop sessions and tries to execute the malware on each session. |
| T1564.001 Hidden Files and Directories |
|
| T1570 Lateral Tool Transfer |
WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.