Noerenberg, E., Costis, A., and Quist, N. (2017, May 16). A Technical Analysis of WannaCry Ransomware. Retrieved December 8, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareWannaCry | WannaCry utilizes |
| T1083 File and Directory Discovery |
MalwareWannaCry | WannaCry searches for variety of user files by file extension before encrypting them using RSA and AES, including Office, PDF, image, audio, video, source code, archive/compression format, and key and certificate files. |
| T1210 Exploitation of Remote Services |
MalwareWannaCry | WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network. |
| T1222.001 Windows Permissions |
MalwareWannaCry | WannaCry uses |
| T1486 Data Encrypted for Impact |
MalwareWannaCry | WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files. |
| T1490 Inhibit System Recovery |
MalwareWannaCry | WannaCry uses |
| T1543.003 Windows Service |
MalwareWannaCry | WannaCry creates the service "mssecsvc2.0" with the display name "Microsoft Security Center (2.0) Service." |
| T1563.002 RDP Hijacking |
MalwareWannaCry | WannaCry enumerates current remote desktop sessions and tries to execute the malware on each session. |
| T1564.001 Hidden Files and Directories |
Toolattrib | attrib can be used to make files or directories hidden. |
| T1564.001 Hidden Files and Directories |
MalwareWannaCry | |
| T1570 Lateral Tool Transfer |
MalwareWannaCry | WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.