WannaCry

S0366

Malware.View on attack.mitre.org

About this malware

WannaCry is ransomware that was first seen in a global attack during May 2017, which affected more than 150 countries. It contains worm-like features to spread itself across a computer network using the SMBv1 exploit EternalBlue.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1016
System Network Configuration Discovery

WannaCry will attempt to determine the local network segment it is a part of.

T1018
Remote System Discovery

WannaCry scans its local network segment for remote systems to try to exploit and copy itself to.

T1047
Windows Management Instrumentation

WannaCry utilizes wmic to delete shadow copies.

T1083
File and Directory Discovery

WannaCry searches for variety of user files by file extension before encrypting them using RSA and AES, including Office, PDF, image, audio, video, source code, archive/compression format, and key and certificate files.

T1090.003
Multi-hop Proxy

WannaCry uses Tor for command and control traffic.

T1120
Peripheral Device Discovery

WannaCry contains a thread that will attempt to scan for new attached drives every few seconds. If one is identified, it will encrypt the files on the attached device.

T1210
Exploitation of Remote Services

WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network.

T1222.001
Windows Permissions

WannaCry uses attrib +h and icacls . /grant Everyone:F /T /C /Q to make some of its files hidden and grant all users full access controls.

T1486
Data Encrypted for Impact

WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files.

T1489
Service Stop

WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores.

T1490
Inhibit System Recovery

WannaCry uses vssadmin, wbadmin, bcdedit, and wmic to delete and disable operating system recovery features.

T1543.003
Windows Service

WannaCry creates the service "mssecsvc2.0" with the display name "Microsoft Security Center (2.0) Service."

T1563.002
RDP Hijacking

WannaCry enumerates current remote desktop sessions and tries to execute the malware on each session.

T1564.001
Hidden Files and Directories

WannaCry uses attrib +h to make some of its files hidden.

T1570
Lateral Tool Transfer

WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. FireEye WannaCry 2017 Open source
    Berry, A., Homan, J., and Eitzman, R. (2017, May 23). WannaCry Malware Profile. Retrieved March 15, 2019.
  2. LogRhythm WannaCry Open source
    Noerenberg, E., Costis, A., and Quist, N. (2017, May 16). A Technical Analysis of WannaCry Ransomware. Retrieved December 8, 2024.
  3. US-CERT WannaCry 2017 Open source
    US-CERT. (2017, May 12). Alert (TA17-132A): Indicators Associated With WannaCry Ransomware. Retrieved March 25, 2019.
  4. Washington Post WannaCry 2017 Open source
    Dwoskin, E. and Adam, K. (2017, May 14). More than 150 countries affected by massive cyberattack, Europol says. Retrieved March 25, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.