MITREExplained
MITREExplained
u.wnry
taskse.exe
mssecsvc.exe Delete
taskdl.exe
3
tasksche.exe Copy Encrypt
mssecsvc2.0
Sets Up Service
Sources: Cisco webinar (Anatomy of the attacks: WannaCry ransomware and Google OAuth phishing)
https://www.fireeye.com/blog/threat-research/2017/05/wannacry-malware-profile.html
Cyber Kill Chain® Background
Package & Delivery Load & Run Encryption Replication Ransom / Extortion
1 ETERNAL BLUE
Subnet
TCP 445
2 DOUBLE PULSAR 4
Scan IP
Scan IP
TCP 445
Subnets
3 Backdoor
Implant
C&C Channel
Kernel execution of:
-ping
-kill
-exec
Source: https://isc.sans.edu/forums/diary/Detecting+SMB+Covert+Channel+Double+Pulsar/22312/; Wikipedia