I have put together a little "petri dish" test environment and started looking for a sample that has the exploit. Some samples out there simply do not have the exploit code, and even tough they will encrypt the files locally, sometimes the mounted shares too, they would not spread.
Luckily, I have found this nice blog post from McAfee Labs: https://securingtomorrow.mcafee.com/mcafee-labs/analysis-wannacry-ransomware/ with the reference to the sample SHA256: 24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c (they keep referring to samples with MD5, which is still a very-very bad practice, but the hash is MD5: DB349B97C37D22F5EA1D1841E3C89EB4)
Once I got the sample from the VxStream Sandbox site, dropped it in the test environment, and monitored it with Security Onion. I was super happy to see it spreading, despite the fact that for the first run my Windows 7 x64 VM went to BSOD as the EthernalBlue exploit failed.
But the second run was a full success, all my Windows 7 VMs got infected. Brad was so kind and made a guest blog post at one of my favorite sites, www.malware-traffic-analysis.net so you can find the pcap, description of the test environment and some screenshots here: http://malware-traffic-analysis.net/2017/05/18/index2.html
More articles
- Pentest Tools Subdomain
- Hacker Tools Github
- Pentest Tools For Mac
- Hacking Apps
- Tools 4 Hack
- Hacking Tools Mac
- Pentest Tools Find Subdomains
- Usb Pentest Tools
- Hacker Tools Free
- Hack Apps
- Hacking Tools For Games
- What Is Hacking Tools
- Hacker Tools Apk Download
- How To Install Pentest Tools In Ubuntu
- Hack Rom Tools
- Pentest Tools Bluekeep
- Pentest Tools For Mac
- Pentest Tools Bluekeep
- Hacks And Tools
- Hacker Search Tools
- Tools 4 Hack
- Hacker Tools Software
- Pentest Tools Free
- Pentest Tools List
- Wifi Hacker Tools For Windows
- Hacking Tools For Windows
- How To Make Hacking Tools
- Pentest Tools Url Fuzzer
- Hacking Apps
- Pentest Tools Framework
- Hacking Tools Usb
- Github Hacking Tools
- Hack App
- Hacking Tools Windows 10
- Pentest Tools Port Scanner
- Hacker Tools Online
- Hacker Tools Online
- Pentest Tools
- Pentest Tools Framework
- Pentest Tools Android
- Best Hacking Tools 2020
- Hacker Tools Apk Download
- Hacker Tools 2020
- Pentest Tools Online
- Ethical Hacker Tools
- Hacker Tools Github
- Hacking Tools Github
- Tools For Hacker
- Nsa Hack Tools Download
- Pentest Tools Tcp Port Scanner
- Hack Tools Mac
- How To Make Hacking Tools
- Hack Tools
- Termux Hacking Tools 2019
- Blackhat Hacker Tools
- Hacker Tools Free
- Hacker Tools 2020
- Hacking Tools Github
- Hacker Tools Free
- Hacking Tools For Windows
- Hacker Tools Apk
- Hacking Tools And Software
- Tools Used For Hacking
- Pentest Box Tools Download
- Pentest Tools For Mac
- Black Hat Hacker Tools
- Black Hat Hacker Tools
- What Are Hacking Tools
- Pentest Tools Alternative
- Hacker Techniques Tools And Incident Handling
- Hacker Tools For Windows
- Android Hack Tools Github
- Hacking Tools 2020
- Hacking Tools Name
- Game Hacking
- Underground Hacker Sites
- Hacking Tools For Windows
- Kik Hack Tools
- Hacking Tools Hardware
No comments:
Post a Comment