Wednesday, April 15, 2020

Pcap Of Wannacry Spreading Using EthernalBlue

Saw that a lot of people were looking for a pcap with WannaCry spreading Using EthernalBlue.

I have put together a little "petri dish" test environment and started looking for a sample that has the exploit. Some samples out there simply do not have the exploit code, and even tough they will encrypt the files locally, sometimes the mounted shares too, they would not spread.

Luckily, I have found this nice blog post from McAfee Labs: https://securingtomorrow.mcafee.com/mcafee-labs/analysis-wannacry-ransomware/ with the reference to the sample SHA256: 24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c (they keep referring to samples with MD5, which is still a very-very bad practice, but the hash is MD5: DB349B97C37D22F5EA1D1841E3C89EB4)

Once I got the sample from the VxStream Sandbox site, dropped it in the test environment, and monitored it with Security Onion. I was super happy to see it spreading, despite the fact that for the first run my Windows 7 x64 VM went to BSOD as the EthernalBlue exploit failed.

But the second run was a full success, all my Windows 7 VMs got infected. Brad was so kind and made a guest blog post at one of my favorite sites, www.malware-traffic-analysis.net so you can find the pcap, description of the test environment and some screenshots here: http://malware-traffic-analysis.net/2017/05/18/index2.html
Read more

  1. Hacker Security Tools
  2. Hacking Tools Mac
  3. Hacking App
  4. Hack Tools
  5. Ethical Hacker Tools
  6. Easy Hack Tools
  7. Hack Tools
  8. Best Hacking Tools 2019
  9. Hacker Tools Software
  10. Hack Tools For Windows
  11. Ethical Hacker Tools
  12. Hacking Tools Pc
  13. Hacking Tools Windows
  14. Hacking Tools Hardware
  15. Hacker Tools Apk
  16. Hackrf Tools
  17. Pentest Tools Website Vulnerability
  18. Pentest Tools Apk
  19. Pentest Tools Bluekeep
  20. Hacker Security Tools
  21. Hak5 Tools
  22. Nsa Hack Tools
  23. Pentest Tools Find Subdomains
  24. Hacking Tools For Kali Linux
  25. Hack Tools For Mac
  26. Pentest Tools Alternative
  27. Hack Tools
  28. Pentest Reporting Tools
  29. Pentest Tools For Windows

No comments:

Post a Comment