Sunday 19 April 2020

Pcap Of Wannacry Spreading Using EthernalBlue

Saw that a lot of people were looking for a pcap with WannaCry spreading Using EthernalBlue.

I have put together a little "petri dish" test environment and started looking for a sample that has the exploit. Some samples out there simply do not have the exploit code, and even tough they will encrypt the files locally, sometimes the mounted shares too, they would not spread.

Luckily, I have found this nice blog post from McAfee Labs: https://securingtomorrow.mcafee.com/mcafee-labs/analysis-wannacry-ransomware/ with the reference to the sample SHA256: 24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c (they keep referring to samples with MD5, which is still a very-very bad practice, but the hash is MD5: DB349B97C37D22F5EA1D1841E3C89EB4)

Once I got the sample from the VxStream Sandbox site, dropped it in the test environment, and monitored it with Security Onion. I was super happy to see it spreading, despite the fact that for the first run my Windows 7 x64 VM went to BSOD as the EthernalBlue exploit failed.

But the second run was a full success, all my Windows 7 VMs got infected. Brad was so kind and made a guest blog post at one of my favorite sites, www.malware-traffic-analysis.net so you can find the pcap, description of the test environment and some screenshots here: http://malware-traffic-analysis.net/2017/05/18/index2.html
More info

  1. Pentest Automation Tools
  2. Hacking Tools For Windows 7
  3. Hacking Apps
  4. Tools Used For Hacking
  5. Black Hat Hacker Tools
  6. Hacking Tools Windows 10
  7. Best Pentesting Tools 2018
  8. Hacking Tools Windows
  9. Hacks And Tools
  10. Hacking Tools For Kali Linux
  11. Beginner Hacker Tools
  12. Pentest Tools Free
  13. Black Hat Hacker Tools
  14. Hacker Tools For Ios
  15. Hacking Tools For Windows Free Download
  16. Hacking Apps
  17. Hack Tools Github
  18. Hacking Tools Pc
  19. Hacker Tools 2020
  20. Hack Tools For Games
  21. Hacking Tools Software
  22. Underground Hacker Sites
  23. Hacker Tools For Ios
  24. Github Hacking Tools
  25. Pentest Tools Github
  26. Hacker Tools Apk
  27. Kik Hack Tools
  28. Pentest Tools Android

0 comments:

Post a Comment