Catch the Next WannaCry or NotPetya Ransomware Attack Before Damage Occurs | LogRhythm
Tags
attack-pattern: | Data Exploits - T1587.004 Exploits - T1588.005 Ip Addresses - T1590.005 Malware - T1587.001 Malware - T1588.001 Software - T1592.002 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | c9a34c1c-da20-4701-b323-f0d1c9b9e864 |
Fingerprint | c4dc69dbd11f9693 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | May 14, 2018, 7 a.m. |
Added to db | Jan. 18, 2023, 9:58 p.m. |
Last updated | Nov. 17, 2024, 6:54 p.m. |
Headline | Catch the Next WannaCry or NotPetya Ransomware Attack Before Damage Occurs |
Title | Catch the Next WannaCry or NotPetya Ransomware Attack Before Damage Occurs | LogRhythm |
Detected Hints/Tags/Attributes | 50/1/9 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 41 | cve-2017-5715 |
|
Details | CVE | 37 | cve-2017-5753 |
|
Details | CVE | 34 | cve-2017-5754 |
|
Details | File | 1 | taskdll.exe |
|
Details | File | 1 | tasksche.dll |
|
Details | File | 22 | taskse.exe |
|
Details | File | 2125 | cmd.exe |
|
Details | Windows Registry Key | 41 | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
|
Details | Windows Registry Key | 2 | HKLM\Software\WanaCrypt0r\wd |