Pcap Of Wannacry Spreading Using EthernalBlue

Saw that a lot of people were looking for a pcap with WannaCry spreading Using EthernalBlue.

I have put together a little "petri dish" test environment and started looking for a sample that has the exploit. Some samples out there simply do not have the exploit code, and even tough they will encrypt the files locally, sometimes the mounted shares too, they would not spread.

Luckily, I have found this nice blog post from McAfee Labs: https://securingtomorrow.mcafee.com/mcafee-labs/analysis-wannacry-ransomware/ with the reference to the sample SHA256: 24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c (they keep referring to samples with MD5, which is still a very-very bad practice, but the hash is MD5: DB349B97C37D22F5EA1D1841E3C89EB4)

Once I got the sample from the VxStream Sandbox site, dropped it in the test environment, and monitored it with Security Onion. I was super happy to see it spreading, despite the fact that for the first run my Windows 7 x64 VM went to BSOD as the EthernalBlue exploit failed.

But the second run was a full success, all my Windows 7 VMs got infected. Brad was so kind and made a guest blog post at one of my favorite sites, www.malware-traffic-analysis.net so you can find the pcap, description of the test environment and some screenshots here: http://malware-traffic-analysis.net/2017/05/18/index2.html
Read more

  1. Pentest Tools Nmap
  2. Pentest Tools For Windows
  3. Hacking Tools For Windows
  4. Hacking Tools Free Download
  5. Hacker Tools Apk
  6. Hacking Tools And Software
  7. Hacker Tools Hardware
  8. Hacking Tools For Beginners
  9. Underground Hacker Sites
  10. Hacker Tools Free
  11. Physical Pentest Tools
  12. Hacking Tools For Windows
  13. Pentest Tools Port Scanner
  14. Hacking Tools Download
  15. Nsa Hacker Tools
  16. Hack Tools For Windows
  17. Best Hacking Tools 2019
  18. Hacking Tools Mac
  19. Hacking Tools Free Download
  20. Best Hacking Tools 2020
  21. New Hacker Tools
  22. Hack Tools For Pc
  23. Hacking Tools Pc
  24. Nsa Hacker Tools
  25. Hack Tools
  26. Hacking Tools For Windows
  27. Pentest Tools Framework
  28. Top Pentest Tools

No comments:

Post a Comment

Note: only a member of this blog may post a comment.

Remember...

If you want more information on any of these news updates, do feel free to call the office at any time! 02890673379
or email office@summermadness.co.uk
....or check out the rest of the SM website

Blog Archive