WannaCry 랜섬웨어 분석 #2 SMB 취약점 분석

2017-06-08 Somansa WannaCry Ransomware Analysis #2 SMB Vulnerability Analysis

https://www.somansa.com/wp-content/uploads/2017/06/20170608_report_2.pdf

Attachments

20170608_report_2.pdf (2 MB)

Thumbnail for WannaCry 랜섬웨어 분석 #2 SMB 취약점 분석

WannaCry spread worm-like across Windows hosts by probing SMB services for the MS17-010 remote code execution vulnerability and using SMB response values to decide whether a target was vulnerable or already compromised. The infection flow used SMB negotiation, session setup, tree connect, transaction, transaction2, NT transact, transaction2 secondary, and echo messages before delivering shellcode and an encrypted malicious DLL. On the victim system, the DLL was decrypted as launcher.dll, injected into lsass.exe, and executed through its PlayGame export to create and launch mssecsvc.exe, after which file encryption and further propagation began. The report also notes Tor-based external communication, with a renamed Tor component listening on local port 9050 as a proxy for actions such as payment checks, and recommends isolating systems, blocking SMB ports 137, 138, 139, and 445, and applying MS17-010.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 24d004a104d4d54034dbcffc2a4b19a… 2017-05-12 2021-12-02
HASH ed01ebfbc9eb5bbea545af4d01bf5f1… 2017-05-12 2021-12-02

Related Reports

« Back