🐾 - 🚨 WannaCry 👿 Ransomware 🔒 kill switch DNS Request

SID: 3321444Rev: 176 views
Sourcepawpatrules
CreatedMay 29, 2025
UpdatedMay 29, 2025
Classificationshellcode-detect
alert dns any any -> any any (msg:"🐾 - 🚨 WannaCry 👿 Ransomware 🔒 kill switch DNS Request"; flow:to_server, stateless; dns_query; content:"iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com"; startswith; endswith; reference:url,https://malpedia.caad.fkie.fraunhofer.de/details/win.wannacryptor; reference:url,https://www.malwaretech.com/2017/05/how-to-accidentally-stop-a-global-cyber-attacks.html; metadata:attack_target Client_and_Server, signature_severity Major, affected_product Windows_XP_Vista_7_8_10_11_Server_32_64_Bit, mitre_tactic_id TA0011, mitre_tactic_name Command_and_Control, mitre_technique_id T1486, mitre_technique_name Data_Encrypted_for_Impact, former_category MALWARE, malware_family WannaCry, created_at 2025_05_29, updated_at 2025_05_29; sid:3321444; rev:1; classtype:shellcode-detect;)

Metadata

attack targetClient_and_Server
signature severityMajor
affected productWindows_XP_Vista_7_8_10_11_Server_32_64_Bit
mitre tactic idTA0011
mitre tactic nameCommand_and_Control
mitre technique idT1486
mitre technique nameData_Encrypted_for_Impact
former categoryMALWARE
malware familyWannaCry
created at2025_05_29
updated at2025_05_29

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!