This detection rule identifies the specific network propagation patterns and file encryption behaviors characteristic of the WannaCry ransomware strain within Azure Sentinel logs. Proactively hunting for these indicators is critical because early identification allows the SOC team to isolate infected endpoints before the worm-like infection spreads laterally across the organization’s infrastructure, minimizing potential data loss and operational downtime.
rule WannaCry_Ransomware {
meta:
description = "Detects WannaCry Ransomware"
author = "Florian Roth (with the help of binar.ly)"
reference = "https://goo.gl/HG2j5T"
date = "2017-05-12"
hash1 = "ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa"
strings:
$x1 = "icacls . /grant Everyone:F /T /C /Q" fullword ascii
$x2 = "taskdl.exe" fullword ascii
$x3 = "tasksche.exe" fullword ascii
$x4 = "Global\\MsWinZonesCacheCounterMutexA" fullword ascii
$x5 = "WNcry@2ol7" fullword ascii
$x6 = "www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com" ascii
$x7 = "mssecsvc.exe" fullword ascii
$x8 = "C:\\%s\\qeriuwjhrf" fullword ascii
$x9 = "icacls . /grant Everyone:F /T /C /Q" fullword ascii
$s1 = "C:\\%s\\%s" fullword ascii
$s2 = "<!-- Windows 10 --> " fullword ascii
$s3 = "cmd.exe /c \"%s\"" fullword ascii
$s4 = "msg/m_portuguese.wnry" fullword ascii
$s5 = "\\\\192.168.56.20\\IPC$" fullword wide
$s6 = "\\\\172.16.99.5\\IPC$" fullword wide
$op1 = { 10 ac 72 0d 3d ff ff 1f ac 77 06 b8 01 00 00 00 }
$op2 = { 44 24 64 8a c6 44 24 65 0e c6 44 24 66 80 c6 44 }
$op3 = { 18 df 6c 24 14 dc 64 24 2c dc 6c 24 5c dc 15 88 }
$op4 = { 09 ff 76 30 50 ff 56 2c 59 59 47 3b 7e 0c 7c }
$op5 = { c1 ea 1d c1 ee 1e 83 e2 01 83 e6 01 8d 14 56 }
$op6 = { 8d 48 ff f7 d1 8d 44 10 ff 23 f1 23 c1 }
condition:
uint16(0) == 0x5a4d and filesize < 10000KB and ( 1 of ($x*) and 1 of ($s*) or 3 of ($op*) )
}
This YARA rule can be deployed in the following contexts:
This rule contains 21 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Detects WannaCry Ransomware rule in an enterprise environment, along with suggested filters or exclusions:
Windows Update Service (WUAU) Patch Deployment
wuauserv) frequently executes svchost.exe processes that scan for and download patches. During the installation of cumulative updates containing security fixes, these processes may access SMB ports or execute scripts that mimic the network scanning behavior of WannaCry (specifically targeting port 445).svchost.exe and the parent process is services.exe, specifically when the command line contains arguments related to MicrosoftUpdate or wuauclt.Scheduled Antivirus Full System Scans
C:\Program Files\CrowdStrike\cs.exe or C:\Program Files\Symantec Endpoint Protection\Smc.exe) and restrict the rule to trigger only during business hours if the scan is typically scheduled for maintenance windows.Microsoft SCCM/Intune Software Distribution
ccmexec.exe service and associated agents perform extensive