← Back to Explore
sigmahighHunting
Wannacry Killswitch Domain
Detects wannacry killswitch domain dns queries
Detection Query
selection:
query:
- ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.testing
- ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.test
- ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.com
- ayylmaotjhsstasdfasdfasdfasdfasdfasdfasdf.com
- iuqssfsodp9ifjaposdfjhgosurijfaewrwergwea.com
condition: selection
Author
Mike Wade
Created
2020-09-16
Data Sources
dns
Tags
attack.command-and-controlattack.t1071.001
Raw Content
title: Wannacry Killswitch Domain
id: 3eaf6218-3bed-4d8a-8707-274096f12a18
status: test
description: Detects wannacry killswitch domain dns queries
references:
- https://www.mandiant.com/resources/blog/wannacry-ransomware-campaign
author: Mike Wade
date: 2020-09-16
modified: 2022-03-24
tags:
- attack.command-and-control
- attack.t1071.001
logsource:
category: dns
detection:
selection:
query:
- 'ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.testing'
- 'ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.test'
- 'ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.com'
- 'ayylmaotjhsstasdfasdfasdfasdfasdfasdfasdf.com'
- 'iuqssfsodp9ifjaposdfjhgosurijfaewrwergwea.com'
condition: selection
falsepositives:
- Analyst testing
level: high