
Introduction to the training and the instructor.
Short introduction to the Wannacry ransomware and it's impact.
Introduction to our scenario we will walk through in the training.
Please see the supporting material attached. Download this before proceeding to the next section.
The info.txt has most of the links and commands you might need to use during the course.
The zip file contains the evidences and supporting material including the presentation. Password is: "wannacry".
Introduction to the section.
Downloading the necessary tools to install Windows 10.
Installing Windows 10 in the lab envrionment.
Introduction to the section.
Downloading the Windows 7 installer ISO.
Installing Windows 7 in the lab environment.
Disabling some features in Windows to enable Wannacry to infect.
Configure shared folders for file transfer and tool install.
Introduction to the section.
Downloading the installer ISO.
Installing OPNsense in the lab environment.
Introduction to the section.
Getting the Wannacry malware sample from multiple sources.
Making sure the lab environment is ready to be infected with Wannacry.
Infect the Windows 10 with Wannacry.
Introduction to the section.
Downloading the tools for taking a memory image.
Taking a memory snapshot.
Downloading the disk imaging tool.
Taking a disk image using FTK Imager.
Downloading the Microsoft Sysinternals Suite.
Quick analysis of the Windows 10 machine. Network connections, processes, services, autoruns.
Introduction to the section.
Gathering system information for the report.
Windows 10 analysis file and process information #1.
Windows 10 analysis file and process information #2.
Windows 10 analysis file and process information #3.
Autoruns analysis.
Downloading a hex editor.
Analysis using a hex editor HxD.
Downloading the tools for static exe file information extraction.
Static exe file analysis.
Getting the password for the embedded payload in the Wannacry executable.
Downloading Registry editing tools.
Analysing the registry using the registry explorer tools.
Introduction to the section.
Downloading network capturing and registry snapshot tools.
Preparing the lab for the sandbox analysis.
Executing Wannacry in the lab and capturing the activity.
Prepare the sandbox analysis results for analysis.
Analysing network traffic capture.
Analysing procmon capture.
Analysing registry changes.
Using Redline automated forensics tool to capture the system activity.
Analysing Redline capture.
Download fakenet networking tool.
Analysing the killswitch domain in the network traffic.
Analysing one more executable in the Windows 7.
List of remediation actions that would prevent Wannacry from encrypting the files or spreading.
Summary of the activities performed by Wannacry.
Closing thoughts and thanks for taking this training!
Wannacry has been one of the most famous ransomware in computer history (so far) which allows us to investigate how it worked and identify indicators of compromise. The goal of the course is not to protect against Wannacry, but to provide you with a methodology to be able to quickly assess the behavour of a suspicious application in a computer. The tools we are using in this course are free for personal use, but there are way more other solutions you can use for the same purpose.
At the end of this training you will have a solid understanding how the ransomware works and how to protect you environment, also you will be able to use the tools to identify and analyse other malicious tools. You will not be a malware analyst, this is not the course for that. This course will give you the steps to be able to do incident response in a quick manner and see what areas you need to develop yourself using other courses. Deep malware analysis is a very interesting area, but not necessarily the part of the incident response team. There are companies specialized in malware analysis, or people specializing in malware analysis. One can spend hours, days, weeks, months analyzing a single malware. This course aims for quick response.