DNS Domains linked to WannaCry ransomware campaign

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Displays the client DNS request for any of the known domains linked to WannaCry. These results may indicate a Wannacry/Wannacrypt ransomware infection. Reference: Domain listing from https://pastebin.com/cRUii32E

Attribute Value
Type Hunting Query
Solution Windows Server DNS
ID aaf84b80-7764-420c-98eb-239b5e194b3d
Tactics Impact
Techniques T1496
Required Connectors DNS
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DnsEvents ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Windows Server DNS