WannaCry Data Collection System Design and Tutorial
Darren Rogers, Vikram Kanth · MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM) · 2021
The proliferation of malware-based attacks, particularly those of the ransomware variety, poses a serious threat to business operations. In order to prevent these types of attacks, existing forms of malware must be analyzed and studied in controlled settings. Unfortunately, implementing a test network to study the effects of ransomware can be difficult for several different reasons including the pedigree of the target ransomware. One example of this struggle is illustrated by the WannaCry ransomware that caused significant damage in 2017. In this paper, we document the importance of malware pedigree in the malware analysis process. We also present the first tutorial creating a test network incorporating both physical and virtual elements in which the WannaCry ransomware was released and analyzed. Finally, we make available our captured data for analysis.