A Framework of Dynamic Analysis of WannaCry
Michael Cardoso, George Cardoso, Na Li · 2025
This paper explores the dynamic analysis of WannaCry, which has had a significant impact on the operations of academia, industry, healthcare, and governments, causing substantial monetary losses in recent years. We run a Windows 7 virtual machine on Cuckoo to simulate both benign and infected machines, and we write custom scripts to simulate different operations on these virtual machines (VMs). Using network traffic and system logs collected from Cuckoo, we apply machine learning algorithms, including Random Forests (RF), Extreme Trees (ET), and Gradient Boosting (GB), to develop log-based and network traffic-based classifiers. Furthermore, we propose a framework that can integrate different types of data, although, in this implementation, we focus on system logs and network traffic for our multimodal classifier. Through extensive experiments, we find that log-based classification outperforms network traffic-based classification, and our multimodal classifier can appropriately weigh the importance of different data types in the classification process.