Windows WannaCry Ransomware Process Execution Indicators
Alerts on Windows process creation where WannaCry-related executables and the @Please_Read_Me@.txt command indicator appear.
FreeUnreviewedSigmacriticalv1
windows-wannacry-ransomware-process-execution-indicators-41d40bff
title: Windows WannaCry Ransomware Process Execution Indicators
id: 89bac153-d09f-40e9-8686-8a52a471751e
status: test
description: This rule flags Windows process creation events tied to WannaCry by matching specific executable names and a “WanaDecryptor” string in the image path or name. It also requires a command line indicator containing “@Please_Read_Me@.txt”, which is used by the malware as part of its ransomware behavior. These signals matter because they combine file/process artifacts with ransom-related command-line context, reducing the chance of benign matches.
references:
- https://www.hybrid-analysis.com/sample/ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa?environmentId=100
- https://x.com/nas_bench/status/1868639048484425963
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2017/Malware/WannaCry/proc_creation_win_malware_wannacry.yml
author: Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), oscd.community, Jonhnathan Ribeiro, Huntrule Team
date: 2019-01-16
modified: 2025-10-18
tags:
- attack.lateral-movement
- attack.defense-impairment
- attack.t1210
- attack.discovery
- attack.t1083
- attack.t1222.001
- attack.impact
- attack.t1486
- attack.t1490
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith:
- \tasksche.exe
- \mssecsvc.exe
- \taskdl.exe
- \taskhsvc.exe
- \taskse.exe
- \111.exe
- \lhdfrgui.exe
- \linuxnew.exe
- \wannacry.exe
- Image|contains: WanaDecryptor
selection_cmd:
CommandLine|contains: "@Please_Read_Me@.txt"
condition: 1 of selection_*
falsepositives:
- Unknown
level: critical
license: DRL-1.1
related:
- id: 41d40bff-377a-43e2-8e1b-2e543069e079
type: derived
What it detects
This rule flags Windows process creation events tied to WannaCry by matching specific executable names and a “WanaDecryptor” string in the image path or name. It also requires a command line indicator containing “@Please_Read_Me@.txt”, which is used by the malware as part of its ransomware behavior. These signals matter because they combine file/process artifacts with ransom-related command-line context, reducing the chance of benign matches.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.