Windows WannaCry Ransomware Process Execution Indicators

Alerts on Windows process creation where WannaCry-related executables and the @Please_Read_Me@.txt command indicator appear.

FreeUnreviewedSigmacriticalv1
title: Windows WannaCry Ransomware Process Execution Indicators
id: 89bac153-d09f-40e9-8686-8a52a471751e
status: test
description: This rule flags Windows process creation events tied to WannaCry by matching specific executable names and a “WanaDecryptor” string in the image path or name. It also requires a command line indicator containing “@Please_Read_Me@.txt”, which is used by the malware as part of its ransomware behavior. These signals matter because they combine file/process artifacts with ransom-related command-line context, reducing the chance of benign matches.
references:
  - https://www.hybrid-analysis.com/sample/ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa?environmentId=100
  - https://x.com/nas_bench/status/1868639048484425963
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2017/Malware/WannaCry/proc_creation_win_malware_wannacry.yml
author: Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), oscd.community, Jonhnathan Ribeiro, Huntrule Team
date: 2019-01-16
modified: 2025-10-18
tags:
  - attack.lateral-movement
  - attack.defense-impairment
  - attack.t1210
  - attack.discovery
  - attack.t1083
  - attack.t1222.001
  - attack.impact
  - attack.t1486
  - attack.t1490
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith:
        - \tasksche.exe
        - \mssecsvc.exe
        - \taskdl.exe
        - \taskhsvc.exe
        - \taskse.exe
        - \111.exe
        - \lhdfrgui.exe
        - \linuxnew.exe
        - \wannacry.exe
    - Image|contains: WanaDecryptor
  selection_cmd:
    CommandLine|contains: "@Please_Read_Me@.txt"
  condition: 1 of selection_*
falsepositives:
  - Unknown
level: critical
license: DRL-1.1
related:
  - id: 41d40bff-377a-43e2-8e1b-2e543069e079
    type: derived

What it detects

This rule flags Windows process creation events tied to WannaCry by matching specific executable names and a “WanaDecryptor” string in the image path or name. It also requires a command line indicator containing “@Please_Read_Me@.txt”, which is used by the malware as part of its ransomware behavior. These signals matter because they combine file/process artifacts with ransom-related command-line context, reducing the chance of benign matches.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.