INTERFACE: eth0 (PROMISC)SNIFFING
dashboardmodule-07
CRITICAL

WannaCry Simulator

Interactive simulation and visual analysis of the attack vector.

01Worm Propagation

WannaCry spreads laterally via the EternalBlue SMBv1 exploit, compromising vulnerable Windows systems on the same network segment.

SMBv1 SCANNER (PORT 445)

> Waiting for payload execution...

02File System Attack

Once inside, it rapidly iterates through the file system, encrypting critical documents with military-grade AES-128 and appending .WNCRY extensions.

C:\Users\Target\Documents\

Q4_Financial_Report.pdf
Family_Vacation_2023.jpg
source_code_v2.ts
Passwords_Backup.txt
Bitcoin_Wallet_Keys.dat
Client_Database.sql
Wedding_Photos.png
Confidential_Strategy.docx

03The Killswitch

Before encrypting, WannaCry inexplicably queries a hardcoded, unregistered domain. If the domain is live (sinkholed), the malware completely aborts.

DarkTraceX Network Analyzer v2.4.1 (Sandbox Mode)
Monitoring process: wnry.exe (PID: 8492)