WannaCry delete Volume Shadow Copies

/static/assets/windows-logo.svg
WannaCry deletes the Volume Shadow Copies after encrypting files. This technique uses the commands found in WannaCry to achieve that effect.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
APT38 WannaCry

2022-05-31

/static/assets/windows-logo.svg/static/assets/apple-logo.svg/static/assets/linux-logo.svg
Perform lateral movement using EternalBlue and DoublePulsar exploits.