typeanalysisfamilywannacryconfidencehighcreated2026-08-06updated2026-08-06malware-familyransomwareimpactc2lateral-movementpersistencepeevasion
SHA-256: 50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c

wannacry: 50a9f720 — WannaCry v2.1 outbreak DLL, third confirmed sibling

Executive Summary

A PE32+ x64 DLL compiled 11 May 2017, mislabeled dionaea by OpenCTI but confirmed as a wannacry outbreak sibling. Structurally identical to the previously-analyzed 16fdcfbc sample: same timestamp, same size, same .rsrc ZIP payload, same kill-switch domain (wff.com), and same service name (2.1). The SHA-256 and ssdeep differ, confirming it is a distinct file in the wild, not a re-upload of the prior hash. Static-only analysis; no CAPE Windows guest available.

What It Is

Field Value
SHA-256 50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c
File type PE32+ executable (DLL) (console) x86-64, 6 sections ^[file.txt]
Size 5,298,176 bytes (5.3 MB) ^[triage.json]
Compilation 2017-05-11 12:20:57 UTC (TimeDateStamp 0x59145729) ^[pefile.txt:38]
Linker MSVC 10.0 (Visual Studio 2010) ^[exiftool.json:18]
Runtime MSVCP60.dll + MSVCRT.dll (C++ CRT) ^[strings.txt:242]
Signed No ^[rabin2-info.txt]
Family wannacry — high confidence; OpenCTI label dionaea is false positive

This sample shares every structural fingerprint with 16fdcfbc: same .text entropy (6.32), same 5,124,608-byte .rsrc section containing a password-protected ZIP archive ^[pefile.txt:162-179] ^[binwalk.txt], same launcher.dll / PlayGame export masquerade ^[strings.txt:177-178], same WS2_32.dll + iphlpapi.dll + WININET.dll import profile for SMB propagation and HTTP kill-switch checks. The delta from 16fdcfbc is at the byte level only — the versioned strings, kill-switch domain, service name, and .rsrc contents are identical.

How It Works

Kill-Switch Gate (Version 2.1)

The kill-switch domain is http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com ^[strings.txt:656] — identical to 16fdcfbc. Same InternetOpenUrlA → InternetOpenA WinInet call chain ^[strings.txt:247-248], same circuit-breaker behavior: if the domain resolves and returns data, the payload exits without encryption. See kill-switch-domain-check for the technique deep-dive.

Service Persistence (Version 2.1)

The DLL installs itself as a Windows service named Microsoft Security Center (2.1) Service ^[strings.txt:646] — identical to 16fdcfbc. Same OpenSCManagerA → CreateServiceA → StartServiceCtrlDispatcherA API chain ^[strings.txt:231-232] ^[strings.txt:235-236]. The local service binary is referenced as mssecsvr.exe ^[strings.txt:74] ^[strings.txt:297] ^[strings.txt:371] and mssecsvc2.1 ^[strings.txt:645].

SMB Propagation

Identical to 16fdcfbc: \\%s\IPC$ ^[strings.txt:642] share path for EternalBlue exploitation, WS2_32.dll socket APIs ^[strings.txt:239]. The actual exploit payload is embedded inside the encrypted s.wnry resource and not visible statically.

Embedded Resource Payload

The .rsrc section (5,124,608 bytes, 98% of file) contains a password-protected ZIP with the same contents as 16fdcfbc:

  • c.wnry — encrypted configuration (780 bytes compressed) ^[binwalk.txt]
  • msg/m_*.wnry — 27 ransom-note translations ^[binwalk.txt]
  • r.wnry — encrypted Tor client (864 bytes compressed) ^[binwalk.txt]
  • s.wnry — encrypted main payload (~3 MB compressed) ^[binwalk.txt]

The ZIP is encrypted with ZIP 2.0 password protection. The outer DLL decrypts and extracts these at runtime via FindResourceA / LoadResource / LockResource / SizeofResource ^[strings.txt:109-113].

Decompiled Behavior

Radare2 analysis (level 3, 209 functions) shows the same entry-point layout as 16fdcfbc:

  • entry0 at 0x1800015ec — DLL entry point with DllMain reason-code dispatch ^[rabin2-info.txt]
  • fcn.180001000 — service control dispatcher path (persistence) ^[r2:fcn.180001000]
  • fcn.18000137c — payload execution path (encryption) ^[r2:fcn.18000137c]

The decompiled entry point is heavily CRT-initialized (SEH frames, FLS/TLS setup) with minimal obfuscation. No anti-debug or VM checks are visible in the outer DLL — the binary relies on the kill switch and encrypted inner payload for defense. The fcn.1800050c8 cluster handles resource enumeration and ZIP extraction, confirming the .rsrc payload access pattern.

C2 Infrastructure

Type Indicator Notes
Kill-switch domain www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com Hardcoded plaintext ^[strings.txt:656]
Service name Microsoft Security Center (2.1) Service Fake service for persistence ^[strings.txt:646]
File names mssecsvr.exe, mssecsvc2.1, tasksche.exe Known WannaCry propagation filenames ^[strings.txt:74] ^[strings.txt:645] ^[strings.txt:651]
SMB indicator \\%s\IPC$ EternalBlue exploitation target share ^[strings.txt:642]
Tor C2 Embedded .onion via r.wnry Hidden-service payment portal (inner payload)

Interesting Tidbits

  • OpenCTI mislabel: Tagged dionaea and wannacry by the abuse.ch connector. dionaea is a honeypot project, not a malware family — the label is a false positive from the MalwareBazaar ingestion pipeline. ^[triage.json:7-12]
  • No anti-analysis in outer layer: Unlike modern ransomware, the outer DLL contains no debugger checks, no VM detection, and no timing gates. Defense is entirely the kill-switch gate and the encrypted ZIP payload. ^[strings.txt]
  • Same build, different hash: The SHA-256 and ssdeep differ from 16fdcfbc, but the compilation timestamp, section sizes, entry point, and all versioned strings are identical. This suggests the binary was rebuilt from the same source with only minor byte-level differences (possibly different linker randomization or a recompiled object).
  • Resource ZIP encryption: The .rsrc ZIP uses standard ZIP 2.0 password encryption. The password is not visible in static strings; it is likely hardcoded in the decryption routine inside fcn.1800050c8.

How To Mess With It (Homelab Replication)

See the reproduction notes on the kill-switch-domain-check technique page for a working C + WinInet snippet that demonstrates the circuit-breaker pattern. To replicate the full WannaCry build stack:

  • Toolchain: MSVC 10.0 (Visual Studio 2010), x64 target, DLL subsystem
  • Runtime: Link against MSVCP60 + MSVCRT (C++ CRT from VC++ 6.0 era)
  • Resource: Embed a password-protected ZIP in .rsrc using standard RCData or named resource types
  • Verification: Compile a DLL with launcher.dll / PlayGame export names, InternetOpenUrlA kill-switch check, and CreateServiceA persistence. Run capa — should hit connect to URL, create service, and load resource capabilities.

Deployable Signatures

YARA Rule

rule wannacry_v21_dll {
    meta:
        description = "WannaCry v2.1 DLL variant with wff.com kill-switch"
        author = "PacketPursuit SOC"
        date = "2026-08-06"
        sha256 = "50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c"
    strings:
        $kill = "www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com" ascii wide
        $svc  = "Microsoft Security Center (2.1) Service" ascii wide
        $msse = "mssecsvr.exe" ascii wide
        $msse2 = "mssecsvc2.1" ascii wide
        $task = "tasksche.exe" ascii wide
        $wnry = ".wnry" ascii wide
        $ipc  = "\\%s\\IPC$" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x4550 and
        3 of them
}

Sigma Rule

title: WannaCry v2.1 Service Installation
logsource:
    product: windows
    service: system
detection:
    selection:
        EventID: 7045
        ServiceName: 'Microsoft Security Center (2.1) Service'
    condition: selection

IOC List

Category Value
SHA-256 50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c
Kill-switch domain www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
Service name Microsoft Security Center (2.1) Service
File names mssecsvr.exe, mssecsvc2.1, tasksche.exe
SMB indicator \\%s\IPC$

Behavioral Fingerprint

This DLL, when loaded by a launcher or rundll32, first attempts an outbound HTTP GET to www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com. If the domain resolves and returns data, the process terminates immediately. On failure, it installs itself as a fake "Microsoft Security Center (2.1)" service for persistence, then extracts an encrypted ZIP payload from its own .rsrc section and begins SMB scanning on TCP/445 for lateral movement. No anti-debug checks in the outer layer; defense is the kill-switch gate and payload encryption.

Detection Signatures

ATT&CK Technique Evidence
T1486 — Data Encrypted for Impact Embedded s.wnry encrypted payload, CryptAcquireContextA ^[strings.txt:227]
T1490 — Inhibit System Recovery Ransom note ZIP contains recovery instructions; known to delete shadow copies in inner payload
T1021.002 — SMB/Windows Admin Shares \\%s\IPC$ ^[strings.txt:642], mssecsvr.exe propagation service ^[strings.txt:74]
T1543.003 — Windows Service CreateServiceA + OpenSCManagerA + Microsoft Security Center (2.1) Service ^[strings.txt:231-232] ^[strings.txt:646]
T1071.001 — Web Protocols Kill-switch check via InternetOpenUrlA ^[strings.txt:247-248]
T1588.001 — Malicious Link Kill-switch domain hardcoded ^[strings.txt:656]

References

  • MITRE ATT&CK: WannaCry (S0367) — https://attack.mitre.org/software/S0367/
  • Wiki sibling: 16fdcfbc — WannaCry v2.1 DLL with wff.com kill-switch ^[/intel/analyses/16fdcfbc4c5d2a7d5e2ccfd28e4b99208797c91315390718de532d9bd9e46d20.html]
  • Wiki sibling: ad4df92f — WannaCry v2.0 DLL with wea.com kill-switch ^[/intel/analyses/ad4df92f352378948654b371e619072118f8e6eb3550a6d47ced2710ccf438c3.html]
  • Wiki: wannacry entity page, kill-switch-domain-check technique page

Provenance

  • file.txt — file(1) 5.44
  • pefile.txt — pefile 2023.2.7
  • strings.txt — GNU strings 2.40
  • binwalk.txt — binwalk v2.3.4
  • rabin2-info.txt — radare2 5.9.4
  • exiftool.json — ExifTool 12.76
  • triage.json — PacketPursuit triage-fast, 2026-05-27
  • Radare2 decompilation — r2, analysis level 3, 209 functions