50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67cwannacry: 50a9f720 — WannaCry v2.1 outbreak DLL, third confirmed sibling
Executive Summary
A PE32+ x64 DLL compiled 11 May 2017, mislabeled dionaea by OpenCTI but confirmed as a wannacry outbreak sibling. Structurally identical to the previously-analyzed 16fdcfbc sample: same timestamp, same size, same .rsrc ZIP payload, same kill-switch domain (wff.com), and same service name (2.1). The SHA-256 and ssdeep differ, confirming it is a distinct file in the wild, not a re-upload of the prior hash. Static-only analysis; no CAPE Windows guest available.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c |
| File type | PE32+ executable (DLL) (console) x86-64, 6 sections ^[file.txt] |
| Size | 5,298,176 bytes (5.3 MB) ^[triage.json] |
| Compilation | 2017-05-11 12:20:57 UTC (TimeDateStamp 0x59145729) ^[pefile.txt:38] |
| Linker | MSVC 10.0 (Visual Studio 2010) ^[exiftool.json:18] |
| Runtime | MSVCP60.dll + MSVCRT.dll (C++ CRT) ^[strings.txt:242] |
| Signed | No ^[rabin2-info.txt] |
| Family | wannacry — high confidence; OpenCTI label dionaea is false positive |
This sample shares every structural fingerprint with 16fdcfbc: same .text entropy (6.32), same 5,124,608-byte .rsrc section containing a password-protected ZIP archive ^[pefile.txt:162-179] ^[binwalk.txt], same launcher.dll / PlayGame export masquerade ^[strings.txt:177-178], same WS2_32.dll + iphlpapi.dll + WININET.dll import profile for SMB propagation and HTTP kill-switch checks. The delta from 16fdcfbc is at the byte level only — the versioned strings, kill-switch domain, service name, and .rsrc contents are identical.
How It Works
Kill-Switch Gate (Version 2.1)
The kill-switch domain is http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com ^[strings.txt:656] — identical to 16fdcfbc. Same InternetOpenUrlA → InternetOpenA WinInet call chain ^[strings.txt:247-248], same circuit-breaker behavior: if the domain resolves and returns data, the payload exits without encryption. See kill-switch-domain-check for the technique deep-dive.
Service Persistence (Version 2.1)
The DLL installs itself as a Windows service named Microsoft Security Center (2.1) Service ^[strings.txt:646] — identical to 16fdcfbc. Same OpenSCManagerA → CreateServiceA → StartServiceCtrlDispatcherA API chain ^[strings.txt:231-232] ^[strings.txt:235-236]. The local service binary is referenced as mssecsvr.exe ^[strings.txt:74] ^[strings.txt:297] ^[strings.txt:371] and mssecsvc2.1 ^[strings.txt:645].
SMB Propagation
Identical to 16fdcfbc: \\%s\IPC$ ^[strings.txt:642] share path for EternalBlue exploitation, WS2_32.dll socket APIs ^[strings.txt:239]. The actual exploit payload is embedded inside the encrypted s.wnry resource and not visible statically.
Embedded Resource Payload
The .rsrc section (5,124,608 bytes, 98% of file) contains a password-protected ZIP with the same contents as 16fdcfbc:
c.wnry— encrypted configuration (780 bytes compressed) ^[binwalk.txt]msg/m_*.wnry— 27 ransom-note translations ^[binwalk.txt]r.wnry— encrypted Tor client (864 bytes compressed) ^[binwalk.txt]s.wnry— encrypted main payload (~3 MB compressed) ^[binwalk.txt]
The ZIP is encrypted with ZIP 2.0 password protection. The outer DLL decrypts and extracts these at runtime via FindResourceA / LoadResource / LockResource / SizeofResource ^[strings.txt:109-113].
Decompiled Behavior
Radare2 analysis (level 3, 209 functions) shows the same entry-point layout as 16fdcfbc:
entry0at0x1800015ec— DLL entry point withDllMainreason-code dispatch ^[rabin2-info.txt]fcn.180001000— service control dispatcher path (persistence) ^[r2:fcn.180001000]fcn.18000137c— payload execution path (encryption) ^[r2:fcn.18000137c]
The decompiled entry point is heavily CRT-initialized (SEH frames, FLS/TLS setup) with minimal obfuscation. No anti-debug or VM checks are visible in the outer DLL — the binary relies on the kill switch and encrypted inner payload for defense. The fcn.1800050c8 cluster handles resource enumeration and ZIP extraction, confirming the .rsrc payload access pattern.
C2 Infrastructure
| Type | Indicator | Notes |
|---|---|---|
| Kill-switch domain | www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com |
Hardcoded plaintext ^[strings.txt:656] |
| Service name | Microsoft Security Center (2.1) Service |
Fake service for persistence ^[strings.txt:646] |
| File names | mssecsvr.exe, mssecsvc2.1, tasksche.exe |
Known WannaCry propagation filenames ^[strings.txt:74] ^[strings.txt:645] ^[strings.txt:651] |
| SMB indicator | \\%s\IPC$ |
EternalBlue exploitation target share ^[strings.txt:642] |
| Tor C2 | Embedded .onion via r.wnry |
Hidden-service payment portal (inner payload) |
Interesting Tidbits
- OpenCTI mislabel: Tagged
dionaeaandwannacryby the abuse.ch connector.dionaeais a honeypot project, not a malware family — the label is a false positive from the MalwareBazaar ingestion pipeline. ^[triage.json:7-12] - No anti-analysis in outer layer: Unlike modern ransomware, the outer DLL contains no debugger checks, no VM detection, and no timing gates. Defense is entirely the kill-switch gate and the encrypted ZIP payload. ^[strings.txt]
- Same build, different hash: The SHA-256 and ssdeep differ from
16fdcfbc, but the compilation timestamp, section sizes, entry point, and all versioned strings are identical. This suggests the binary was rebuilt from the same source with only minor byte-level differences (possibly different linker randomization or a recompiled object). - Resource ZIP encryption: The
.rsrcZIP uses standard ZIP 2.0 password encryption. The password is not visible in static strings; it is likely hardcoded in the decryption routine insidefcn.1800050c8.
How To Mess With It (Homelab Replication)
See the reproduction notes on the kill-switch-domain-check technique page for a working C + WinInet snippet that demonstrates the circuit-breaker pattern. To replicate the full WannaCry build stack:
- Toolchain: MSVC 10.0 (Visual Studio 2010), x64 target, DLL subsystem
- Runtime: Link against MSVCP60 + MSVCRT (C++ CRT from VC++ 6.0 era)
- Resource: Embed a password-protected ZIP in
.rsrcusing standard RCData or named resource types - Verification: Compile a DLL with
launcher.dll/PlayGameexport names,InternetOpenUrlAkill-switch check, andCreateServiceApersistence. Runcapa— should hitconnect to URL,create service, andload resourcecapabilities.
Deployable Signatures
YARA Rule
rule wannacry_v21_dll {
meta:
description = "WannaCry v2.1 DLL variant with wff.com kill-switch"
author = "PacketPursuit SOC"
date = "2026-08-06"
sha256 = "50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c"
strings:
$kill = "www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com" ascii wide
$svc = "Microsoft Security Center (2.1) Service" ascii wide
$msse = "mssecsvr.exe" ascii wide
$msse2 = "mssecsvc2.1" ascii wide
$task = "tasksche.exe" ascii wide
$wnry = ".wnry" ascii wide
$ipc = "\\%s\\IPC$" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x4550 and
3 of them
}
Sigma Rule
title: WannaCry v2.1 Service Installation
logsource:
product: windows
service: system
detection:
selection:
EventID: 7045
ServiceName: 'Microsoft Security Center (2.1) Service'
condition: selection
IOC List
| Category | Value |
|---|---|
| SHA-256 | 50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c |
| Kill-switch domain | www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com |
| Service name | Microsoft Security Center (2.1) Service |
| File names | mssecsvr.exe, mssecsvc2.1, tasksche.exe |
| SMB indicator | \\%s\IPC$ |
Behavioral Fingerprint
This DLL, when loaded by a launcher or rundll32, first attempts an outbound HTTP GET to www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com. If the domain resolves and returns data, the process terminates immediately. On failure, it installs itself as a fake "Microsoft Security Center (2.1)" service for persistence, then extracts an encrypted ZIP payload from its own .rsrc section and begins SMB scanning on TCP/445 for lateral movement. No anti-debug checks in the outer layer; defense is the kill-switch gate and payload encryption.
Detection Signatures
| ATT&CK Technique | Evidence |
|---|---|
| T1486 — Data Encrypted for Impact | Embedded s.wnry encrypted payload, CryptAcquireContextA ^[strings.txt:227] |
| T1490 — Inhibit System Recovery | Ransom note ZIP contains recovery instructions; known to delete shadow copies in inner payload |
| T1021.002 — SMB/Windows Admin Shares | \\%s\IPC$ ^[strings.txt:642], mssecsvr.exe propagation service ^[strings.txt:74] |
| T1543.003 — Windows Service | CreateServiceA + OpenSCManagerA + Microsoft Security Center (2.1) Service ^[strings.txt:231-232] ^[strings.txt:646] |
| T1071.001 — Web Protocols | Kill-switch check via InternetOpenUrlA ^[strings.txt:247-248] |
| T1588.001 — Malicious Link | Kill-switch domain hardcoded ^[strings.txt:656] |
References
- MITRE ATT&CK: WannaCry (S0367) — https://attack.mitre.org/software/S0367/
- Wiki sibling:
16fdcfbc— WannaCry v2.1 DLL withwff.comkill-switch ^[/intel/analyses/16fdcfbc4c5d2a7d5e2ccfd28e4b99208797c91315390718de532d9bd9e46d20.html] - Wiki sibling:
ad4df92f— WannaCry v2.0 DLL withwea.comkill-switch ^[/intel/analyses/ad4df92f352378948654b371e619072118f8e6eb3550a6d47ced2710ccf438c3.html] - Wiki: wannacry entity page, kill-switch-domain-check technique page
Provenance
file.txt— file(1) 5.44pefile.txt— pefile 2023.2.7strings.txt— GNU strings 2.40binwalk.txt— binwalk v2.3.4rabin2-info.txt— radare2 5.9.4exiftool.json— ExifTool 12.76triage.json— PacketPursuit triage-fast, 2026-05-27- Radare2 decompilation — r2, analysis level 3, 209 functions