541c9bc518635762bf9c14baec63c2703e3d9887246d3816865c95e2e430bfffwannacry: 541c9bc5 — Sixth confirmed WannaCry sibling, v2.0 build, intermediate .rsrc size
Executive Summary
A PE32+ x64 DLL compiled 11 May 2017, mislabeled dionaea by OpenCTI but confirmed as the sixth distinct wannacry outbreak sibling in the corpus. Shares the v2.0 kill-switch domain (wea.com) and service name (2.0) with ad4df92f and b52a8049, but carries a new intermediate .rsrc section size (5,243,392 bytes) between the 5,124,608-byte baseline and the 5,304,320-byte b52a8049 variant. Same outer-file size, same timestamp, same Bitcoin wallets. Static-only analysis; no CAPE Windows guest.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 541c9bc518635762bf9c14baec63c2703e3d9887246d3816865c95e2e430bfff |
| File type | PE32+ executable (DLL) (console) x86-64, 6 sections ^[file.txt] |
| Size | 5,298,176 bytes (5.3 MB) ^[exiftool.json] |
| Compilation | 2017-05-11 12:20:57 UTC (TimeDateStamp 0x59145729) ^[pefile.txt:38] |
| Linker | MSVC 10.0 (Visual Studio 2010) ^[exiftool.json:18] |
| Runtime | MSVCP60.dll + MSVCRT.dll (C++ CRT) ^[strings.txt:242] |
| Signed | No ^[rabin2-info.txt] |
| Family | wannacry — high confidence; OpenCTI label dionaea is false positive |
The binary is a DLL with console subsystem (Subsystem: 0x3) ^[pefile.txt:69], intended to be loaded by a launcher or run via rundll32. Export table shows launcher.dll / PlayGame masquerade strings ^[strings.txt:177-178] — a known WannaCry launcher artifact.
The .rsrc section is 5,243,392 bytes (0x500200) ^[pefile.txt:162-179], which is:
- 118,784 bytes larger than
ad4df92f/50a9f720(5,124,608 bytes) - 60,928 bytes smaller than
b52a8049(5,304,320 bytes)
This intermediate size is a new datapoint in the WannaCry builder pipeline, suggesting the embedded ZIP payload was re-compressed or re-packed with different parameters while the outer launcher DLL remained byte-identical in structure.
How It Works
Kill-Switch Gate (Version 2.0)
The kill-switch domain is http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com ^[strings.txt:656]. This matches the ad4df92f v2.0 sibling and differs from the 16fdcfbc/50a9f720 v2.1 siblings only in the TLD suffix (wea.com vs wff.com). Same InternetOpenUrlA → InternetOpenA WinInet call chain ^[strings.txt:247-248], same circuit-breaker behavior: if the domain resolves and returns data, the payload exits without encryption. See kill-switch-domain-check for the technique deep-dive.
Service Persistence (Version 2.0)
The DLL installs itself as a Windows service named Microsoft Security Center (2.0) Service ^[strings.txt:646] using OpenSCManagerA → CreateServiceA → StartServiceCtrlDispatcherA ^[strings.txt:231-232] ^[strings.txt:236]. The local service binary is referenced as mssecsvc.exe ^[strings.txt:74] ^[strings.txt:297] ^[strings.txt:371] and mssecsvc2.0 ^[strings.txt:645].
SMB Propagation
Identical to other siblings: \\%s\IPC$ ^[strings.txt:642] share path for EternalBlue exploitation, WS2_32.dll socket APIs ^[strings.txt:239], iphlpapi.dll for network enumeration ^[strings.txt:245]. The actual exploit payload is embedded inside the encrypted s.wnry resource and not visible statically.
Embedded Resource Payload
The .rsrc section contains a password-protected ZIP archive with the same family of contents ^[binwalk.txt]:
b.wnry— encrypted launcher/binary (1,440,054 bytes uncompressed)c.wnry— encrypted configuration (780 bytes)msg/m_*.wnry— 27 ransom-note translations (Bulgarian through Vietnamese) ^[strings.txt:936+]r.wnry— encrypted Tor client (864 bytes)s.wnry— encrypted main payload (~3,038,286 bytes uncompressed)
The outer DLL decrypts and extracts these at runtime via FindResourceA / LoadResource / LockResource / SizeofResource ^[strings.txt:109-113].
Cryptography
Key generation uses the Microsoft Base Cryptographic Provider:
CryptAcquireContextA+CryptGenRandom^[strings.txt:227] for RNG- The ransomware uses RSA-2048 (per public literature) to encrypt per-file AES-128 keys
Decompiled Behavior
Radare2 analysis (level 2, 209 functions) shows the same entry-point layout as the other siblings:
entry0at0x1800015ec— DLL entry point withDllMainreason-code dispatch ^[rabin2-info.txt]- Service control dispatcher path (persistence)
- Payload execution path (encryption)
The decompiled entry point is standard MSVC CRT-initialized with SEH frames, FLS/TLS setup, and no anti-debug or VM checks in the outer layer. No notable function deltas from prior siblings.
C2 Infrastructure
| Type | Indicator | Notes |
|---|---|---|
| Kill-switch domain | www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com |
Hardcoded; if reachable, encryption aborts ^[strings.txt:656] |
| SMB lateral | \\%s\IPC$ |
EternalBlue propagation to random internal IPs ^[strings.txt:642] |
| Service name | Microsoft Security Center (2.0) Service |
Fake service for persistence ^[strings.txt:646] |
| Bitcoin wallets | 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn, 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw, 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 |
Hardcoded payment addresses ^[strings.txt:865-867] |
No hardcoded IP addresses or email addresses visible in the outer DLL. The Tor C2 .onion address lives inside the encrypted r.wnry resource and is not statically recoverable.
Sibling Correlation
| Attribute | 16fdcfbc (v2.1) |
50a9f720 (v2.1) |
ad4df92f (v2.0) |
b52a8049 (v2.0) |
541c9bc5 (v2.0) |
|---|---|---|---|---|---|
| Size | 5,298,176 | 5,298,176 | 5,298,176 | 5,298,176 | 5,298,176 |
.rsrc size |
5,124,608 | 5,124,608 | 5,124,608 | 5,304,320 | 5,243,392 |
| Kill-switch TLD | wff.com |
wff.com |
wea.com |
wea.com |
wea.com |
| Service version | 2.1 |
2.1 |
2.0 |
2.0 |
2.0 |
mssecsvc ref |
mssecsvr.exe / 2.1 |
mssecsvr.exe / 2.1 |
mssecsvc.exe / 2.0 |
mssecsvc.exe / 2.0 |
mssecsvc.exe / 2.0 |
| ssdeep blocksize | 49152 |
49152 |
49152 |
98304 |
49152 |
The .rsrc size of 5,243,392 bytes is a new intermediate datapoint between the baseline 5,124,608 and the oversized 5,304,320 of b52a8049. The ssdeep blocksize remains 49152 (same as ad4df92f), suggesting the outer .text/.rdata structure is closer to the baseline than the b52a8049 variant. This is consistent with a builder pipeline that compiled the launcher DLL once and then varied only the embedded resource ZIP.
Interesting Tidbits
- OpenCTI mislabel: Tagged
dionaeaandexe^[triage.json] — it is neither a Dionaea honeypot artifact nor an EXE; it is a DLL and it is WannaCry. - Sixth confirmed sibling: This brings the corpus WannaCry cluster to six confirmed distinct SHA-256s. The
.rsrcsize spectrum now spans 5,124,608 → 5,243,392 → 5,304,320 bytes for the v2.0 branch. - Bitcoin wallets present in outer DLL: The three hardcoded BTC wallets are visible in the outer DLL strings ^[strings.txt:865-867], matching
b52a8049. In16fdcfbcandad4df92fthese wallets are not visible in the outer strings (or were extracted differently). - YARA generic only: Fires
PE_File_GenericandSuspicious_Crypto_Imports^[yara.txt] — no WannaCry-specific YARA rule hit. Family attribution relies on string forensics and corpus correlation. - capa/floss failures: Both
capa.txtandfloss.txtare error stubs ^[capa.txt] ^[floss.txt] — tooling failed, reinforcing the importance of manual string analysis. - Same timestamp, different hash: All six siblings carry
TimeDateStamp 0x59145729(2017-05-11 12:20:57 UTC) but have different SHA-256s. Consistent with link-time stamping across multiple compiles from the same source tree.
Deployable Signatures
YARA Rule
rule WannaCry_v20_DLL_541c9bc5 {
meta:
description = "WannaCry v2.0 DLL variant with wea.com kill-switch, intermediate .rsrc size"
author = "PacketPursuit SOC"
date = "2026-08-30"
sha256 = "541c9bc518635762bf9c14baec63c2703e3d9887246d3816865c95e2e430bfff"
strings:
$kill = "www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com" ascii wide
$svc = "Microsoft Security Center (2.0) Service" ascii wide
$msse = "mssecsvc.exe" ascii wide
$msse2 = "mssecsvc2.0" ascii wide
$task = "tasksche.exe" ascii wide
$wnry = ".wnry" ascii wide
$ipc = "\\%s\\IPC$" ascii wide
$btc1 = "115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn" ascii wide
$btc2 = "12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw" ascii wide
$btc3 = "13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x4550 and
4 of them
}
Sigma Rule
title: WannaCry v2.0 Service Installation (541c9bc5 variant)
detection:
selection:
EventID: 7045
ServiceName: 'Microsoft Security Center (2.0) Service'
condition: selection
IOC List
| Category | Value |
|---|---|
| SHA-256 | 541c9bc518635762bf9c14baec63c2703e3d9887246d3816865c95e2e430bfff |
| ssdeep | 49152:jn2nAQqMSPbcBVQej/1INRx+TSqTdX1HkQo6SAARdhnvxJM0H:DyDqPoBhz1aRxcSUDk36SAEdhvxWa |
| Kill-switch domain | www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com |
| Service name | Microsoft Security Center (2.0) Service |
| File names | mssecsvc.exe, mssecsvc2.0, tasksche.exe |
| SMB indicator | \\%s\IPC$ |
| Bitcoin wallets | 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn, 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw, 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 |
Behavioral Fingerprint
This DLL, when loaded by a launcher or rundll32, first attempts an outbound HTTP GET to www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com. If the domain resolves and returns data, the process terminates immediately. On failure, it installs itself as a fake "Microsoft Security Center (2.0)" service for persistence, then extracts an encrypted ZIP payload from its own .rsrc section and begins SMB scanning on TCP/445 for lateral movement. No anti-debug checks in the outer layer; defense is the kill-switch gate and payload encryption. The outer DLL contains three hardcoded Bitcoin wallet addresses and uses launcher.dll / PlayGame export masquerade.
Detection Signatures
| ATT&CK Technique | Evidence |
|---|---|
| T1486 — Data Encrypted for Impact | Embedded s.wnry encrypted payload, CryptAcquireContextA ^[strings.txt:227] |
| T1490 — Inhibit System Recovery | Ransom note ZIP contains recovery instructions; known to delete shadow copies in inner payload |
| T1021.002 — SMB/Windows Admin Shares | \\%s\IPC$ ^[strings.txt:642], mssecsvc.exe propagation service ^[strings.txt:74] |
| T1543.003 — Windows Service | CreateServiceA + OpenSCManagerA + Microsoft Security Center (2.0) Service ^[strings.txt:231-232] ^[strings.txt:646] |
| T1071.001 — Web Protocols | Kill-switch check via InternetOpenUrlA ^[strings.txt:247-248] |
| T1588.001 — Malicious Link | Kill-switch domain hardcoded ^[strings.txt:656] |
| T1497.001 — Virtualisation/Sandbox Evasion | Kill-switch domain check acts as circuit-breaker ^[strings.txt:656] |
References
- MITRE ATT&CK: WannaCry (S0367) — https://attack.mitre.org/software/S0367/
- Wiki sibling:
16fdcfbc— WannaCry v2.1 DLL withwff.comkill-switch ^[/intel/analyses/16fdcfbc4c5d2a7d5e2ccfd28e4b99208797c91315390718de532d9bd9e46d20.html] - Wiki sibling:
ad4df92f— WannaCry v2.0 DLL withwea.comkill-switch ^[/intel/analyses/ad4df92f352378948654b371e619072118f8e6eb3550a6d47ced2710ccf438c3.html] - Wiki sibling:
50a9f720— WannaCry v2.1 DLL, distinct hash ^[/intel/analyses/50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c.html] - Wiki sibling:
b52a8049— WannaCry v2.0 DLL, oversized .rsrc ^[/intel/analyses/b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb.html] - Wiki sibling:
549867cd— WannaCry v2.1 DLL, malformed PE header ^[/intel/analyses/549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3.html] - Wiki: wannacry entity page, kill-switch-domain-check technique page
Provenance
file.txt— file(1) 5.44pefile.txt— pefile 2023.2.7strings.txt— GNU strings 2.40 (4584 lines)binwalk.txt— binwalk v2.3.4rabin2-info.txt— radare2 5.9.4exiftool.json— ExifTool 12.76triage.json— PacketPursuit triage-fast, 2026-05-29yara.txt— YARA 4.5.2ssdeep.txt— ssdeep 2.14.1capa.txt— capa error stub (signatures missing)floss.txt— floss error stub (argument parsing failure)- Radare2 decompilation — r2mcp, analysis level 2, 209 functions