typeanalysisfamilywannacryconfidencehighcreated2026-08-30updated2026-08-30malware-familyransomwareimpactc2lateral-movementpersistencepeevasion
SHA-256: 541c9bc518635762bf9c14baec63c2703e3d9887246d3816865c95e2e430bfff

wannacry: 541c9bc5 — Sixth confirmed WannaCry sibling, v2.0 build, intermediate .rsrc size

Executive Summary

A PE32+ x64 DLL compiled 11 May 2017, mislabeled dionaea by OpenCTI but confirmed as the sixth distinct wannacry outbreak sibling in the corpus. Shares the v2.0 kill-switch domain (wea.com) and service name (2.0) with ad4df92f and b52a8049, but carries a new intermediate .rsrc section size (5,243,392 bytes) between the 5,124,608-byte baseline and the 5,304,320-byte b52a8049 variant. Same outer-file size, same timestamp, same Bitcoin wallets. Static-only analysis; no CAPE Windows guest.

What It Is

Field Value
SHA-256 541c9bc518635762bf9c14baec63c2703e3d9887246d3816865c95e2e430bfff
File type PE32+ executable (DLL) (console) x86-64, 6 sections ^[file.txt]
Size 5,298,176 bytes (5.3 MB) ^[exiftool.json]
Compilation 2017-05-11 12:20:57 UTC (TimeDateStamp 0x59145729) ^[pefile.txt:38]
Linker MSVC 10.0 (Visual Studio 2010) ^[exiftool.json:18]
Runtime MSVCP60.dll + MSVCRT.dll (C++ CRT) ^[strings.txt:242]
Signed No ^[rabin2-info.txt]
Family wannacry — high confidence; OpenCTI label dionaea is false positive

The binary is a DLL with console subsystem (Subsystem: 0x3) ^[pefile.txt:69], intended to be loaded by a launcher or run via rundll32. Export table shows launcher.dll / PlayGame masquerade strings ^[strings.txt:177-178] — a known WannaCry launcher artifact.

The .rsrc section is 5,243,392 bytes (0x500200) ^[pefile.txt:162-179], which is:

  • 118,784 bytes larger than ad4df92f/50a9f720 (5,124,608 bytes)
  • 60,928 bytes smaller than b52a8049 (5,304,320 bytes)

This intermediate size is a new datapoint in the WannaCry builder pipeline, suggesting the embedded ZIP payload was re-compressed or re-packed with different parameters while the outer launcher DLL remained byte-identical in structure.

How It Works

Kill-Switch Gate (Version 2.0)

The kill-switch domain is http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com ^[strings.txt:656]. This matches the ad4df92f v2.0 sibling and differs from the 16fdcfbc/50a9f720 v2.1 siblings only in the TLD suffix (wea.com vs wff.com). Same InternetOpenUrlA → InternetOpenA WinInet call chain ^[strings.txt:247-248], same circuit-breaker behavior: if the domain resolves and returns data, the payload exits without encryption. See kill-switch-domain-check for the technique deep-dive.

Service Persistence (Version 2.0)

The DLL installs itself as a Windows service named Microsoft Security Center (2.0) Service ^[strings.txt:646] using OpenSCManagerA → CreateServiceA → StartServiceCtrlDispatcherA ^[strings.txt:231-232] ^[strings.txt:236]. The local service binary is referenced as mssecsvc.exe ^[strings.txt:74] ^[strings.txt:297] ^[strings.txt:371] and mssecsvc2.0 ^[strings.txt:645].

SMB Propagation

Identical to other siblings: \\%s\IPC$ ^[strings.txt:642] share path for EternalBlue exploitation, WS2_32.dll socket APIs ^[strings.txt:239], iphlpapi.dll for network enumeration ^[strings.txt:245]. The actual exploit payload is embedded inside the encrypted s.wnry resource and not visible statically.

Embedded Resource Payload

The .rsrc section contains a password-protected ZIP archive with the same family of contents ^[binwalk.txt]:

  • b.wnry — encrypted launcher/binary (1,440,054 bytes uncompressed)
  • c.wnry — encrypted configuration (780 bytes)
  • msg/m_*.wnry — 27 ransom-note translations (Bulgarian through Vietnamese) ^[strings.txt:936+]
  • r.wnry — encrypted Tor client (864 bytes)
  • s.wnry — encrypted main payload (~3,038,286 bytes uncompressed)

The outer DLL decrypts and extracts these at runtime via FindResourceA / LoadResource / LockResource / SizeofResource ^[strings.txt:109-113].

Cryptography

Key generation uses the Microsoft Base Cryptographic Provider:

  • CryptAcquireContextA + CryptGenRandom ^[strings.txt:227] for RNG
  • The ransomware uses RSA-2048 (per public literature) to encrypt per-file AES-128 keys

Decompiled Behavior

Radare2 analysis (level 2, 209 functions) shows the same entry-point layout as the other siblings:

  • entry0 at 0x1800015ec — DLL entry point with DllMain reason-code dispatch ^[rabin2-info.txt]
  • Service control dispatcher path (persistence)
  • Payload execution path (encryption)

The decompiled entry point is standard MSVC CRT-initialized with SEH frames, FLS/TLS setup, and no anti-debug or VM checks in the outer layer. No notable function deltas from prior siblings.

C2 Infrastructure

Type Indicator Notes
Kill-switch domain www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com Hardcoded; if reachable, encryption aborts ^[strings.txt:656]
SMB lateral \\%s\IPC$ EternalBlue propagation to random internal IPs ^[strings.txt:642]
Service name Microsoft Security Center (2.0) Service Fake service for persistence ^[strings.txt:646]
Bitcoin wallets 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn, 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw, 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 Hardcoded payment addresses ^[strings.txt:865-867]

No hardcoded IP addresses or email addresses visible in the outer DLL. The Tor C2 .onion address lives inside the encrypted r.wnry resource and is not statically recoverable.

Sibling Correlation

Attribute 16fdcfbc (v2.1) 50a9f720 (v2.1) ad4df92f (v2.0) b52a8049 (v2.0) 541c9bc5 (v2.0)
Size 5,298,176 5,298,176 5,298,176 5,298,176 5,298,176
.rsrc size 5,124,608 5,124,608 5,124,608 5,304,320 5,243,392
Kill-switch TLD wff.com wff.com wea.com wea.com wea.com
Service version 2.1 2.1 2.0 2.0 2.0
mssecsvc ref mssecsvr.exe / 2.1 mssecsvr.exe / 2.1 mssecsvc.exe / 2.0 mssecsvc.exe / 2.0 mssecsvc.exe / 2.0
ssdeep blocksize 49152 49152 49152 98304 49152

The .rsrc size of 5,243,392 bytes is a new intermediate datapoint between the baseline 5,124,608 and the oversized 5,304,320 of b52a8049. The ssdeep blocksize remains 49152 (same as ad4df92f), suggesting the outer .text/.rdata structure is closer to the baseline than the b52a8049 variant. This is consistent with a builder pipeline that compiled the launcher DLL once and then varied only the embedded resource ZIP.

Interesting Tidbits

  • OpenCTI mislabel: Tagged dionaea and exe ^[triage.json] — it is neither a Dionaea honeypot artifact nor an EXE; it is a DLL and it is WannaCry.
  • Sixth confirmed sibling: This brings the corpus WannaCry cluster to six confirmed distinct SHA-256s. The .rsrc size spectrum now spans 5,124,608 → 5,243,392 → 5,304,320 bytes for the v2.0 branch.
  • Bitcoin wallets present in outer DLL: The three hardcoded BTC wallets are visible in the outer DLL strings ^[strings.txt:865-867], matching b52a8049. In 16fdcfbc and ad4df92f these wallets are not visible in the outer strings (or were extracted differently).
  • YARA generic only: Fires PE_File_Generic and Suspicious_Crypto_Imports ^[yara.txt] — no WannaCry-specific YARA rule hit. Family attribution relies on string forensics and corpus correlation.
  • capa/floss failures: Both capa.txt and floss.txt are error stubs ^[capa.txt] ^[floss.txt] — tooling failed, reinforcing the importance of manual string analysis.
  • Same timestamp, different hash: All six siblings carry TimeDateStamp 0x59145729 (2017-05-11 12:20:57 UTC) but have different SHA-256s. Consistent with link-time stamping across multiple compiles from the same source tree.

Deployable Signatures

YARA Rule

rule WannaCry_v20_DLL_541c9bc5 {
    meta:
        description = "WannaCry v2.0 DLL variant with wea.com kill-switch, intermediate .rsrc size"
        author = "PacketPursuit SOC"
        date = "2026-08-30"
        sha256 = "541c9bc518635762bf9c14baec63c2703e3d9887246d3816865c95e2e430bfff"
    strings:
        $kill = "www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com" ascii wide
        $svc  = "Microsoft Security Center (2.0) Service" ascii wide
        $msse = "mssecsvc.exe" ascii wide
        $msse2 = "mssecsvc2.0" ascii wide
        $task = "tasksche.exe" ascii wide
        $wnry = ".wnry" ascii wide
        $ipc  = "\\%s\\IPC$" ascii wide
        $btc1 = "115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn" ascii wide
        $btc2 = "12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw" ascii wide
        $btc3 = "13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x4550 and
        4 of them
}

Sigma Rule

title: WannaCry v2.0 Service Installation (541c9bc5 variant)
detection:
    selection:
        EventID: 7045
        ServiceName: 'Microsoft Security Center (2.0) Service'
    condition: selection

IOC List

Category Value
SHA-256 541c9bc518635762bf9c14baec63c2703e3d9887246d3816865c95e2e430bfff
ssdeep 49152:jn2nAQqMSPbcBVQej/1INRx+TSqTdX1HkQo6SAARdhnvxJM0H:DyDqPoBhz1aRxcSUDk36SAEdhvxWa
Kill-switch domain www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
Service name Microsoft Security Center (2.0) Service
File names mssecsvc.exe, mssecsvc2.0, tasksche.exe
SMB indicator \\%s\IPC$
Bitcoin wallets 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn, 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw, 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94

Behavioral Fingerprint

This DLL, when loaded by a launcher or rundll32, first attempts an outbound HTTP GET to www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com. If the domain resolves and returns data, the process terminates immediately. On failure, it installs itself as a fake "Microsoft Security Center (2.0)" service for persistence, then extracts an encrypted ZIP payload from its own .rsrc section and begins SMB scanning on TCP/445 for lateral movement. No anti-debug checks in the outer layer; defense is the kill-switch gate and payload encryption. The outer DLL contains three hardcoded Bitcoin wallet addresses and uses launcher.dll / PlayGame export masquerade.

Detection Signatures

ATT&CK Technique Evidence
T1486 — Data Encrypted for Impact Embedded s.wnry encrypted payload, CryptAcquireContextA ^[strings.txt:227]
T1490 — Inhibit System Recovery Ransom note ZIP contains recovery instructions; known to delete shadow copies in inner payload
T1021.002 — SMB/Windows Admin Shares \\%s\IPC$ ^[strings.txt:642], mssecsvc.exe propagation service ^[strings.txt:74]
T1543.003 — Windows Service CreateServiceA + OpenSCManagerA + Microsoft Security Center (2.0) Service ^[strings.txt:231-232] ^[strings.txt:646]
T1071.001 — Web Protocols Kill-switch check via InternetOpenUrlA ^[strings.txt:247-248]
T1588.001 — Malicious Link Kill-switch domain hardcoded ^[strings.txt:656]
T1497.001 — Virtualisation/Sandbox Evasion Kill-switch domain check acts as circuit-breaker ^[strings.txt:656]

References

  • MITRE ATT&CK: WannaCry (S0367) — https://attack.mitre.org/software/S0367/
  • Wiki sibling: 16fdcfbc — WannaCry v2.1 DLL with wff.com kill-switch ^[/intel/analyses/16fdcfbc4c5d2a7d5e2ccfd28e4b99208797c91315390718de532d9bd9e46d20.html]
  • Wiki sibling: ad4df92f — WannaCry v2.0 DLL with wea.com kill-switch ^[/intel/analyses/ad4df92f352378948654b371e619072118f8e6eb3550a6d47ced2710ccf438c3.html]
  • Wiki sibling: 50a9f720 — WannaCry v2.1 DLL, distinct hash ^[/intel/analyses/50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c.html]
  • Wiki sibling: b52a8049 — WannaCry v2.0 DLL, oversized .rsrc ^[/intel/analyses/b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb.html]
  • Wiki sibling: 549867cd — WannaCry v2.1 DLL, malformed PE header ^[/intel/analyses/549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3.html]
  • Wiki: wannacry entity page, kill-switch-domain-check technique page

Provenance

  • file.txt — file(1) 5.44
  • pefile.txt — pefile 2023.2.7
  • strings.txt — GNU strings 2.40 (4584 lines)
  • binwalk.txt — binwalk v2.3.4
  • rabin2-info.txt — radare2 5.9.4
  • exiftool.json — ExifTool 12.76
  • triage.json — PacketPursuit triage-fast, 2026-05-29
  • yara.txt — YARA 4.5.2
  • ssdeep.txt — ssdeep 2.14.1
  • capa.txt — capa error stub (signatures missing)
  • floss.txt — floss error stub (argument parsing failure)
  • Radare2 decompilation — r2mcp, analysis level 2, 209 functions