549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3wannacry: 549867cd — v2.1 sibling with malformed PE header, inflated .rsrc SizeOfRawData
Executive Summary
A fifth confirmed WannaCry v2.1 sibling (SHA-256 549867cd...) sharing the same build timestamp, kill-switch domain (www.iuqerfsodp9ifjagosurijfaewrwergwff.com), and service name (Microsoft Security Center (2.1) Service) as sibling 16fdcfbc. Distinguished by a malformed PE header in which .rsrc and .reloc sections claim SizeOfRawData values exceeding the actual file length, producing pefile parsing errors and an inflated SizeOfImage (0x513000 vs actual 0x4C9800). Static-only; CAPE skipped (no Windows guest). For shared family behaviour see wannacry.
What It Is
- SHA-256:
549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3 - File type: PE32+ executable (DLL) (console) x86-64, 6 sections ^[file.txt]
- Size: 5,019,648 bytes
- Build timestamp: Thu May 11 12:20:57 2017 UTC ^[pefile.txt:48]
- Linker: MSVC 10.0 (Visual Studio 2010) — MajorLinkerVersion 0xA ^[pefile.txt:59]
- Export:
launcher.dll:PlayGame(ordinal 1, RVA 0x11A4) ^[pefile.txt:278] - Subsystem: Windows CUI (console) ^[rabin2-info.txt:32]
- ASLR/NX: Dynamic base + NX compatible (DllCharacteristics 0x140) ^[pefile.txt:80]
- Signing: Unsigned ^[rabin2-info.txt:27]
- Family: wannacry — high-confidence attribution based on kill-switch domain, service name, embedded ZIP payload structure, and BTC wallets.
How It Works
This is a cluster sibling; shared behaviour (kill-switch check, service persistence, EternalBlue propagation, AES-128/RSA-2048 encryption, Tor C2) is documented on the wannacry entity page. Per-sample deltas below.
PE header malformation. The .rsrc section claims SizeOfRawData = 0x500200 (5,242,624 bytes) and .reloc claims 0xE00 (3,584 bytes), but the file is only 5,019,648 bytes. pefile flags three parsing errors: sections 4 and 5 have SizeOfRawData larger than file, and section 5's PointerToRawData points beyond EOF ^[pefile.txt:5–13]. The SizeOfImage header field is 0x513000 (5,308,416 bytes), also larger than the actual file. Despite the header inflation, the embedded ZIP payload (starting at raw offset ~0x4EA3C / RVA ~0x110A4) is intact and fully parseable.
Embedded payload structure. Identical to other v2.1 siblings: a password-protected ZIP inside .rsrc containing:
b.wnry— encryption component (compressed 14,164 → uncompressed 1,440,054) ^[binwalk.txt:12]c.wnry— configuration (compressed 177 → uncompressed 780) ^[binwalk.txt:13]msg/m_*.wnry— 27-language ransom notes ^[binwalk.txt:14–41]r.wnry— Tor client (compressed 484 → uncompressed 864) ^[binwalk.txt:42]s.wnry— main decryptor/UI (compressed 3,009,375 → uncompressed 3,038,286) ^[binwalk.txt:43]
Kill-switch. Hardcoded HTTP GET to http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com; aborts if the domain resolves ^[strings.txt:656]. This is the v2.1 domain (same as sibling 16fdcfbc and 50a9f720).
Service persistence. Installs as Windows service Microsoft Security Center (2.1) Service with internal name mssecsvc2.1 ^[strings.txt:645–646]. The dropped executable is tasksche.exe ^[strings.txt:651,831].
Bitcoin wallets. Three hardcoded addresses in the outer DLL:
115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn^[strings.txt:827]12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw^[strings.txt:828]13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94^[strings.txt:829]
Mutex. Global\MsWinZonesCacheCounterMutexA ^[strings.txt:830] — used for single-instance enforcement.
Inner payload imports. The embedded tasksche.exe (visible in strings as a second PE import table) imports CryptAcquireContextA, CryptGenRandom, service control APIs (OpenSCManagerA, CreateServiceA, StartServiceA), WinHTTP (InternetOpenA, InternetOpenUrlA), and networking (WS2_32.dll, iphlpapi.dll) ^[strings.txt:227–249].
Decompiled Behavior
Radare2 analysis found 209 functions. Entry point at 0x1800015EC (entry0) is the standard DLL entry-point dispatcher:
void entry0(int64_t arg1, uint32_t arg2, int64_t arg3) {
// DLL_PROCESS_ATTACH (1)
if (arg2 == 1) {
if (qword[0x1800092e0] != 0) {
// calls fcn.18000137c (init)
// calls fcn.180001000 (main work)
// calls fcn.18000137c again
// calls indirect via qword[0x1800092e0]
}
}
// DLL_PROCESS_DETACH (0) and other reasons handled similarly
}
^[r2:entry0]
The function pointer at 0x1800092e0 is referenced three times in entry0 and appears to be the primary payload dispatch routine. fcn.180001000 returns early (likely a stub or guard function). The actual malware logic is in the indirectly-called function and in the embedded tasksche.exe payload extracted from .rsrc.
No CAPE detonation. Dynamic analysis was skipped because no Windows CAPE guest is configured. All behaviour inferences above are static-only, cross-referenced against the known WannaCry v2.1 runtime behaviour documented in sibling reports.
C2 Infrastructure
| Indicator | Value | Source |
|---|---|---|
| Kill-switch domain | www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com |
^[strings.txt:656] |
| Tor C2 | Embedded r.wnry → .onion payment portal |
^[binwalk.txt:42] |
| BTC #1 | 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn |
^[strings.txt:827] |
| BTC #2 | 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw |
^[strings.txt:828] |
| BTC #3 | 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 |
^[strings.txt:829] |
| Service name | Microsoft Security Center (2.1) Service |
^[strings.txt:646] |
| Service short name | mssecsvc2.1 |
^[strings.txt:645] |
| Mutex | Global\MsWinZonesCacheCounterMutexA |
^[strings.txt:830] |
| Dropped filename | tasksche.exe |
^[strings.txt:651] |
Interesting Tidbits
- The
.rsrcsection'sVirtualSizeandSizeOfRawDataboth claim0x500200bytes, but the file ends at offset0x4C9800. This produces aResource size 0x500001 exceeds file sizewarning from pefile ^[pefile.txt:11]. The header malformation is likely a build artefact rather than deliberate anti-analysis, because the ZIP payload is still fully recoverable by binwalk. - The outer DLL exports
PlayGamefromlauncher.dll— a generic game-masquerade export name. The innertasksche.exehandles all malicious logic. capafailed to run (missing signatures directory) ^[capa.txt]; no capability mapping available for this analysis.flossalso failed (argument parsing error — the triage pipeline passed the sample path as an argument to--no) ^[floss.txt].- The strings contain multiple embedded PE DOS stubs (
!This program cannot be run in DOS mode) at various offsets, corresponding to the outer DLL, innertasksche.exe, and thes.wnry/b.wnrypayloads inside the ZIP.
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2010 (MSVC 10.0), C++ with MSVCP60/MSVCRT runtime, targeting PE32+ x64 DLL console subsystem.
Build recipe:
- Compile a minimal x64 DLL with a single exported function (
PlayGame) that extracts an embedded ZIP resource viaFindResourceA/LoadResource/LockResource. - Embed a password-protected ZIP as a custom resource type (e.g., named
"W"with ID0x65). - On
DLL_PROCESS_ATTACH, extract the ZIP to%WINDIR%\tasksche.exe, then spawn it viaCreateProcessA. - The extracted EXE should install itself as a service (
CreateServiceA+StartServiceA) and attempt an HTTP GET to a hardcoded domain before proceeding. - Use standard Windows crypto APIs (
CryptAcquireContextA,CryptGenRandom,CryptEncrypt) for AES-128 file encryption with an RSA-2048 public key embedded in the payload.
Verification: Compare your reproducer's pefile section layout and strings against this sample — should show identical launcher.dll / PlayGame export, custom resource type "W", and tasksche.exe drop pattern.
Deployable Signatures
YARA Rule
rule wannacry_v2_1_wff_kill_switch {
meta:
description = "WannaCry v2.1 outer DLL — wff.com kill-switch, mssecsvc2.1 service, PlayGame export"
author = "PacketPursuit SOC"
reference = "raw/analyses/549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3"
date = "2026-08-15"
version = "1.0"
strings:
$kill = "www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com" ascii wide
$svc = "Microsoft Security Center (2.1) Service" ascii wide
$svcshort = "mssecsvc2.1" ascii wide
$drop = "tasksche.exe" ascii wide
$mutex = "MsWinZonesCacheCounterMutexA" ascii wide
$exp1 = "launcher.dll" ascii wide
$exp2 = "PlayGame" ascii wide
$btc1 = "115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn" ascii wide
$btc2 = "12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw" ascii wide
$btc3 = "13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94" ascii wide
condition:
uint16(0) == 0x5A4D and
pe.is_dll() and
pe.machine == pe.MACHINE_AMD64 and
$kill and $svc and $exp2 and
2 of ($btc*)
}
IOC List
| Type | Value |
|---|---|
| SHA-256 | 549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3 |
| Export name | PlayGame |
| Export module | launcher.dll |
| Kill-switch URL | http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com |
| Service display name | Microsoft Security Center (2.1) Service |
| Service name | mssecsvc2.1 |
| Dropped executable | tasksche.exe |
| Mutex | Global\MsWinZonesCacheCounterMutexA |
| BTC wallet #1 | 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn |
| BTC wallet #2 | 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw |
| BTC wallet #3 | 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 |
| Embedded ZIP files | b.wnry, c.wnry, r.wnry, s.wnry, msg/m_*.wnry |
Behavioral Fingerprint
This binary is a PE32+ x64 DLL with a single exported function (PlayGame) masquerading as launcher.dll. On load, it extracts a password-protected ZIP from a custom resource type ("W", ID 0x65) in its .rsrc section, drops the contents to disk as tasksche.exe, and launches it. The inner executable installs a Windows service named Microsoft Security Center (2.1) Service (mssecsvc2.1) and attempts an unencrypted HTTP GET to www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com; if the domain resolves, execution aborts. If the kill-switch fails, it propagates via EternalBlue SMB exploit (TCP/445) to random internal IPs and encrypts files using AES-128 with RSA-2048 key management. A global mutex MsWinZonesCacheCounterMutexA prevents multiple instances. Three hardcoded Bitcoin wallet addresses are embedded in the outer DLL strings.
Detection Signatures
- YARA matches:
PE_File_Generic,Suspicious_Crypto_Imports^[yara.txt] - capa: Failed — signatures directory missing. No ATT&CK mapping generated for this analysis. ^[capa.txt]
- MITRE ATT&CK (inferred from static + known WannaCry behaviour):
- T1486 — Data Encrypted for Impact (AES-128 file encryption)
- T1210 — Exploitation of Remote Services (EternalBlue SMB CVE-2017-0144)
- T1543.003 — Create or Modify System Process: Windows Service (
mssecsvc2.1) - T1071.001 — Application Layer Protocol: Web Protocols (HTTP kill-switch check)
- T1490 — Inhibit System Recovery (shadow copy deletion, bcdedit in inner payload)
- T1078 — Valid Accounts (spreads via SMB with stolen credentials/hashes)
- T1105 — Ingress Tool Transfer (drops
tasksche.exefrom embedded ZIP) - T1027 — Obfuscated Files or Information (encrypted payload inside ZIP in
.rsrc)
References
- wannacry — cluster entity page with full TTP documentation
- ransomware — parent malware category
- Artifact ID:
e180f0b6-eb6e-449e-8af9-3cbe865d8457 - Source: OpenCTI / MalwareBazaar via
urlhaus-recent-payloadsconnector - Sibling analyses:
16fdcfbc(v2.1,wff.com),50a9f720(v2.1,wff.com),ad4df92f(v2.0,wea.com),b52a8049(v2.0, larger.rsrc)
Provenance
- File type:
filecommand (unknown version) ^[file.txt] - PE parsing: pefile Python library ^[pefile.txt]
- Strings:
strings -a -n 6^[strings.txt] - FLOSS: FireEye flare-floss (failed — argument parsing error) ^[floss.txt]
- CAPA: Mandiant flare-capa (failed — missing signatures) ^[capa.txt]
- Binwalk: binwalk v2.x ^[binwalk.txt]
- rabin2: radare2 v5.x ^[rabin2-info.txt]
- Radare2 decompilation: r2
pdcatentry0(0x1800015EC), analysis level 3, 209 functions found ^[r2:entry0] - ExifTool: ExifTool 12.76 ^[exiftool.json]
- CAPE: Skipped — no Windows guest available ^[dynamic-analysis.md]