typeanalysisfamilywannacryconfidencehighcreated2026-08-15updated2026-08-15malware-familyransomwareimpactlateral-movementc2pe
SHA-256: 549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3

wannacry: 549867cd — v2.1 sibling with malformed PE header, inflated .rsrc SizeOfRawData

Executive Summary

A fifth confirmed WannaCry v2.1 sibling (SHA-256 549867cd...) sharing the same build timestamp, kill-switch domain (www.iuqerfsodp9ifjagosurijfaewrwergwff.com), and service name (Microsoft Security Center (2.1) Service) as sibling 16fdcfbc. Distinguished by a malformed PE header in which .rsrc and .reloc sections claim SizeOfRawData values exceeding the actual file length, producing pefile parsing errors and an inflated SizeOfImage (0x513000 vs actual 0x4C9800). Static-only; CAPE skipped (no Windows guest). For shared family behaviour see wannacry.

What It Is

  • SHA-256: 549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3
  • File type: PE32+ executable (DLL) (console) x86-64, 6 sections ^[file.txt]
  • Size: 5,019,648 bytes
  • Build timestamp: Thu May 11 12:20:57 2017 UTC ^[pefile.txt:48]
  • Linker: MSVC 10.0 (Visual Studio 2010) — MajorLinkerVersion 0xA ^[pefile.txt:59]
  • Export: launcher.dll : PlayGame (ordinal 1, RVA 0x11A4) ^[pefile.txt:278]
  • Subsystem: Windows CUI (console) ^[rabin2-info.txt:32]
  • ASLR/NX: Dynamic base + NX compatible (DllCharacteristics 0x140) ^[pefile.txt:80]
  • Signing: Unsigned ^[rabin2-info.txt:27]
  • Family: wannacry — high-confidence attribution based on kill-switch domain, service name, embedded ZIP payload structure, and BTC wallets.

How It Works

This is a cluster sibling; shared behaviour (kill-switch check, service persistence, EternalBlue propagation, AES-128/RSA-2048 encryption, Tor C2) is documented on the wannacry entity page. Per-sample deltas below.

PE header malformation. The .rsrc section claims SizeOfRawData = 0x500200 (5,242,624 bytes) and .reloc claims 0xE00 (3,584 bytes), but the file is only 5,019,648 bytes. pefile flags three parsing errors: sections 4 and 5 have SizeOfRawData larger than file, and section 5's PointerToRawData points beyond EOF ^[pefile.txt:5–13]. The SizeOfImage header field is 0x513000 (5,308,416 bytes), also larger than the actual file. Despite the header inflation, the embedded ZIP payload (starting at raw offset ~0x4EA3C / RVA ~0x110A4) is intact and fully parseable.

Embedded payload structure. Identical to other v2.1 siblings: a password-protected ZIP inside .rsrc containing:

  • b.wnry — encryption component (compressed 14,164 → uncompressed 1,440,054) ^[binwalk.txt:12]
  • c.wnry — configuration (compressed 177 → uncompressed 780) ^[binwalk.txt:13]
  • msg/m_*.wnry — 27-language ransom notes ^[binwalk.txt:14–41]
  • r.wnry — Tor client (compressed 484 → uncompressed 864) ^[binwalk.txt:42]
  • s.wnry — main decryptor/UI (compressed 3,009,375 → uncompressed 3,038,286) ^[binwalk.txt:43]

Kill-switch. Hardcoded HTTP GET to http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com; aborts if the domain resolves ^[strings.txt:656]. This is the v2.1 domain (same as sibling 16fdcfbc and 50a9f720).

Service persistence. Installs as Windows service Microsoft Security Center (2.1) Service with internal name mssecsvc2.1 ^[strings.txt:645–646]. The dropped executable is tasksche.exe ^[strings.txt:651,831].

Bitcoin wallets. Three hardcoded addresses in the outer DLL:

  • 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn ^[strings.txt:827]
  • 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw ^[strings.txt:828]
  • 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 ^[strings.txt:829]

Mutex. Global\MsWinZonesCacheCounterMutexA ^[strings.txt:830] — used for single-instance enforcement.

Inner payload imports. The embedded tasksche.exe (visible in strings as a second PE import table) imports CryptAcquireContextA, CryptGenRandom, service control APIs (OpenSCManagerA, CreateServiceA, StartServiceA), WinHTTP (InternetOpenA, InternetOpenUrlA), and networking (WS2_32.dll, iphlpapi.dll) ^[strings.txt:227–249].

Decompiled Behavior

Radare2 analysis found 209 functions. Entry point at 0x1800015EC (entry0) is the standard DLL entry-point dispatcher:

void entry0(int64_t arg1, uint32_t arg2, int64_t arg3) {
    // DLL_PROCESS_ATTACH (1)
    if (arg2 == 1) {
        if (qword[0x1800092e0] != 0) {
            // calls fcn.18000137c (init)
            // calls fcn.180001000 (main work)
            // calls fcn.18000137c again
            // calls indirect via qword[0x1800092e0]
        }
    }
    // DLL_PROCESS_DETACH (0) and other reasons handled similarly
}

^[r2:entry0]

The function pointer at 0x1800092e0 is referenced three times in entry0 and appears to be the primary payload dispatch routine. fcn.180001000 returns early (likely a stub or guard function). The actual malware logic is in the indirectly-called function and in the embedded tasksche.exe payload extracted from .rsrc.

No CAPE detonation. Dynamic analysis was skipped because no Windows CAPE guest is configured. All behaviour inferences above are static-only, cross-referenced against the known WannaCry v2.1 runtime behaviour documented in sibling reports.

C2 Infrastructure

Indicator Value Source
Kill-switch domain www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com ^[strings.txt:656]
Tor C2 Embedded r.wnry → .onion payment portal ^[binwalk.txt:42]
BTC #1 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn ^[strings.txt:827]
BTC #2 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw ^[strings.txt:828]
BTC #3 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 ^[strings.txt:829]
Service name Microsoft Security Center (2.1) Service ^[strings.txt:646]
Service short name mssecsvc2.1 ^[strings.txt:645]
Mutex Global\MsWinZonesCacheCounterMutexA ^[strings.txt:830]
Dropped filename tasksche.exe ^[strings.txt:651]

Interesting Tidbits

  • The .rsrc section's VirtualSize and SizeOfRawData both claim 0x500200 bytes, but the file ends at offset 0x4C9800. This produces a Resource size 0x500001 exceeds file size warning from pefile ^[pefile.txt:11]. The header malformation is likely a build artefact rather than deliberate anti-analysis, because the ZIP payload is still fully recoverable by binwalk.
  • The outer DLL exports PlayGame from launcher.dll — a generic game-masquerade export name. The inner tasksche.exe handles all malicious logic.
  • capa failed to run (missing signatures directory) ^[capa.txt]; no capability mapping available for this analysis.
  • floss also failed (argument parsing error — the triage pipeline passed the sample path as an argument to --no) ^[floss.txt].
  • The strings contain multiple embedded PE DOS stubs (!This program cannot be run in DOS mode) at various offsets, corresponding to the outer DLL, inner tasksche.exe, and the s.wnry / b.wnry payloads inside the ZIP.

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2010 (MSVC 10.0), C++ with MSVCP60/MSVCRT runtime, targeting PE32+ x64 DLL console subsystem.

Build recipe:

  1. Compile a minimal x64 DLL with a single exported function (PlayGame) that extracts an embedded ZIP resource via FindResourceA / LoadResource / LockResource.
  2. Embed a password-protected ZIP as a custom resource type (e.g., named "W" with ID 0x65).
  3. On DLL_PROCESS_ATTACH, extract the ZIP to %WINDIR%\tasksche.exe, then spawn it via CreateProcessA.
  4. The extracted EXE should install itself as a service (CreateServiceA + StartServiceA) and attempt an HTTP GET to a hardcoded domain before proceeding.
  5. Use standard Windows crypto APIs (CryptAcquireContextA, CryptGenRandom, CryptEncrypt) for AES-128 file encryption with an RSA-2048 public key embedded in the payload.

Verification: Compare your reproducer's pefile section layout and strings against this sample — should show identical launcher.dll / PlayGame export, custom resource type "W", and tasksche.exe drop pattern.

Deployable Signatures

YARA Rule

rule wannacry_v2_1_wff_kill_switch {
    meta:
        description = "WannaCry v2.1 outer DLL — wff.com kill-switch, mssecsvc2.1 service, PlayGame export"
        author = "PacketPursuit SOC"
        reference = "raw/analyses/549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3"
        date = "2026-08-15"
        version = "1.0"
    strings:
        $kill = "www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com" ascii wide
        $svc = "Microsoft Security Center (2.1) Service" ascii wide
        $svcshort = "mssecsvc2.1" ascii wide
        $drop = "tasksche.exe" ascii wide
        $mutex = "MsWinZonesCacheCounterMutexA" ascii wide
        $exp1 = "launcher.dll" ascii wide
        $exp2 = "PlayGame" ascii wide
        $btc1 = "115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn" ascii wide
        $btc2 = "12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw" ascii wide
        $btc3 = "13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        pe.is_dll() and
        pe.machine == pe.MACHINE_AMD64 and
        $kill and $svc and $exp2 and
        2 of ($btc*)
}

IOC List

Type Value
SHA-256 549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3
Export name PlayGame
Export module launcher.dll
Kill-switch URL http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
Service display name Microsoft Security Center (2.1) Service
Service name mssecsvc2.1
Dropped executable tasksche.exe
Mutex Global\MsWinZonesCacheCounterMutexA
BTC wallet #1 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn
BTC wallet #2 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw
BTC wallet #3 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94
Embedded ZIP files b.wnry, c.wnry, r.wnry, s.wnry, msg/m_*.wnry

Behavioral Fingerprint

This binary is a PE32+ x64 DLL with a single exported function (PlayGame) masquerading as launcher.dll. On load, it extracts a password-protected ZIP from a custom resource type ("W", ID 0x65) in its .rsrc section, drops the contents to disk as tasksche.exe, and launches it. The inner executable installs a Windows service named Microsoft Security Center (2.1) Service (mssecsvc2.1) and attempts an unencrypted HTTP GET to www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com; if the domain resolves, execution aborts. If the kill-switch fails, it propagates via EternalBlue SMB exploit (TCP/445) to random internal IPs and encrypts files using AES-128 with RSA-2048 key management. A global mutex MsWinZonesCacheCounterMutexA prevents multiple instances. Three hardcoded Bitcoin wallet addresses are embedded in the outer DLL strings.

Detection Signatures

  • YARA matches: PE_File_Generic, Suspicious_Crypto_Imports ^[yara.txt]
  • capa: Failed — signatures directory missing. No ATT&CK mapping generated for this analysis. ^[capa.txt]
  • MITRE ATT&CK (inferred from static + known WannaCry behaviour):
    • T1486 — Data Encrypted for Impact (AES-128 file encryption)
    • T1210 — Exploitation of Remote Services (EternalBlue SMB CVE-2017-0144)
    • T1543.003 — Create or Modify System Process: Windows Service (mssecsvc2.1)
    • T1071.001 — Application Layer Protocol: Web Protocols (HTTP kill-switch check)
    • T1490 — Inhibit System Recovery (shadow copy deletion, bcdedit in inner payload)
    • T1078 — Valid Accounts (spreads via SMB with stolen credentials/hashes)
    • T1105 — Ingress Tool Transfer (drops tasksche.exe from embedded ZIP)
    • T1027 — Obfuscated Files or Information (encrypted payload inside ZIP in .rsrc)

References

  • wannacry — cluster entity page with full TTP documentation
  • ransomware — parent malware category
  • Artifact ID: e180f0b6-eb6e-449e-8af9-3cbe865d8457
  • Source: OpenCTI / MalwareBazaar via urlhaus-recent-payloads connector
  • Sibling analyses: 16fdcfbc (v2.1, wff.com), 50a9f720 (v2.1, wff.com), ad4df92f (v2.0, wea.com), b52a8049 (v2.0, larger .rsrc)

Provenance

  • File type: file command (unknown version) ^[file.txt]
  • PE parsing: pefile Python library ^[pefile.txt]
  • Strings: strings -a -n 6 ^[strings.txt]
  • FLOSS: FireEye flare-floss (failed — argument parsing error) ^[floss.txt]
  • CAPA: Mandiant flare-capa (failed — missing signatures) ^[capa.txt]
  • Binwalk: binwalk v2.x ^[binwalk.txt]
  • rabin2: radare2 v5.x ^[rabin2-info.txt]
  • Radare2 decompilation: r2 pdc at entry0 (0x1800015EC), analysis level 3, 209 functions found ^[r2:entry0]
  • ExifTool: ExifTool 12.76 ^[exiftool.json]
  • CAPE: Skipped — no Windows guest available ^[dynamic-analysis.md]