b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72ebwannacry: b52a8049 — Fourth confirmed WannaCry sibling, v2.0 build, kill-switch wea.com, oversized .rsrc
Executive Summary
A PE32+ x64 DLL compiled 11 May 2017, mislabeled dionaea by OpenCTI but confirmed as a wannacry outbreak sibling. It shares the v2.0 kill-switch domain (wea.com) and service name (2.0) with the previously-analysed ad4df92f sibling, but is not byte-identical: a larger .rsrc section (5,304,320 vs 5,124,608 bytes), a distinct ssdeep hash, and a divergent ZIP payload layout mark it as a fourth confirmed distinct file in the wild. Static-only analysis; no CAPE Windows guest available.
What It Is
| Field | Value |
|---|---|
| SHA-256 | b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb |
| File type | PE32+ executable (DLL) (console) x86-64, 6 sections ^[file.txt] |
| Size | 5,298,176 bytes (5.3 MB) ^[exiftool.json] |
| Compilation | 2017-05-11 12:20:57 UTC (TimeDateStamp 0x59145729) ^[pefile.txt:38] |
| Linker | MSVC 10.0 (Visual Studio 2010) ^[exiftool.json:18] |
| Runtime | MSVCP60.dll + MSVCRT.dll (C++ CRT) ^[strings.txt:242] |
| Signed | No ^[rabin2-info.txt] |
| Family | wannacry — high confidence; OpenCTI label dionaea is false positive |
The binary is a DLL with console subsystem (Subsystem: 0x3) ^[pefile.txt:69], intended to be loaded by a launcher or run via rundll32. Export table shows launcher.dll / PlayGame masquerade strings ^[strings.txt:177-178] — a known WannaCry launcher artifact.
How It Works
Kill-Switch Gate (Version 2.0)
The kill-switch domain is http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com ^[strings.txt:658]. This matches the ad4df92f v2.0 sibling and differs from the 16fdcfbc/50a9f720 v2.1 siblings only in the TLD suffix (wea.com vs wff.com). Same InternetOpenUrlA → InternetOpenA WinInet call chain ^[strings.txt:247-248], same circuit-breaker behavior: if the domain resolves and returns data, the payload exits without encryption. See kill-switch-domain-check for the technique deep-dive.
Service Persistence (Version 2.0)
The DLL installs itself as a Windows service named Microsoft Security Center (2.0) Service ^[strings.txt:646] using OpenSCManagerA → CreateServiceA → StartServiceCtrlDispatcherA ^[strings.txt:231-232] ^[strings.txt:236]. The local service binary is referenced as mssecsvc.exe ^[strings.txt:74] ^[strings.txt:297] ^[strings.txt:371] and mssecsvc2.0 ^[strings.txt:645].
SMB Propagation
Identical to other siblings: \\%s\IPC$ ^[strings.txt:642] share path for EternalBlue exploitation, WS2_32.dll socket APIs ^[strings.txt:239] ^[strings.txt:799], iphlpapi.dll for network enumeration ^[strings.txt:245]. The actual exploit payload is embedded inside the encrypted s.wnry resource and not visible statically.
Embedded Resource Payload
The .rsrc section is 5,304,320 bytes — larger than the 5,124,608 bytes observed in ad4df92f — and contains a password-protected ZIP archive with the same family of contents ^[binwalk.txt]:
b.wnry— encrypted launcher/binary (1,440,054 bytes uncompressed)c.wnry— encrypted configuration (780 bytes)msg/m_*.wnry— 27 ransom-note translations (Bulgarian, Chinese Simplified/Traditional, Croatian, Czech, Danish, Dutch, English, Filipino, Finnish, French, German, Greek, Indonesian, Italian, Japanese, Korean, Latvian, Norwegian, Polish, Portuguese, Romanian, Russian, Slovak, Spanish, Swedish, Turkish, Vietnamese) ^[strings.txt:936+]r.wnry— encrypted Tor client (864 bytes)s.wnry— encrypted main payload (~3,038,286 bytes uncompressed)
The ZIP is encrypted with ZIP 2.0 password protection. The outer DLL decrypts and extracts these at runtime via FindResourceA / LoadResource / LockResource / SizeofResource ^[strings.txt:109-113].
Cryptography
Key generation uses the Microsoft Base Cryptographic Provider:
CryptAcquireContextA+CryptGenRandom^[strings.txt:227] ^[strings.txt:865] for RNG- The ransomware uses RSA-2048 (per public literature) to encrypt per-file AES-128 keys
Decompiled Behavior
Radare2 analysis (level 2, 209 functions) shows the same entry-point layout as the other siblings:
entry0at0x1800015ec— DLL entry point withDllMainreason-code dispatch ^[rabin2-info.txt]- Service control dispatcher path (persistence)
- Payload execution path (encryption)
The decompiled entry point is standard MSVC CRT-initialised with SEH frames, FLS/TLS setup, and no anti-debug or VM checks in the outer layer. No notable function deltas from ad4df92f or 16fdcfbc.
C2 Infrastructure
| Type | Indicator | Notes |
|---|---|---|
| Kill-switch domain | www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com |
Hardcoded; if reachable, encryption aborts ^[strings.txt:658] |
| SMB lateral | \\%s\IPC$ |
EternalBlue propagation to random internal IPs ^[strings.txt:642] |
| Service name | Microsoft Security Center (2.0) Service |
Fake service for persistence ^[strings.txt:646] |
| Bitcoin wallets | 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn, 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw, 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 |
Hardcoded payment addresses ^[strings.txt:867-869] |
No hardcoded IP addresses or email addresses visible in the outer DLL. The Tor C2 .onion address lives inside the encrypted r.wnry resource and is not statically recoverable.
Sibling Correlation
| Attribute | 16fdcfbc (v2.1) |
50a9f720 (v2.1) |
ad4df92f (v2.0) |
b52a8049 (v2.0) |
|---|---|---|---|---|
| Size | 5,298,176 | 5,298,176 | 5,298,176 | 5,298,176 |
.rsrc size |
5,124,608 | 5,124,608 | 5,124,608 | 5,304,320 |
| Kill-switch TLD | wff.com |
wff.com |
wea.com |
wea.com |
| Service version | 2.1 |
2.1 |
2.0 |
2.0 |
mssecsvc ref |
mssecsvr.exe / 2.1 |
mssecsvr.exe / 2.1 |
mssecsvc.exe / 2.0 |
mssecsvc.exe / 2.0 |
| ssdeep | 49152:… |
49152:… |
49152:… |
98304:… (blocksize doubled) |
The .rsrc size delta (~180 KB larger) and the ssdeep blocksize doubling suggest this build used a different ZIP compression level or embedded a slightly different inner payload, even though the outer compilation timestamp is identical. This is consistent with a builder pipeline that compiled the launcher DLL once and then varied the embedded resource ZIP.
Interesting Tidbits
- OpenCTI mislabel: Tagged
dionaeaandexe^[triage.json] — it is neither a Dionaea honeypot artifact nor an EXE; it is a DLL and it is WannaCry. - Bitcoin wallets present in outer DLL: Unlike
16fdcfbcandad4df92f, this sample has the three hardcoded BTC wallets visible in the outer DLL strings ^[strings.txt:867-869]. In the other siblings these wallets are only inside the encrypted ransom-note resources. This may indicate a build-stage difference or simply that the wallets were also present in those binaries but in a different string encoding. - YARA generic only: Fires
PE_File_GenericandSuspicious_Crypto_Imports^[yara.txt] — no WannaCry-specific YARA rule hit. The family attribution relies on string forensics and corpus correlation. - capa/floss failures: Both
capa.txtandfloss.txtare error stubs ^[capa.txt] ^[floss.txt] — the tooling failed on this sample, reinforcing the importance of manual string analysis. - Same timestamp, different hash: All four siblings carry
TimeDateStamp 0x59145729(2017-05-11 12:20:57 UTC) but have different SHA-256s and ssdeeps. This is consistent with link-time stamping across multiple compiles from the same source tree.
Deployable Signatures
YARA Rule
rule WannaCry_v20_DLL_b52a8049 {
meta:
description = "WannaCry v2.0 DLL variant with wea.com kill-switch and outer-DLL bitcoin wallets"
author = "PacketPursuit SOC"
date = "2026-08-07"
sha256 = "b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb"
strings:
$kill = "www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com" ascii wide
$svc = "Microsoft Security Center (2.0) Service" ascii wide
$msse = "mssecsvc.exe" ascii wide
$msse2 = "mssecsvc2.0" ascii wide
$task = "tasksche.exe" ascii wide
$wnry = ".wnry" ascii wide
$ipc = "\\%s\\IPC$" ascii wide
$btc1 = "115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn" ascii wide
$btc2 = "12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw" ascii wide
$btc3 = "13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x4550 and
4 of them
}
Sigma Rule
title: WannaCry v2.0 Service Installation (b52a8049 variant)
detection:
selection:
EventID: 7045
ServiceName: 'Microsoft Security Center (2.0) Service'
condition: selection
IOC List
| Category | Value |
|---|---|
| SHA-256 | b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb |
| MD5 | 040ed1613a8aa0d8caf59474ec94022e |
| ssdeep | 98304:D9zqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2H:D9zqPe1Cxcxk3ZAEUadzR8yc4H |
| Kill-switch domain | www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com |
| Service name | Microsoft Security Center (2.0) Service |
| File names | mssecsvc.exe, mssecsvc2.0, tasksche.exe |
| SMB indicator | \\%s\IPC$ |
| Bitcoin wallets | 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn, 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw, 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 |
Behavioral Fingerprint
This DLL, when loaded by a launcher or rundll32, first attempts an outbound HTTP GET to www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com. If the domain resolves and returns data, the process terminates immediately. On failure, it installs itself as a fake "Microsoft Security Center (2.0)" service for persistence, then extracts an encrypted ZIP payload from its own .rsrc section and begins SMB scanning on TCP/445 for lateral movement. No anti-debug checks in the outer layer; defense is the kill-switch gate and payload encryption. The outer DLL also contains three hardcoded Bitcoin wallet addresses, suggesting this build may have been configured for a specific payment campaign.
Detection Signatures
| ATT&CK Technique | Evidence |
|---|---|
| T1486 — Data Encrypted for Impact | Embedded s.wnry encrypted payload, CryptAcquireContextA ^[strings.txt:227] |
| T1490 — Inhibit System Recovery | Ransom note ZIP contains recovery instructions; known to delete shadow copies in inner payload |
| T1021.002 — SMB/Windows Admin Shares | \\%s\IPC$ ^[strings.txt:642], mssecsvc.exe propagation service ^[strings.txt:74] |
| T1543.003 — Windows Service | CreateServiceA + OpenSCManagerA + Microsoft Security Center (2.0) Service ^[strings.txt:231-232] ^[strings.txt:646] |
| T1071.001 — Web Protocols | Kill-switch check via InternetOpenUrlA ^[strings.txt:247-248] |
| T1588.001 — Malicious Link | Kill-switch domain hardcoded ^[strings.txt:658] |
| T1497.001 — Virtualisation/Sandbox Evasion | Kill-switch domain check acts as circuit-breaker ^[strings.txt:658] |
References
- MITRE ATT&CK: WannaCry (S0367) — https://attack.mitre.org/software/S0367/
- Wiki sibling:
16fdcfbc— WannaCry v2.1 DLL withwff.comkill-switch ^[/intel/analyses/16fdcfbc4c5d2a7d5e2ccfd28e4b99208797c91315390718de532d9bd9e46d20.html] - Wiki sibling:
ad4df92f— WannaCry v2.0 DLL withwea.comkill-switch ^[/intel/analyses/ad4df92f352378948654b371e619072118f8e6eb3550a6d47ced2710ccf438c3.html] - Wiki sibling:
50a9f720— WannaCry v2.1 DLL, distinct hash ^[/intel/analyses/50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c.html] - Wiki: wannacry entity page, kill-switch-domain-check technique page
Provenance
file.txt— file(1) 5.44pefile.txt— pefile 2023.2.7strings.txt— GNU strings 2.40 (7001 lines)binwalk.txt— binwalk v2.3.4rabin2-info.txt— radare2 5.9.4exiftool.json— ExifTool 12.76triage.json— PacketPursuit triage-fast, 2026-05-26yara.txt— YARA 4.5.2ssdeep.txt— ssdeep 2.14.1- Radare2 decompilation — r2mcp, analysis level 2, 209 functions