typeanalysisfamilywannacryconfidencehighcreated2026-08-07updated2026-08-07malware-familyransomwareimpactc2lateral-movementpersistencepeevasion
SHA-256: b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb

wannacry: b52a8049 — Fourth confirmed WannaCry sibling, v2.0 build, kill-switch wea.com, oversized .rsrc

Executive Summary

A PE32+ x64 DLL compiled 11 May 2017, mislabeled dionaea by OpenCTI but confirmed as a wannacry outbreak sibling. It shares the v2.0 kill-switch domain (wea.com) and service name (2.0) with the previously-analysed ad4df92f sibling, but is not byte-identical: a larger .rsrc section (5,304,320 vs 5,124,608 bytes), a distinct ssdeep hash, and a divergent ZIP payload layout mark it as a fourth confirmed distinct file in the wild. Static-only analysis; no CAPE Windows guest available.

What It Is

Field Value
SHA-256 b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb
File type PE32+ executable (DLL) (console) x86-64, 6 sections ^[file.txt]
Size 5,298,176 bytes (5.3 MB) ^[exiftool.json]
Compilation 2017-05-11 12:20:57 UTC (TimeDateStamp 0x59145729) ^[pefile.txt:38]
Linker MSVC 10.0 (Visual Studio 2010) ^[exiftool.json:18]
Runtime MSVCP60.dll + MSVCRT.dll (C++ CRT) ^[strings.txt:242]
Signed No ^[rabin2-info.txt]
Family wannacry — high confidence; OpenCTI label dionaea is false positive

The binary is a DLL with console subsystem (Subsystem: 0x3) ^[pefile.txt:69], intended to be loaded by a launcher or run via rundll32. Export table shows launcher.dll / PlayGame masquerade strings ^[strings.txt:177-178] — a known WannaCry launcher artifact.

How It Works

Kill-Switch Gate (Version 2.0)

The kill-switch domain is http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com ^[strings.txt:658]. This matches the ad4df92f v2.0 sibling and differs from the 16fdcfbc/50a9f720 v2.1 siblings only in the TLD suffix (wea.com vs wff.com). Same InternetOpenUrlA → InternetOpenA WinInet call chain ^[strings.txt:247-248], same circuit-breaker behavior: if the domain resolves and returns data, the payload exits without encryption. See kill-switch-domain-check for the technique deep-dive.

Service Persistence (Version 2.0)

The DLL installs itself as a Windows service named Microsoft Security Center (2.0) Service ^[strings.txt:646] using OpenSCManagerA → CreateServiceA → StartServiceCtrlDispatcherA ^[strings.txt:231-232] ^[strings.txt:236]. The local service binary is referenced as mssecsvc.exe ^[strings.txt:74] ^[strings.txt:297] ^[strings.txt:371] and mssecsvc2.0 ^[strings.txt:645].

SMB Propagation

Identical to other siblings: \\%s\IPC$ ^[strings.txt:642] share path for EternalBlue exploitation, WS2_32.dll socket APIs ^[strings.txt:239] ^[strings.txt:799], iphlpapi.dll for network enumeration ^[strings.txt:245]. The actual exploit payload is embedded inside the encrypted s.wnry resource and not visible statically.

Embedded Resource Payload

The .rsrc section is 5,304,320 bytes — larger than the 5,124,608 bytes observed in ad4df92f — and contains a password-protected ZIP archive with the same family of contents ^[binwalk.txt]:

  • b.wnry — encrypted launcher/binary (1,440,054 bytes uncompressed)
  • c.wnry — encrypted configuration (780 bytes)
  • msg/m_*.wnry — 27 ransom-note translations (Bulgarian, Chinese Simplified/Traditional, Croatian, Czech, Danish, Dutch, English, Filipino, Finnish, French, German, Greek, Indonesian, Italian, Japanese, Korean, Latvian, Norwegian, Polish, Portuguese, Romanian, Russian, Slovak, Spanish, Swedish, Turkish, Vietnamese) ^[strings.txt:936+]
  • r.wnry — encrypted Tor client (864 bytes)
  • s.wnry — encrypted main payload (~3,038,286 bytes uncompressed)

The ZIP is encrypted with ZIP 2.0 password protection. The outer DLL decrypts and extracts these at runtime via FindResourceA / LoadResource / LockResource / SizeofResource ^[strings.txt:109-113].

Cryptography

Key generation uses the Microsoft Base Cryptographic Provider:

  • CryptAcquireContextA + CryptGenRandom ^[strings.txt:227] ^[strings.txt:865] for RNG
  • The ransomware uses RSA-2048 (per public literature) to encrypt per-file AES-128 keys

Decompiled Behavior

Radare2 analysis (level 2, 209 functions) shows the same entry-point layout as the other siblings:

  • entry0 at 0x1800015ec — DLL entry point with DllMain reason-code dispatch ^[rabin2-info.txt]
  • Service control dispatcher path (persistence)
  • Payload execution path (encryption)

The decompiled entry point is standard MSVC CRT-initialised with SEH frames, FLS/TLS setup, and no anti-debug or VM checks in the outer layer. No notable function deltas from ad4df92f or 16fdcfbc.

C2 Infrastructure

Type Indicator Notes
Kill-switch domain www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com Hardcoded; if reachable, encryption aborts ^[strings.txt:658]
SMB lateral \\%s\IPC$ EternalBlue propagation to random internal IPs ^[strings.txt:642]
Service name Microsoft Security Center (2.0) Service Fake service for persistence ^[strings.txt:646]
Bitcoin wallets 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn, 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw, 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 Hardcoded payment addresses ^[strings.txt:867-869]

No hardcoded IP addresses or email addresses visible in the outer DLL. The Tor C2 .onion address lives inside the encrypted r.wnry resource and is not statically recoverable.

Sibling Correlation

Attribute 16fdcfbc (v2.1) 50a9f720 (v2.1) ad4df92f (v2.0) b52a8049 (v2.0)
Size 5,298,176 5,298,176 5,298,176 5,298,176
.rsrc size 5,124,608 5,124,608 5,124,608 5,304,320
Kill-switch TLD wff.com wff.com wea.com wea.com
Service version 2.1 2.1 2.0 2.0
mssecsvc ref mssecsvr.exe / 2.1 mssecsvr.exe / 2.1 mssecsvc.exe / 2.0 mssecsvc.exe / 2.0
ssdeep 49152:… 49152:… 49152:… 98304:… (blocksize doubled)

The .rsrc size delta (~180 KB larger) and the ssdeep blocksize doubling suggest this build used a different ZIP compression level or embedded a slightly different inner payload, even though the outer compilation timestamp is identical. This is consistent with a builder pipeline that compiled the launcher DLL once and then varied the embedded resource ZIP.

Interesting Tidbits

  • OpenCTI mislabel: Tagged dionaea and exe ^[triage.json] — it is neither a Dionaea honeypot artifact nor an EXE; it is a DLL and it is WannaCry.
  • Bitcoin wallets present in outer DLL: Unlike 16fdcfbc and ad4df92f, this sample has the three hardcoded BTC wallets visible in the outer DLL strings ^[strings.txt:867-869]. In the other siblings these wallets are only inside the encrypted ransom-note resources. This may indicate a build-stage difference or simply that the wallets were also present in those binaries but in a different string encoding.
  • YARA generic only: Fires PE_File_Generic and Suspicious_Crypto_Imports ^[yara.txt] — no WannaCry-specific YARA rule hit. The family attribution relies on string forensics and corpus correlation.
  • capa/floss failures: Both capa.txt and floss.txt are error stubs ^[capa.txt] ^[floss.txt] — the tooling failed on this sample, reinforcing the importance of manual string analysis.
  • Same timestamp, different hash: All four siblings carry TimeDateStamp 0x59145729 (2017-05-11 12:20:57 UTC) but have different SHA-256s and ssdeeps. This is consistent with link-time stamping across multiple compiles from the same source tree.

Deployable Signatures

YARA Rule

rule WannaCry_v20_DLL_b52a8049 {
    meta:
        description = "WannaCry v2.0 DLL variant with wea.com kill-switch and outer-DLL bitcoin wallets"
        author = "PacketPursuit SOC"
        date = "2026-08-07"
        sha256 = "b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb"
    strings:
        $kill = "www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com" ascii wide
        $svc  = "Microsoft Security Center (2.0) Service" ascii wide
        $msse = "mssecsvc.exe" ascii wide
        $msse2 = "mssecsvc2.0" ascii wide
        $task = "tasksche.exe" ascii wide
        $wnry = ".wnry" ascii wide
        $ipc  = "\\%s\\IPC$" ascii wide
        $btc1 = "115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn" ascii wide
        $btc2 = "12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw" ascii wide
        $btc3 = "13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x4550 and
        4 of them
}

Sigma Rule

title: WannaCry v2.0 Service Installation (b52a8049 variant)
detection:
    selection:
        EventID: 7045
        ServiceName: 'Microsoft Security Center (2.0) Service'
    condition: selection

IOC List

Category Value
SHA-256 b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb
MD5 040ed1613a8aa0d8caf59474ec94022e
ssdeep 98304:D9zqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2H:D9zqPe1Cxcxk3ZAEUadzR8yc4H
Kill-switch domain www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
Service name Microsoft Security Center (2.0) Service
File names mssecsvc.exe, mssecsvc2.0, tasksche.exe
SMB indicator \\%s\IPC$
Bitcoin wallets 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn, 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw, 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94

Behavioral Fingerprint

This DLL, when loaded by a launcher or rundll32, first attempts an outbound HTTP GET to www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com. If the domain resolves and returns data, the process terminates immediately. On failure, it installs itself as a fake "Microsoft Security Center (2.0)" service for persistence, then extracts an encrypted ZIP payload from its own .rsrc section and begins SMB scanning on TCP/445 for lateral movement. No anti-debug checks in the outer layer; defense is the kill-switch gate and payload encryption. The outer DLL also contains three hardcoded Bitcoin wallet addresses, suggesting this build may have been configured for a specific payment campaign.

Detection Signatures

ATT&CK Technique Evidence
T1486 — Data Encrypted for Impact Embedded s.wnry encrypted payload, CryptAcquireContextA ^[strings.txt:227]
T1490 — Inhibit System Recovery Ransom note ZIP contains recovery instructions; known to delete shadow copies in inner payload
T1021.002 — SMB/Windows Admin Shares \\%s\IPC$ ^[strings.txt:642], mssecsvc.exe propagation service ^[strings.txt:74]
T1543.003 — Windows Service CreateServiceA + OpenSCManagerA + Microsoft Security Center (2.0) Service ^[strings.txt:231-232] ^[strings.txt:646]
T1071.001 — Web Protocols Kill-switch check via InternetOpenUrlA ^[strings.txt:247-248]
T1588.001 — Malicious Link Kill-switch domain hardcoded ^[strings.txt:658]
T1497.001 — Virtualisation/Sandbox Evasion Kill-switch domain check acts as circuit-breaker ^[strings.txt:658]

References

  • MITRE ATT&CK: WannaCry (S0367) — https://attack.mitre.org/software/S0367/
  • Wiki sibling: 16fdcfbc — WannaCry v2.1 DLL with wff.com kill-switch ^[/intel/analyses/16fdcfbc4c5d2a7d5e2ccfd28e4b99208797c91315390718de532d9bd9e46d20.html]
  • Wiki sibling: ad4df92f — WannaCry v2.0 DLL with wea.com kill-switch ^[/intel/analyses/ad4df92f352378948654b371e619072118f8e6eb3550a6d47ced2710ccf438c3.html]
  • Wiki sibling: 50a9f720 — WannaCry v2.1 DLL, distinct hash ^[/intel/analyses/50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c.html]
  • Wiki: wannacry entity page, kill-switch-domain-check technique page

Provenance

  • file.txt — file(1) 5.44
  • pefile.txt — pefile 2023.2.7
  • strings.txt — GNU strings 2.40 (7001 lines)
  • binwalk.txt — binwalk v2.3.4
  • rabin2-info.txt — radare2 5.9.4
  • exiftool.json — ExifTool 12.76
  • triage.json — PacketPursuit triage-fast, 2026-05-26
  • yara.txt — YARA 4.5.2
  • ssdeep.txt — ssdeep 2.14.1
  • Radare2 decompilation — r2mcp, analysis level 2, 209 functions