typeentityconfidencehighcreated2026-06-10updated2026-08-15malware-familyransomwareimpactlateral-movementc2

WannaCry

Overview

WannaCry (also known as WannaCrypt, WCry, or Wana Decrypt0r) is a ransomware worm that caused a global outbreak in May 2017. It combines AES-128 file encryption with RSA-2048 key management, SMB-based lateral movement via the EternalBlue exploit (CVE-2017-0144), and a hardcoded kill-switch circuit breaker. The outbreak infected over 200,000 systems across 150 countries within four days.

Build Stack

  • Compiler: MSVC 10.0 (Visual Studio 2010) ^[raw/analyses/16fdcfbc/report.md]
  • Runtime: MSVCP60.dll + MSVCRT.dll (C++ CRT from Visual C++ 6.0 era)
  • Target: PE32+ x64 DLL with console subsystem
  • Packing: None on outer DLL; inner payload (s.wnry) is encrypted inside a password-protected ZIP in .rsrc
  • Signing: Unsigned

Deploy / TTPs

TTP Implementation
Kill switch Hardcoded HTTP GET to www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com; aborts if domain resolves ^[raw/analyses/16fdcfbc/report.md]
Persistence Installs as Windows service: Microsoft Security Center (2.1) Service ^[raw/analyses/16fdcfbc/report.md]
Lateral movement EternalBlue exploit over SMB (TCP/445) to random internal IPs ^[raw/analyses/16fdcfbc/report.md]
Encryption AES-128 per-file keys, encrypted with embedded RSA-2048 public key
Ransom note 27-language notes embedded as encrypted .wnry files inside .rsrc ZIP ^[raw/analyses/16fdcfbc/report.md]
Tor C2 Embedded Tor client (r.wnry) connects to .onion payment portal
File deletion Deletes shadow copies and disables recovery in inner payload

Variants / Aliases

  • WannaCrypt — alternate spelling used in early media coverage
  • WCry — shortened form
  • Wana Decrypt0r — UI title shown by decryptor
  • Version 2.0 — emerged after initial kill-switch domain was sinkholed; removed the kill switch in some builds

Notable Analyses

  • 16fdcfbc — PE32+ x64 DLL with kill-switch (wff.com), service persistence (2.1), and 27-language ransom-note ZIP. Mislabeled dionaea by OpenCTI. ^[/intel/analyses/16fdcfbc4c5d2a7d5e2ccfd28e4b99208797c91315390718de532d9bd9e46d20.html]
  • ad4df92f — Near-identical sibling: same timestamp, same size, same ZIP payload, but kill-switch domain wea.com and service version 2.0. Rapid outbreak re-build. ^[/intel/analyses/ad4df92f352378948654b371e619072118f8e6eb3550a6d47ced2710ccf438c3.html]
  • 50a9f720 — Third confirmed sibling: same build as 16fdcfbc (v2.1, wff.com kill-switch, Microsoft Security Center (2.1) Service). Distinct SHA-256 and ssdeep; not a re-upload. Static-only. ^[/intel/analyses/50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c.html]
  • b52a8049 — Fourth confirmed sibling: v2.0 build (wea.com kill-switch, Microsoft Security Center (2.0) Service), same timestamp and outer size as ad4df92f, but larger .rsrc section (5,304,320 vs 5,124,608 bytes) and distinct ssdeep. Bitcoin wallets visible in outer DLL strings. Static-only. ^[/intel/analyses/b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb.html]
  • 549867cd — Fifth confirmed sibling: v2.1 build (wff.com kill-switch, Microsoft Security Center (2.1) Service), same May 11 2017 timestamp as 16fdcfbc and 50a9f720. Distinguished by malformed PE header: .rsrc and .reloc sections claim SizeOfRawData exceeding actual file length, producing pefile parsing errors and inflated SizeOfImage (0x513000 vs actual 0x4C9800). Embedded ZIP payload intact. Static-only. ^[/intel/analyses/549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3.html]
  • 541c9bc5 — Sixth confirmed sibling: v2.0 build (wea.com kill-switch, Microsoft Security Center (2.0) Service), same timestamp and outer size, but intermediate .rsrc section size (5,243,392 bytes — between the baseline 5,124,608 and b52a8049's 5,304,320). Bitcoin wallets visible in outer DLL strings. ssdeep blocksize 49152 matching baseline. Static-only. ^[/intel/analyses/541c9bc518635762bf9c14baec63c2703e3d9887246d3816865c95e2e430bfff.html]

Related Entities / Techniques

  • ransomware — parent malware category
  • kill-switch-domain-check — the circuit-breaker anti-analysis technique
  • EternalBlue SMB propagation — lateral-movement technique (create technique page if observed in 2+ analyses)

Capabilities

  • kill-switch-domain-check
  • eternalblue-smb-propagation
  • windows-service-persistence
  • embedded-rsrc-zip-payload
  • aes-rsa-hybrid-encryption
  • tor-hidden-service-c2
  • shadow-copy-deletion
  • multilingual-ransom-note