WannaCry
Overview
WannaCry (also known as WannaCrypt, WCry, or Wana Decrypt0r) is a ransomware worm that caused a global outbreak in May 2017. It combines AES-128 file encryption with RSA-2048 key management, SMB-based lateral movement via the EternalBlue exploit (CVE-2017-0144), and a hardcoded kill-switch circuit breaker. The outbreak infected over 200,000 systems across 150 countries within four days.
Build Stack
- Compiler: MSVC 10.0 (Visual Studio 2010) ^[raw/analyses/16fdcfbc/report.md]
- Runtime: MSVCP60.dll + MSVCRT.dll (C++ CRT from Visual C++ 6.0 era)
- Target: PE32+ x64 DLL with console subsystem
- Packing: None on outer DLL; inner payload (
s.wnry) is encrypted inside a password-protected ZIP in.rsrc - Signing: Unsigned
Deploy / TTPs
| TTP | Implementation |
|---|---|
| Kill switch | Hardcoded HTTP GET to www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com; aborts if domain resolves ^[raw/analyses/16fdcfbc/report.md] |
| Persistence | Installs as Windows service: Microsoft Security Center (2.1) Service ^[raw/analyses/16fdcfbc/report.md] |
| Lateral movement | EternalBlue exploit over SMB (TCP/445) to random internal IPs ^[raw/analyses/16fdcfbc/report.md] |
| Encryption | AES-128 per-file keys, encrypted with embedded RSA-2048 public key |
| Ransom note | 27-language notes embedded as encrypted .wnry files inside .rsrc ZIP ^[raw/analyses/16fdcfbc/report.md] |
| Tor C2 | Embedded Tor client (r.wnry) connects to .onion payment portal |
| File deletion | Deletes shadow copies and disables recovery in inner payload |
Variants / Aliases
- WannaCrypt — alternate spelling used in early media coverage
- WCry — shortened form
- Wana Decrypt0r — UI title shown by decryptor
- Version 2.0 — emerged after initial kill-switch domain was sinkholed; removed the kill switch in some builds
Notable Analyses
16fdcfbc— PE32+ x64 DLL with kill-switch (wff.com), service persistence (2.1), and 27-language ransom-note ZIP. Mislabeleddionaeaby OpenCTI. ^[/intel/analyses/16fdcfbc4c5d2a7d5e2ccfd28e4b99208797c91315390718de532d9bd9e46d20.html]ad4df92f— Near-identical sibling: same timestamp, same size, same ZIP payload, but kill-switch domainwea.comand service version2.0. Rapid outbreak re-build. ^[/intel/analyses/ad4df92f352378948654b371e619072118f8e6eb3550a6d47ced2710ccf438c3.html]50a9f720— Third confirmed sibling: same build as16fdcfbc(v2.1,wff.comkill-switch,Microsoft Security Center (2.1) Service). Distinct SHA-256 and ssdeep; not a re-upload. Static-only. ^[/intel/analyses/50a9f720deb53f88edf2f6761f1f82aca0bbde9b98e8abc6f79a3f8390bbe67c.html]b52a8049— Fourth confirmed sibling: v2.0 build (wea.comkill-switch,Microsoft Security Center (2.0) Service), same timestamp and outer size asad4df92f, but larger.rsrcsection (5,304,320 vs 5,124,608 bytes) and distinct ssdeep. Bitcoin wallets visible in outer DLL strings. Static-only. ^[/intel/analyses/b52a8049ef2a2af8acfbfc2fee8613bff13244d6c9e45c96370febf929ed72eb.html]549867cd— Fifth confirmed sibling: v2.1 build (wff.comkill-switch,Microsoft Security Center (2.1) Service), same May 11 2017 timestamp as16fdcfbcand50a9f720. Distinguished by malformed PE header:.rsrcand.relocsections claimSizeOfRawDataexceeding actual file length, producing pefile parsing errors and inflatedSizeOfImage(0x513000 vs actual 0x4C9800). Embedded ZIP payload intact. Static-only. ^[/intel/analyses/549867cd2132dad97e3a87578c7129afe008feae99438f513b853f674fcb16e3.html]541c9bc5— Sixth confirmed sibling: v2.0 build (wea.comkill-switch,Microsoft Security Center (2.0) Service), same timestamp and outer size, but intermediate.rsrcsection size (5,243,392 bytes — between the baseline 5,124,608 andb52a8049's 5,304,320). Bitcoin wallets visible in outer DLL strings. ssdeep blocksize49152matching baseline. Static-only. ^[/intel/analyses/541c9bc518635762bf9c14baec63c2703e3d9887246d3816865c95e2e430bfff.html]
Related Entities / Techniques
- ransomware — parent malware category
- kill-switch-domain-check — the circuit-breaker anti-analysis technique
- EternalBlue SMB propagation — lateral-movement technique (create technique page if observed in 2+ analyses)
Capabilities
- kill-switch-domain-check
- eternalblue-smb-propagation
- windows-service-persistence
- embedded-rsrc-zip-payload
- aes-rsa-hybrid-encryption
- tor-hidden-service-c2
- shadow-copy-deletion
- multilingual-ransom-note