Falcon Report: CrowdStrike Falcon Prevents the Attack

2017-05-12 Crowd Strike

https://www.crowdstrike.com/blog/falcon-intelligence-report-wanna-ransomware-spreads-rapidly-continually-encrypts-victim-files/

Thumbnail for Falcon Report: CrowdStrike Falcon Prevents the Attack

CrowdStrike details the WannaCry/Wanna ransomware variant that spread widely in May 2017 by abusing the EternalBlue SMB vulnerability after initial infection. The malware encrypts 177 file types, appends .wncry, continues encrypting renamed or newly created files, and presents ransom notes with demands of $300 or $600 in Bitcoin. The excerpt describes service-based installation under ProgramData, execution through tasksche.exe, an SMB exploitation component gated by a kill-switch domain check, and Tor-based command-and-control used for ransom payment flows. It also lists observed Bitcoin wallets and notes AES/RSA-based encryption, giving defenders concrete behaviors and artifacts for detection and prevention.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN xxlvbrloxvriy2c5.onion 2017-05-12 2021-12-02
DOMAIN cwwnhwhlz52maqm7.onion 2017-05-12 2021-12-02
DOMAIN gx7ekbenv2riucmf.onion 2017-05-12 2021-12-02
DOMAIN 76jdd2ir2embyv47.onion 2017-05-12 2021-12-02
DOMAIN 57g7spgrzlojinas.onion 2017-05-12 2021-12-02

Related Reports

« Back