Falcon Report: CrowdStrike Falcon Prevents the Attack
2017-05-12 • Crowd Strike •
CrowdStrike details the WannaCry/Wanna ransomware variant that spread widely in May 2017 by abusing the EternalBlue SMB vulnerability after initial infection. The malware encrypts 177 file types, appends .wncry, continues encrypting renamed or newly created files, and presents ransom notes with demands of $300 or $600 in Bitcoin. The excerpt describes service-based installation under ProgramData, execution through tasksche.exe, an SMB exploitation component gated by a kill-switch domain check, and Tor-based command-and-control used for ransom payment flows. It also lists observed Bitcoin wallets and notes AES/RSA-based encryption, giving defenders concrete behaviors and artifacts for detection and prevention.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | xxlvbrloxvriy2c5.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | cwwnhwhlz52maqm7.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | gx7ekbenv2riucmf.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | 76jdd2ir2embyv47.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | 57g7spgrzlojinas.onion | 2017-05-12 | 2021-12-02 |