The WannaCry Attack
2025-02-04 • Derek DSouza •
https://medium.com/@dereksaviodsouza/the-wannacry-attack-034eeae3e712
The essay summarizes the 2017 WannaCry ransomware worm, which infected more than 200,000 Windows systems across roughly 150 countries and disrupted organizations including healthcare, transport, and manufacturing. It explains how WannaCry used EternalBlue against SMBv1 and DoublePulsar to spread, then encrypted files with RSA and AES while demanding Bitcoin ransom payments. The source notes U.S. attribution suspicions toward the DPRK-backed Lazarus Group while also stating North Korea denied involvement. It also covers the hard-coded kill-switch domain registered by Marcus Hutchins and the broader risk created by unpatched systems and leaked exploit stockpiles.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://www.thesslstore.com/blo… | 2025-02-04 | 2025-02-04 |
| HASH | 9c7c7149387a1c79679a87dd1ba755bc | 2017-05-15 | 2025-02-04 |
| HASH | ac21c8ad899727137c4b94458d7aa8d8 | 2017-05-15 | 2025-02-04 |