The WannaCry Attack

2025-02-04 Derek DSouza

https://medium.com/@dereksaviodsouza/the-wannacry-attack-034eeae3e712

The essay summarizes the 2017 WannaCry ransomware worm, which infected more than 200,000 Windows systems across roughly 150 countries and disrupted organizations including healthcare, transport, and manufacturing. It explains how WannaCry used EternalBlue against SMBv1 and DoublePulsar to spread, then encrypted files with RSA and AES while demanding Bitcoin ransom payments. The source notes U.S. attribution suspicions toward the DPRK-backed Lazarus Group while also stating North Korea denied involvement. It also covers the hard-coded kill-switch domain registered by Marcus Hutchins and the broader risk created by unpatched systems and leaked exploit stockpiles.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://www.thesslstore.com/blo… 2025-02-04 2025-02-04
HASH 9c7c7149387a1c79679a87dd1ba755bc 2017-05-15 2025-02-04
HASH ac21c8ad899727137c4b94458d7aa8d8 2017-05-15 2025-02-04

Related Reports

« Back