WANACRYPT0R RANSOMWORM
2017-05-16 • Bae Systems •
http://baesystemsai.blogspot.kr/2017/05/wanacrypt0r-ransomworm.html
BAE Systems analyzed WanaCrypt0r as a ransomware worm that spread globally after the ETERNALBLUE SMB exploit became publicly available. The executable checked a hard-coded domain before launching its payload, registered itself as a service, and used worm functionality to replicate across networks, with SMB exposure and MS17-010 exploitation central to the observed spread. The ransomware unpacked embedded resources into a working directory, used a mutex and registry value for execution state, bundled Tor tooling, and selected from three hard-coded Bitcoin wallets for ransom payment. The excerpt says the initial infection vector was still unknown and notes that some phishing claims were linked to a separate Jaff ransomware campaign, making SMB exposure the better-supported propagation path in the text.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9c7c7149387a1c79679a87dd1ba755bc | 2017-05-15 | 2025-02-04 |
| HASH | ac21c8ad899727137c4b94458d7aa8d8 | 2017-05-15 | 2025-02-04 |
| DOMAIN | xxlvbrloxvriy2c5.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | cwwnhwhlz52maqm7.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | gx7ekbenv2riucmf.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | 76jdd2ir2embyv47.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | 57g7spgrzlojinas.onion | 2017-05-12 | 2021-12-02 |
| URL | http://www.iuqerfsodp9ifjaposdf… | 2017-05-16 | 2017-05-23 |