WANACRYPT0R RANSOMWORM

2017-05-16 Bae Systems

http://baesystemsai.blogspot.kr/2017/05/wanacrypt0r-ransomworm.html

Thumbnail for WANACRYPT0R RANSOMWORM

BAE Systems analyzed WanaCrypt0r as a ransomware worm that spread globally after the ETERNALBLUE SMB exploit became publicly available. The executable checked a hard-coded domain before launching its payload, registered itself as a service, and used worm functionality to replicate across networks, with SMB exposure and MS17-010 exploitation central to the observed spread. The ransomware unpacked embedded resources into a working directory, used a mutex and registry value for execution state, bundled Tor tooling, and selected from three hard-coded Bitcoin wallets for ransom payment. The excerpt says the initial infection vector was still unknown and notes that some phishing claims were linked to a separate Jaff ransomware campaign, making SMB exposure the better-supported propagation path in the text.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9c7c7149387a1c79679a87dd1ba755bc 2017-05-15 2025-02-04
HASH ac21c8ad899727137c4b94458d7aa8d8 2017-05-15 2025-02-04
DOMAIN xxlvbrloxvriy2c5.onion 2017-05-12 2021-12-02
DOMAIN cwwnhwhlz52maqm7.onion 2017-05-12 2021-12-02
DOMAIN gx7ekbenv2riucmf.onion 2017-05-12 2021-12-02
DOMAIN 76jdd2ir2embyv47.onion 2017-05-12 2021-12-02
DOMAIN 57g7spgrzlojinas.onion 2017-05-12 2021-12-02
URL http://www.iuqerfsodp9ifjaposdf… 2017-05-16 2017-05-23

Related Reports

« Back