WannaCry
2023-01-17 • Any Run •
WannaCry, sometimes also called WCry or WanaCryptor is ransomware malware, meaning that it encrypts files of its victims and demands a payment to restore the stolen information, usually in bitcoin with ransom amounts ranging from $300 to $600 equivalents. A fix of the EternalBlue exploit along with the discovery of the “kill switch” that allowed to stop the execution of the malware were the two main contributions that helped to slow down this malicious campaign. To do so, the ransomware scans all machines with port 445 being open and if the connection is made, tries to exploit the SMBv1 vulnerability (EternalBlue). Those attacks were carried out by a so-called Lazarus Group, members of which were linked to North Korea.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | fferfsodp9ifjaposdfjhgosurijfae… | 2023-01-17 | 2023-01-17 |
| DOMAIN | iuqerfsodp9ifjaposdfjhgosurijfa… | 2017-05-12 | 2023-01-17 |