WannaCry Malware Profile

2017-05-23 Fireeye

https://www.fireeye.com/blog/threat-research/2017/05/wannacry-malware-profile.html

Thumbnail for WannaCry Malware Profile

FireEye describes WannaCry, also called WCry or WanaCryptor, as a self-propagating ransomware family that spread internally and across the internet by exploiting the MS17-010 SMB vulnerability with EternalBlue. The malware combined a ransomware component with a propagation component, encrypted files with the .WCRY extension, dropped a decryptor, demanded Bitcoin payment, and used encrypted Tor channels for command-and-control. Persistence artifacts included Run keys and services such as mssecsvc.exe and tasksche.exe, while destructive recovery-inhibition commands deleted shadow copies and backup catalogs. Its spreader enumerated local subnets, attempted connections to port 445, and launched exploitation threads against reachable SMB services, with a kill-switch domain determining whether installation and encryption continued.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN iuqerfsodp9ifjaposdfjhgosurijfa… 2017-05-12 2023-01-17
HASH db349b97c37d22f5ea1d1841e3c89eb4 2017-05-12 2021-12-02
HASH 84c82835a5d21bbcf75a61706d8ab549 2017-05-12 2021-12-02
DOMAIN xxlvbrloxvriy2c5.onion 2017-05-12 2021-12-02
DOMAIN cwwnhwhlz52maqm7.onion 2017-05-12 2021-12-02
DOMAIN gx7ekbenv2riucmf.onion 2017-05-12 2021-12-02
DOMAIN 76jdd2ir2embyv47.onion 2017-05-12 2021-12-02
DOMAIN 57g7spgrzlojinas.onion 2017-05-12 2021-12-02
HASH ae08f79a0d800b82fcbe1b43cdbdbefc 2017-05-23 2017-05-23
HASH 08b9e69b57e4c9b966664f8e1c27ab09 2017-05-23 2017-05-23
HASH fa948f7d8dfb21ceddd6794f2d56b44f 2017-05-23 2017-05-23
HASH 537efeecdfa94cc421e58fd82a58ba9e 2017-05-23 2017-05-23
HASH c2559b51cfd37bdbd5fdb978061c6c16 2017-05-23 2017-05-23
HASH c911aba4ab1da6c28cf86338ab2ab6cc 2017-05-23 2017-05-23
HASH 4e57113a6bf6b88fdd32782a4a381274 2017-05-23 2017-05-23
HASH 531ba6b1a5460fc9446946f91cc8c94b 2017-05-23 2017-05-23
HASH 8d61648d34cba8ae9d1e2a219019add1 2017-05-23 2017-05-23
HASH 3d59bbb5553fe03a89f817819540f469 2017-05-23 2017-05-23
HASH ad4c9de7c8c40813f200ba1c2fa33083 2017-05-23 2017-05-23
HASH 6735cb43fe44832b061eeb3f5956b099 2017-05-23 2017-05-23
HASH 35c2f97eea8819b1caebd23fee732d8f 2017-05-23 2017-05-23
HASH 80ce983d22c6213f35867053bec1c293 2017-05-23 2017-05-23
HASH fe68c2dc0d2419b38f44d83f2fcf232e 2017-05-23 2017-05-23
HASH 2efc3690d67cd073a9406a25005f7cea 2017-05-23 2017-05-23
HASH 96dff36b5275c67e35097d77a120d0d4 2017-05-23 2017-05-23
HASH 5dcaac857e695a65f5c3ef1441a73a8f 2017-05-23 2017-05-23
HASH c7a19984eb9f37198652eaf2fd1ee25c 2017-05-23 2017-05-23
HASH f351e1fcca0c4ea05fc44d15a17f8b36 2017-05-23 2017-05-23
HASH 0252d45ca21c8e43c9742285c48e91ad 2017-05-23 2017-05-23
HASH 30a200f78498990095b36f574b6e8690 2017-05-23 2017-05-23
HASH a44964a7be94072cdfe085bc43e7dc95 2017-05-23 2017-05-23
HASH 3e0020fc529b1c2a061016dd2469ba96 2017-05-23 2017-05-23
HASH 3788f91c694dfc48e12417ce93356b0f 2017-05-23 2017-05-23
HASH 313e0ececd24f4fa1504118a11bc7986 2017-05-23 2017-05-23
HASH c33afb4ecc04ee1bcc6975bea49abe40 2017-05-23 2017-05-23
HASH 7a8d499407c6a647c03c4471a67eaad7 2017-05-23 2017-05-23
HASH 2c5a3b81d5c4715b7bea01033367fcb5 2017-05-23 2017-05-23
HASH c17170262312f3be7027bc2ca825bf0c 2017-05-23 2017-05-23
HASH 17194003fa70ce477326ce2f6deeb270 2017-05-23 2017-05-23
HASH fb4e8718fea95bb7479727fde80cb424 2017-05-23 2017-05-23
HASH ff70cc7c00951084175d12128ce02399 2017-05-23 2017-05-23
HASH bee19b98d2e5b12211ce211eecb13de6 2017-05-23 2017-05-23
HASH e79d7f2833a9c2e2553c7fe04a1b63f4 2017-05-23 2017-05-23
HASH 8419be28a0dcec3f55823620922b00fa 2017-05-23 2017-05-23
HASH 95673b0f968c0f55b32204361940d184 2017-05-23 2017-05-23
HASH 452615db2336d60af7e2057481e4cab5 2017-05-23 2017-05-23
HASH b77e1221f7ecd0b5d696cb66cda1609e 2017-05-23 2017-05-23
URL http://www.btcfrog.com/qr/bitco… 2017-05-23 2017-05-23
DOMAIN iuqssfsodp9ifjaposdfjhgosurijfa… 2017-05-23 2017-05-23
DOMAIN ayylmaotjhsstasdfasdfasdfasdfas… 2017-05-23 2017-05-23
URL http://www.iuqerfsodp9ifjaposdf… 2017-05-16 2017-05-23
DOMAIN ifferfsodp9ifjaposdfjhgosurijfa… 2017-05-14 2017-05-23
HASH 8495400f199ac77853c53b5a3f278f3e 2017-05-12 2017-05-23
HASH 4fef5e34143e646dbf9907c4374276f5 2017-05-12 2017-05-23
HASH 7bf2b57f2a205768755c07f238fb32cc 2017-05-12 2017-05-23

Related Reports

« Back