WannaCry ransomware used in widespread attacks all over the world

2017-05-12 Kaspersky

https://securelist.com/wannacry-ransomware-used-in-widespread-attacks-all-over-the-world/78351/

Thumbnail for WannaCry ransomware used in widespread attacks all over the world

WannaCry ransomware spread globally by exploiting SMBv2 remote code execution on unpatched Microsoft Windows systems, using the EternalBlue exploit released in the Shadow Brokers dump. Kaspersky telemetry recorded more than 45,000 attempted infections across 74 countries in the first hours, with affected organizations including Spain-based entities and UK National Health Service medical institutions. The malware encrypted a broad set of office, database, archive, email, developer, certificate, media, and virtual machine files, appended the .WCRY extension, changed the victim wallpaper, and displayed multilingual ransom instructions. Samples used Tor components for command-and-control access and listed Bitcoin wallets for payment, with ransom pressure enforced through countdown timers and price increases. The outbreak highlighted how exposed SMB services and delayed patching could turn a ransomware payload into a fast-moving global incident.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5bef35496fcbdbe841c82f4d1ab8b7c2 2017-05-12 2021-12-02
HASH d6114ba5f10ad67a4131ab72531f02da 2017-05-12 2021-12-02
HASH 86721e64ffbd69aa6944b9672bcabb6d 2017-05-12 2021-12-02
HASH db349b97c37d22f5ea1d1841e3c89eb4 2017-05-12 2021-12-02
HASH 7f7ccaa16fb15eb1c7399d422f8363e8 2017-05-12 2021-12-02
HASH 84c82835a5d21bbcf75a61706d8ab549 2017-05-12 2021-12-02
DOMAIN xxlvbrloxvriy2c5.onion 2017-05-12 2021-12-02
DOMAIN cwwnhwhlz52maqm7.onion 2017-05-12 2021-12-02
DOMAIN gx7ekbenv2riucmf.onion 2017-05-12 2021-12-02
DOMAIN 76jdd2ir2embyv47.onion 2017-05-12 2021-12-02
DOMAIN 57g7spgrzlojinas.onion 2017-05-12 2021-12-02
HASH 8495400f199ac77853c53b5a3f278f3e 2017-05-12 2017-05-23
HASH 4fef5e34143e646dbf9907c4374276f5 2017-05-12 2017-05-23
HASH 7bf2b57f2a205768755c07f238fb32cc 2017-05-12 2017-05-23
DOMAIN sqjolphimrr7jqw6.onion 2017-05-12 2017-05-13
HASH e372d07207b4da75b3434584cd9f3450 2017-05-12 2017-05-12
HASH 775a0631fb8229b2aa3d7621427085ad 2017-05-12 2017-05-12
HASH f529f4556a5126bba499c26d67892240 2017-05-12 2017-05-12
HASH 8dd63adb68ef053e044a5a2f46e0d2cd 2017-05-12 2017-05-12
HASH b0ad5902366f860f85b892867e5b1e87 2017-05-12 2017-05-12

Related Reports

« Back