WannaCry ransomware used in widespread attacks all over the world
2017-05-12 • Kaspersky •
https://securelist.com/wannacry-ransomware-used-in-widespread-attacks-all-over-the-world/78351/
WannaCry ransomware spread globally by exploiting SMBv2 remote code execution on unpatched Microsoft Windows systems, using the EternalBlue exploit released in the Shadow Brokers dump. Kaspersky telemetry recorded more than 45,000 attempted infections across 74 countries in the first hours, with affected organizations including Spain-based entities and UK National Health Service medical institutions. The malware encrypted a broad set of office, database, archive, email, developer, certificate, media, and virtual machine files, appended the .WCRY extension, changed the victim wallpaper, and displayed multilingual ransom instructions. Samples used Tor components for command-and-control access and listed Bitcoin wallets for payment, with ransom pressure enforced through countdown timers and price increases. The outbreak highlighted how exposed SMB services and delayed patching could turn a ransomware payload into a fast-moving global incident.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 5bef35496fcbdbe841c82f4d1ab8b7c2 | 2017-05-12 | 2021-12-02 |
| HASH | d6114ba5f10ad67a4131ab72531f02da | 2017-05-12 | 2021-12-02 |
| HASH | 86721e64ffbd69aa6944b9672bcabb6d | 2017-05-12 | 2021-12-02 |
| HASH | db349b97c37d22f5ea1d1841e3c89eb4 | 2017-05-12 | 2021-12-02 |
| HASH | 7f7ccaa16fb15eb1c7399d422f8363e8 | 2017-05-12 | 2021-12-02 |
| HASH | 84c82835a5d21bbcf75a61706d8ab549 | 2017-05-12 | 2021-12-02 |
| DOMAIN | xxlvbrloxvriy2c5.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | cwwnhwhlz52maqm7.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | gx7ekbenv2riucmf.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | 76jdd2ir2embyv47.onion | 2017-05-12 | 2021-12-02 |
| DOMAIN | 57g7spgrzlojinas.onion | 2017-05-12 | 2021-12-02 |
| HASH | 8495400f199ac77853c53b5a3f278f3e | 2017-05-12 | 2017-05-23 |
| HASH | 4fef5e34143e646dbf9907c4374276f5 | 2017-05-12 | 2017-05-23 |
| HASH | 7bf2b57f2a205768755c07f238fb32cc | 2017-05-12 | 2017-05-23 |
| DOMAIN | sqjolphimrr7jqw6.onion | 2017-05-12 | 2017-05-13 |
| HASH | e372d07207b4da75b3434584cd9f3450 | 2017-05-12 | 2017-05-12 |
| HASH | 775a0631fb8229b2aa3d7621427085ad | 2017-05-12 | 2017-05-12 |
| HASH | f529f4556a5126bba499c26d67892240 | 2017-05-12 | 2017-05-12 |
| HASH | 8dd63adb68ef053e044a5a2f46e0d2cd | 2017-05-12 | 2017-05-12 |
| HASH | b0ad5902366f860f85b892867e5b1e87 | 2017-05-12 | 2017-05-12 |