Skip to main content

Boteraser | Website and Server Security Solutions

WannaCry

Malware

⚠️ Overview

WannaCry is a ransomware worm first discovered on May 12, 2017, by security researchers across multiple entities, including MalwareTech. It is attributed to the Lazarus Group (also known as Hidden Cobra), a threat actor linked to North Korea's Reconnaissance General Bureau, and falls under the ransomware category due to its encryption of files for ransom demands in Bitcoin.

🔧 Technical Capabilities

WannaCry propagates via the EternalBlue exploit (MS17-010) targeting a vulnerability in Microsoft's SMBv1 protocol (CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0147) and uses the DoublePulsar backdoor implant for payload delivery. It scans internal and external networks for vulnerable Windows systems, executing as a service (mssecsvc.exe) and encrypting over 170 file types with RSA-2048 and AES-128. The malware includes a kill switch—a hardcoded domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com)—that, when registered, halts propagation; it does not use traditional C2 infrastructure but relies on Tor for a small percentage of ransom communications. Persistence is achieved via registry run keys (HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunmssecsvc) and the Windows Service Control Manager, while evasion techniques include obfuscated strings and checking for sandbox environments by querying system processes.

📜 History & Notable Incidents

WannaCry first appeared on May 12, 2017, in a global attack that infected over 230,000 systems across 150 countries within hours. High-profile victims included the UK's National Health Service (NHS), causing 19,000 cancelled appointments and costing £92 million, as well as FedEx, Deutsche Bahn, and the Spanish telecommunications company Telefónica. Emergency patches were released by Microsoft on May 13, 2017, and a researcher (MalwareTech) inadvertently halted the outbreak by registering the kill switch domain; the attack was formally linked to North Korea by the US, UK, and Australian governments in December 2017.

🔍 Detection Indicators

Known file hashes include SHA-256: ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e82aa and MD5: 84c82835a5d21bbcf75a61706d8ab549. Behavioral signatures include rapid SMBv1 connection attempts (port 445), creation of .WNCRY files with encrypted data, and the presence of @[email protected]. Network IOCs include DNS queries for the kill-switch domain and outbound Tor traffic on ports 9050–9051. Registry mutex names observed include "GlobalMsWinZonesCacheCounterMutexA" and "GlobalSMBMutex" for infection control.

☠️ Risk & Impact

WannaCry encrypted user files and demanded $300–$600 in Bitcoin per machine, with total ransom payments collected exceeding $130,000, though global economic losses were estimated at $4–$8 billion by cybersecurity firms. The attack disproportionately affected healthcare, transportation, and manufacturing sectors, particularly organizations running unpatched Windows 7 and Server 2008 systems, leading to operational shutdowns and data recovery costs exceeding $1.5 billion for the NHS alone.

🛡️ Mitigation

Definitive mitigation requires applying Microsoft security update MS17-010 (labeled as critical) to all Windows systems, disabling SMBv1 via Group Policy or PowerShell (Stop-Service lanmanserver -DisableSMB1), and maintaining offline backups.Detection rules include Sigma signatures for EternalBlue exploitation and YARA rules for WannaCry artifacts; endpoint protection products (e.g., CrowdStrike, SentinelOne) block execution through behavioral analysis of file-encryption processes and SMB exploit payloads.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.