Executive Summary
This report presents an exhaustive static and dynamic reverse engineering analysis of the WannaCry (WanaCrypt0r 2.0) ransomware outbreak. The malware exhibits sophisticated multi-component staging, autonomous worm self-propagation via the EternalBlue (MS17-010 / CVE-2017-0144) SMBv1 exploit, an embedded kill-switch domain validation routine, and hybrid RSA-2048 + AES-128-CBC cryptographic destruction of host files.
Two primary phases were deconstructed:
mssecsvc.2.0), and dropping runtime binaries (tasksche.exe).t.wnry / c.wnry): Core cryptographic engine executing the kill-switch pre-flight probe, initializing multi-threaded file system traversals, and enforcing extortion through custom GUI dialogs.Sample Metadata
| Attribute | Telemetry Value |
|---|---|
| Malware Family | WannaCry / WanaCrypt0r 2.0 (WANACRY!) |
| Classification | Ransomware / Autonomous Network Worm |
| Delivery Vector | EternalBlue SMBv1 Remote Code Execution (MS17-010) |
| Service Name | \mssecsvc.2.0\ (Masquerades as Microsoft Security Service) |
| Dropped Binaries | \tasksche.exe\, \t.wnry\, \c.wnry\, \u.wnry\ |
| Embedded Archive Password | \WNcry@2ol7\ |
| Kill Switch Domain | \www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com\ |
| Sample MD5 | \db349b97c37d22f5b0d77f038f65037b\ |
| Sample SHA-256 | \24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c\ |
| Target File Extensions | 176+ business, database, document, and media formats |
Kill Switch Analysis & Validation Logic
The payload executes a pre-flight HTTP probe prior to executing any destructive encryption routines. The hardcoded kill-switch domain is queried via standard WinINet APIs:
// Decompiled Kill-Switch Routine (FUN_00401fe7)
HINTERNET hInternet = InternetOpenA("Microsoft Internet Explorer", 0, NULL, NULL, 0);
HINTERNET hConnect = InternetOpenUrlA(hInternet,
"http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com",
NULL, 0, 0x84000000, 0);
if (hConnect != NULL) {
InternetCloseHandle(hConnect);
InternetCloseHandle(hInternet);
ExitProcess(0); // Kill switch triggered: exit cleanly without encrypting
}
// Kill switch failed or unreachable: PROCEED WITH RANSOMWARE ENCRYPTION
InternetCloseHandle(hInternet);
ExecutePayload();
Marcus Hutchins discovered this unregistered domain in the binary decompilation and registered it for $10.69, inadvertently activating the defensive branch and halting global infections.
Dropper Component Architecture
The initial executable acts as a self-extracting installer executing the following operational flow:
C:\Windows\tasksche.exe or %TEMP%\tasksche.exe.OpenSCManagerA) with full access (0xf003f), creating mssecsvc.2.0 configured for automatic startup.0x80a in .rsrc, decrypts and unzips the embedded archive using the hardcoded key WNcry@2ol7.attrib +h . and executes icacls . /grant Everyone:F /T /C /Q to prevent local access denial during file traversal.Cryptographic Operations & File Encryption
WannaCry implements a hybrid cryptosystem utilizing the Windows CryptoAPI:
WANACRY! followed by the encrypted AES key buffer, file size, and ciphertext payload.0x000: 57 41 4E 41 43 52 59 21 -> "WANACRY!" Magic Signature
0x008: [256 Bytes] -> Encrypted AES Session Key (RSA-2048)
0x108: [4 Bytes] -> Unknown / Flags
0x10C: [4 Bytes] -> File Attributes
0x110: [8 Bytes] -> Original File Size (QWORD)
0x118: [Variable] -> Encrypted File Data (AES-128-CBC)
Indicators of Compromise (IOCs)
File Hashes
| Component | Type | Hash Value |
|---|---|---|
| WannaCry Dropper (Primary) | SHA-256 | \24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c\ |
| WannaCry Dropper (Primary) | MD5 | \db349b97c37d22f5b0d77f038f65037b\ |
| tasksche.exe | MD5 | \84c82835a5d21bbcf75a61706d8ab549\ |
| t.wnry (Payload DLL) | MD5 | \5ff465074be7d9c15d48832e0b4da660\ |
Network Infrastructure & Domains
| Indicator Type | Value | Role |
|---|---|---|
| Domain | \www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com\ | Hardcoded Kill Switch Domain |
| Bitcoin Address 1 | \13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94\ | Hardcoded Ransom Wallet |
| Bitcoin Address 2 | \12t9YDPgwHphJMFjbfR9PXUaknPg48rPmd\ | Hardcoded Ransom Wallet |
| Bitcoin Address 3 | \11513AkHum7dn7TBfA5P4auWgvphtiDtK3\ | Hardcoded Ransom Wallet |
Detection Signatures (YARA)
rule Ransomware_Win32_WannaCry {
meta:
description = "Detects WannaCry ransomware dropper and payload components"
author = "Chandra Kant Bauri"
reference = "MARE-TI-2025-WIN25"
date = "2026-01-15"
score = 95
strings:
$magic = "WANACRY!" ascii
$pass = "WNcry@2ol7" ascii
$service = "mssecsvc.2.0" ascii
$killswitch = "iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com" ascii
$file1 = "tasksche.exe" ascii wide
$file2 = "c.wnry" ascii
$file3 = "t.wnry" ascii
condition:
($magic and ($pass or $killswitch)) or
(4 of them)
}