Ransomware & Wipers • Windows

WannaCry: Cryptographic Teardown & EternalBlue SMB Propagation Mechanics

Deconstruct the WannaCry ransomware architecture, analyzing its EternalBlue SMB propagation worm, kill-switch domain check, and hybrid RSA/AES encryption.

Executive Summary

This report presents an exhaustive static and dynamic reverse engineering analysis of the WannaCry (WanaCrypt0r 2.0) ransomware outbreak. The malware exhibits sophisticated multi-component staging, autonomous worm self-propagation via the EternalBlue (MS17-010 / CVE-2017-0144) SMBv1 exploit, an embedded kill-switch domain validation routine, and hybrid RSA-2048 + AES-128-CBC cryptographic destruction of host files.

Two primary phases were deconstructed:

1.Dropper Component: Self-extracting PE executable responsible for extracting password-protected embedded payloads, creating persistent Windows services (mssecsvc.2.0), and dropping runtime binaries (tasksche.exe).
2.Payload Component (t.wnry / c.wnry): Core cryptographic engine executing the kill-switch pre-flight probe, initializing multi-threaded file system traversals, and enforcing extortion through custom GUI dialogs.

Sample Metadata

Kill Switch Analysis & Validation Logic

The payload executes a pre-flight HTTP probe prior to executing any destructive encryption routines. The hardcoded kill-switch domain is queried via standard WinINet APIs:

C
// Decompiled Kill-Switch Routine (FUN_00401fe7)
HINTERNET hInternet = InternetOpenA("Microsoft Internet Explorer", 0, NULL, NULL, 0);
HINTERNET hConnect = InternetOpenUrlA(hInternet, 
    "http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com", 
    NULL, 0, 0x84000000, 0);

if (hConnect != NULL) {
    InternetCloseHandle(hConnect);
    InternetCloseHandle(hInternet);
    ExitProcess(0); // Kill switch triggered: exit cleanly without encrypting
}

// Kill switch failed or unreachable: PROCEED WITH RANSOMWARE ENCRYPTION
InternetCloseHandle(hInternet);
ExecutePayload();

Marcus Hutchins discovered this unregistered domain in the binary decompilation and registered it for $10.69, inadvertently activating the defensive branch and halting global infections.

Dropper Component Architecture

The initial executable acts as a self-extracting installer executing the following operational flow:

1.Command-Line Verification: Checks argument counts; if executed without parameters, copies itself to C:\Windows\tasksche.exe or %TEMP%\tasksche.exe.
2.Service Installation: Opens the Service Control Manager (OpenSCManagerA) with full access (0xf003f), creating mssecsvc.2.0 configured for automatic startup.
3.Payload Extraction: Locates encrypted resource 0x80a in .rsrc, decrypts and unzips the embedded archive using the hardcoded key WNcry@2ol7.
4.Permissions Configuration: Enforces hidden attributes via attrib +h . and executes icacls . /grant Everyone:F /T /C /Q to prevent local access denial during file traversal.

Cryptographic Operations & File Encryption

WannaCry implements a hybrid cryptosystem utilizing the Windows CryptoAPI:

▪AES-128-CBC: Generates a random session key per file to encrypt data blocks in 1024-byte chunks.
▪RSA-2048: The generated AES session key is encrypted with the attacker public master key and prepended to the file header.
▪File Header Structure: Encrypted files are marked with the magic header WANACRY! followed by the encrypted AES key buffer, file size, and ciphertext payload.
TELEMETRY / DISASSEMBLY
0x000:  57 41 4E 41 43 52 59 21  -> "WANACRY!" Magic Signature
0x008:  [256 Bytes]              -> Encrypted AES Session Key (RSA-2048)
0x108:  [4 Bytes]                -> Unknown / Flags
0x10C:  [4 Bytes]                -> File Attributes
0x110:  [8 Bytes]                -> Original File Size (QWORD)
0x118:  [Variable]               -> Encrypted File Data (AES-128-CBC)

Indicators of Compromise (IOCs)

File Hashes

ComponentTypeHash Value
WannaCry Dropper (Primary)SHA-256\24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c\
WannaCry Dropper (Primary)MD5\db349b97c37d22f5b0d77f038f65037b\
tasksche.exeMD5\84c82835a5d21bbcf75a61706d8ab549\
t.wnry (Payload DLL)MD5\5ff465074be7d9c15d48832e0b4da660\

Network Infrastructure & Domains

Indicator TypeValueRole
Domain\www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com\Hardcoded Kill Switch Domain
Bitcoin Address 1\13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94\Hardcoded Ransom Wallet
Bitcoin Address 2\12t9YDPgwHphJMFjbfR9PXUaknPg48rPmd\Hardcoded Ransom Wallet
Bitcoin Address 3\11513AkHum7dn7TBfA5P4auWgvphtiDtK3\Hardcoded Ransom Wallet

Detection Signatures (YARA)

YARA
rule Ransomware_Win32_WannaCry {
    meta:
        description = "Detects WannaCry ransomware dropper and payload components"
        author = "Chandra Kant Bauri"
        reference = "MARE-TI-2025-WIN25"
        date = "2026-01-15"
        score = 95

    strings:
        $magic = "WANACRY!" ascii
        $pass = "WNcry@2ol7" ascii
        $service = "mssecsvc.2.0" ascii
        $killswitch = "iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com" ascii
        $file1 = "tasksche.exe" ascii wide
        $file2 = "c.wnry" ascii
        $file3 = "t.wnry" ascii

    condition:
        ($magic and ($pass or $killswitch)) or
        (4 of them)
}
Copied