Indicators Associated With WannaCry Ransomware

2017-05-12 • USCISA •

https://www.cisa.gov/news-events/alerts/2017/05/12/indicators-associated-wannacry-ransomware

Thumbnail for Indicators Associated With WannaCry Ransomware

The U.S. Government publicly attributed the WannaCry ransomware variant to North Korea, and CISA linked the activity to its broader Hidden Cobra reporting. WannaCry spread globally through the MS17-010/EternalBlue SMBv1 exploit, encrypting files and demanding a bitcoin ransom. US-CERT analysis found that the dropper contacted a hard-coded kill-switch domain, installed itself as the `mssecsvc2.0` service, scanned SMB-related ports, and propagated to systems exposing TCP port 445. CISA urged organizations to patch MS17-010, disable SMBv1 where feasible, segment networks, and maintain tested offline backups.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4186675cb6706f9d51167fb0f14cd3f… 2017-05-12 2021-12-02
DOMAIN www.iuqerfsodp9ifjaposdfjhgosur… 2017-05-12 2017-05-23
URL http://www.iuqerfsodp9ifjaposdf… 2017-05-12 2017-05-23
YARA Wanna_Cry_Ransomware_Generic 2017-05-12 2017-05-12
HASH 4da1f312a214c07143abeeafb695d904 2017-05-12 2017-05-12

Related Reports

« Back