Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- WannaCry Sample IOCs:
- Referenced in https://youtu.be/d_j8UUQbJsc
- Sample Metadata
- ===============
- MD5: 84c82835a5d21bbcf75a61706d8ab549
- SHA1: 5ff465afaabcbf0150d1a3ab2c2e74f3a4426467
- ssdeep: 98304:QqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2g3x:QqPe1Cxcxk3ZAEUadzR8yc4gB
- .text MD5: 920e964050a1a5dd60dd00083fd541a2
- .rdata MD5: 2c42611802d585e6eed68595876d1a15
- .data MD5: 83506e37bd8b50cacabd480f8eb3849b
- .rsrc MD5: f99ce7dc94308f0a149a19e022e4c316
- Bitcoin Wallet:
- ===============
- 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94
- File System Indicators:
- =======================
- %UserProfile%\Desktop\taskdl.exe [MD5: 4fef5e34143e646dbf9907c4374276f5]
- %UserProfile%\Desktop\taskse.exe [MD5: 8495400f199ac77853c53b5a3f278f3e]
- %UserProfile%\Desktop\b.wnry [MD5: c17170262312f3be7027bc2ca825bf0c]
- %UserProfile%\Desktop\c.wnry [MD5: 6395e8b6865c296d756a8d30bd6924e7]
- %UserProfile%\Desktop\r.wnry [MD5: 3e0020fc529b1c2a061016dd2469ba96]
- %UserProfile%\Desktop\s.wnry [MD5: ad4c9de7c8c40813f200ba1c2fa33083]
- %UserProfile%\Desktop\t.wnry [MD5: 5dcaac857e695a65f5c3ef1441a73a8f]
- %UserProfile%\Desktop\u.wnry [MD5: 7bf2b57f2a205768755c07f238fb32cc]
- %UserProfile%\Desktop\00000000.pky [MD5: e14fd58eacc813d4f19f09ad03a06bfb]
- %UserProfile%\Desktop\00000000.eky [MD5: 95f55e7994eaea478f68f4c6b8fc3f40]
- %UserProfile%\Desktop\00000000.res [MD5: 296531a0a234e73bb7beb6893e99f1af]
- %UserProfile%\Desktop\@WanaDecryptor@.exe [MD5: 7bf2b57f2a205768755c07f238fb32cc]
- %UserProfile%\Desktop\msg\m_bulgarian.wnry [MD5: 95673b0f968c0f55b32204361940d184]
- %UserProfile%\Desktop\msg\m_chinese (simplified).wnry [MD5: 0252d45ca21c8e43c9742285c48e91ad]
- %UserProfile%\Desktop\msg\m_chinese (traditional).wnry [MD5: 2efc3690d67cd073a9406a25005f7cea]
- %UserProfile%\Desktop\msg\m_croatian.wnry [MD5: 17194003fa70ce477326ce2f6deeb270]
- %UserProfile%\Desktop\msg\m_czech.wnry [MD5: 537efeecdfa94cc421e58fd82a58ba9e]
- %UserProfile%\Desktop\msg\m_danish.wnry [MD5: 2c5a3b81d5c4715b7bea01033367fcb5]
- %UserProfile%\Desktop\msg\m_dutch.wnry [MD5: 7a8d499407c6a647c03c4471a67eaad7]
- %UserProfile%\Desktop\msg\m_english.wnry [MD5: fe68c2dc0d2419b38f44d83f2fcf232e]
- %UserProfile%\Desktop\msg\m_filipino.wnry [MD5: 08b9e69b57e4c9b966664f8e1c27ab09]
- %UserProfile%\Desktop\msg\m_finnish.wnry [MD5: 35c2f97eea8819b1caebd23fee732d8f]
- %UserProfile%\Desktop\msg\m_french.wnry [MD5: 4e57113a6bf6b88fdd32782a4a381274]
- %UserProfile%\Desktop\msg\m_german.wnry [MD5: 3d59bbb5553fe03a89f817819540f469]
- %UserProfile%\Desktop\msg\m_greek.wnry [MD5: fb4e8718fea95bb7479727fde80cb424]
- %UserProfile%\Desktop\msg\m_indonesian.wnry [MD5: 3788f91c694dfc48e12417ce93356b0f]
- %UserProfile%\Desktop\msg\m_italian.wnry [MD5: 30a200f78498990095b36f574b6e8690]
- %UserProfile%\Desktop\msg\m_japanese.wnry [MD5: b77e1221f7ecd0b5d696cb66cda1609e]
- %UserProfile%\Desktop\msg\m_korean.wnry [MD5: 6735cb43fe44832b061eeb3f5956b099]
- %UserProfile%\Desktop\msg\m_latvian.wnry [MD5: c33afb4ecc04ee1bcc6975bea49abe40]
- %UserProfile%\Desktop\msg\m_norwegian.wnry [MD5: ff70cc7c00951084175d12128ce02399]
- %UserProfile%\Desktop\msg\m_polish.wnry [MD5: e79d7f2833a9c2e2553c7fe04a1b63f4]
- %UserProfile%\Desktop\msg\m_portuguese.wnry [MD5: fa948f7d8dfb21ceddd6794f2d56b44f]
- %UserProfile%\Desktop\msg\m_romanian.wnry [MD5: 313e0ececd24f4fa1504118a11bc7986]
- %UserProfile%\Desktop\msg\m_russian.wnry [MD5: 452615db2336d60af7e2057481e4cab5]
- %UserProfile%\Desktop\msg\m_slovak.wnry [MD5: c911aba4ab1da6c28cf86338ab2ab6cc]
- %UserProfile%\Desktop\msg\m_spanish.wnry [MD5: 8d61648d34cba8ae9d1e2a219019add1]
- %UserProfile%\Desktop\msg\m_swedish.wnry [MD5: c7a19984eb9f37198652eaf2fd1ee25c]
- %UserProfile%\Desktop\msg\m_turkish.wnry [MD5: 531ba6b1a5460fc9446946f91cc8c94b]
- %UserProfile%\Desktop\msg\m_vietnamese.wnry [MD5: 8419be28a0dcec3f55823620922b00fa]
- %UserProfile%\Desktop\@Please_Read_Me@.txt [MD5: 7e6b6da7c61fcb66f3f30166871def5b]
- %UserProfile%\Desktop\TaskData\Tor\libeay32.dll [MD5: 6ed47014c3bb259874d673fb3eaedc85]
- %UserProfile%\Desktop\TaskData\Tor\libevent-2-0-5.dll [MD5: 90f50a285efa5dd9c7fddce786bdef25]
- %UserProfile%\Desktop\TaskData\Tor\libevent_core-2-0-5.dll [MD5: e5df3824f2fcad0c75fd601fcf37ee70]
- %UserProfile%\Desktop\TaskData\Tor\libevent_extra-2-0-5.dll [MD5: 6d6602388ab232ca9e8633462e683739]
- %UserProfile%\Desktop\TaskData\Tor\libgcc_s_sjlj-1.dll [MD5: 73d4823075762ee2837950726baa2af9]
- %UserProfile%\Desktop\TaskData\Tor\libssp-0.dll [MD5: 78581e243e2b41b17452da8d0b5b2a48]
- %UserProfile%\Desktop\TaskData\Tor\ssleay32.dll [MD5: a12c2040f6fddd34e7acb42f18dd6bdc]
- %UserProfile%\Desktop\TaskData\Tor\tor.exe [MD5: fe7eb54691ad6e6af77f8a9a0b6de26d]
- %UserProfile%\Desktop\TaskData\Tor\zlib1.dll [MD5: fb072e9f69afdb57179f59b512f828a4]
- %UserProfile%\Desktop\TaskData\Tor\taskhsvc.exe [MD5: fe7eb54691ad6e6af77f8a9a0b6de26d]
- Registry Activity:
- ==================
- Amongst many other entries:
- [RegSetValue] reg.exe:1768 > HKCU\Software\Microsoft\Windows\CurrentVersion\Run\uelzyfymlxjskv282 = C:\Users\REM\Desktop\tasksche.exe
- [RegDeleteValue] taskhostw.exe:1384 > HKCU\Software\Microsoft\Windows\CurrentVersion\Run\internat.exe
- Network Indicators:
- ===================
- gx7ekbenv2riucmf.onion
- 57g7spgrzlojinas.onion
- xxlvbrloxvriy2c5.onion
- 76jdd2ir2embyv47.onion
- cwwnhwhlz52maqm7.onion
- 104.243.35.196
- 107.170.101.39
- 109.105.109.162
- 120.29.217.46
- 127.192.0.0/10
- 128.199.55.207
- 128.31.0.34
- 128.31.0.39
- 131.188.40.188
- 131.188.40.189
- 134.119.3.164
- 136.243.214.137
- 138.201.130.32
- 144.76.163.93
- 144.76.26.175
- 146.185.177.103
- 148.251.190.229
- 149.56.45.200
- 151.80.42.103
- 154.35.175.225
- 163.172.13.165
- 163.172.131.88
- 163.172.138.22
- 163.172.139.104
- 163.172.149.122
- 163.172.149.155
- 163.172.157.213
- 163.172.176.167
- 163.172.194.53
- 163.172.223.200
- 163.172.25.118
- 163.172.35.247
- 163.172.35.249
- 164.132.77.175
- 167.114.35.28
- 167.114.66.61
- 171.25.193.131
- 171.25.193.77
- 171.25.193.78
- 171.25.193.9
- 173.244.44.53
- 173.255.245.116
- 176.10.104.240
- 176.10.104.243
- 176.126.252.11
- 176.126.252.12
- 178.16.208.56
- 178.16.208.57
- 178.16.208.58
- 178.254.13.126
- 178.254.20.134
- 178.254.44.135
- 178.33.183.251
- 178.62.173.203
- 178.62.197.82
- 178.62.199.226
- 178.62.22.36
- 178.62.60.37
- 178.62.86.96
- 185.100.84.212
- 185.100.85.101
- 185.100.85.61
- 185.100.86.100
- 185.11.180.67
- 185.129.62.62
- 185.13.38.75
- 185.13.39.197
- 185.21.100.50
- 185.35.202.221
- 185.66.250.141
- 185.96.180.29
- 185.97.32.18
- 188.138.112.60
- 188.165.194.195
- 188.166.133.133
- 188.166.23.127
- 188.40.128.246
- 192.160.102.164
- 192.187.124.98
- 192.34.63.137
- 192.42.113.102
- 192.87.28.28
- 192.87.28.82
- 193.11.114.43
- 193.11.114.45
- 193.11.114.46
- 193.11.164.243
- 193.23.244.244
- 193.35.52.53
- 194.109.206.212
- 195.154.122.54
- 195.154.164.243
- 197.231.221.211
- 198.199.64.217
- 198.50.191.95
- 198.96.155.3
- 199.254.238.52
- 199.254.238.53
- 204.11.50.131
- 204.8.156.142
- 212.129.38.254
- 212.129.62.232
- 212.47.229.2
- 212.47.230.49
- 212.47.233.86
- 212.47.237.95
- 212.47.240.10
- 212.47.241.21
- 212.47.244.38
- 212.83.154.33
- 212.83.40.238
- 213.239.217.18
- 213.61.66.116
- 213.61.66.117
- 213.61.66.118
- 217.12.199.208
- 217.79.179.177
- 217.79.190.25
- 31.185.104.20
- 31.31.78.49
- 37.157.195.87
- 37.187.102.186
- 37.187.104.178
- 37.187.22.87
- 37.187.7.74
- 37.218.247.217
- 37.221.162.226
- 37.59.46.159
- 45.62.255.25
- 46.101.151.222
- 46.101.169.151
- 46.101.237.246
- 46.28.110.244
- 46.28.207.141
- 46.28.207.19
- 46.4.111.124
- 5.199.142.236
- 5.34.183.205
- 5.35.251.247
- 5.39.92.199
- 5.9.146.203
- 5.9.151.241
- 5.9.158.75
- 5.9.159.14
- 51.254.101.242
- 51.254.136.195
- 51.254.246.203
- 51.255.41.65
- 52.18.199.239
- 62.102.148.67
- 62.210.124.124
- 62.210.129.246
- 62.210.92.11
- 64.113.32.29
- 66.111.2.20
- 69.162.139.9
- 78.142.142.246
- 78.24.75.53
- 78.47.18.110
- 80.127.137.19
- 81.2.209.10
- 81.30.158.213
- 81.7.10.93
- 81.7.16.182
- 82.223.21.74
- 83.212.99.68
- 85.10.202.87
- 85.214.206.219
- 85.214.62.48
- 85.235.250.88
- 85.248.227.164
- 85.25.159.65
- 86.105.212.130
- 86.59.119.83
- 86.59.119.88
- 86.59.21.38
- 89.163.247.43
- 89.40.71.149
- 91.121.84.137
- 91.219.236.222
- 91.219.237.229
- 91.219.237.244
- 91.229.20.27
- 92.222.20.130
- 92.222.38.67
- 92.222.4.102
- 93.115.97.242
- 93.180.156.84
- 94.23.204.175
- 95.128.43.164
- 95.130.11.147
- 95.130.12.119
- 95.183.48.12
- 97.74.237.196
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement