WannaCry in the Wild: Intercepting a DoublePulsar Injection & Launcher.dll Payload
Overview
Nearly a decade after its historic global outbreak in May 2017, the automated scanning and exploitation apparatus behind WannaCry (WanaCrypt0r 2.0) remains an active fixture of the IPv4 background noise. Threat actors and automated worm bots continue spraying vulnerable endpoints with NSA-leaked EternalBlue (MS17-010) exploits and DoublePulsar kernel backdoor payloads.
On September 28, 2026 at 08:33 UTC, Malware on Tap's honeypot sensor(s) intercepted an active exploitation sequence originating from Brazil (186.193.28.12). The sensor's SMB emulation engine captured 2,584 frames of raw SMBv1 traffic, assembling a 5.02 MB PE32 DLL payload (launcher.dll, SHA256: ec481093436e1c5a03aaed1a4bc70b6aff99a75e6b1757fb19ec2a676fab0155).
WannaCry / DoublePulsar Opportunistic SMB Spreader
An opportunistic SMBv1 reconnaissance and exploitation sequence attempting in-memory DoublePulsar backdoor injection to deliver the WannaCry launcher.dll payload onto port 445/TCP.
launcher.dll (5,267,459 bytes)Attack Progression & Protocol Analysis
The attacker bot orchestrated a sequential multi-stage probe across five discrete TCP connections before initiating payload transfer:
1. SMB Dialect Negotiation & Session Setup
The client advertises standard legacy dialects (PC NETWORK PROGRAM 1.0, LANMAN1.0, Windows for Workgroups 3.1a, NT LM 0.12). Connection 10010 completes anonymous authentication and establishes session state without credentials.
2. DoublePulsar Verification (MID 0xfeff)
Rather than reinjecting raw kernel shellcode via buffer overflow, the bot tests whether a DoublePulsar ring-0 hook is already present by sending a crafted SMB_COM_TRANSACTION2 request with MultiplexID = 0xfeff.
3. High-Throughput Payload Ingestion
Upon receiving affirmative responses from the SMB emulator, Connection 10016 transfers 2,584 consecutive frames spanning 10.59 MB of raw bistream data, decodes the incoming chunks and flushes the completed binary to disk.
Phase: In-Memory Dropper InjectionBinary Deep Dive: launcher.dll
Static dissection of the dropped binary (afc8cc2c81345acf3a1f4add32c460bf) confirms that it is the canonical 32-bit launcher.dll component designed to bootstrap the core ransomware encryptor (tasksche.exe).
PE Header & Export Characteristics
Parsing the portable executable headers reveals strict alignment with the original May 2017 outbreak binaries:
PE Format: PE32 (x86 32-bit Dynamic Link Library)
Compilation Timestamp: 1494505297 (Thu, 11 May 2017 12:21:37 UTC)
Image Base: 0x10000000
Entry Point: 0x11e9
Export Table: launcher.dll (1 exported function)
Ordinal 1: PlayGame (RVA 0x1114)
The exported symbol PlayGame is the signature entry point executed by DoublePulsar's user-mode APC injector or via command-line execution:
rundll32.exe launcher.dll,PlayGame
Section Breakdown & Embedded Resource .rsrc
The section table demonstrates an extraordinarily bloated resource section comprising 99.5% of the entire binary footprint:
| Section | Virtual Size | Virtual RVA | Raw Data Size | Characteristics / Role |
|---|---|---|---|---|
.text | 0x28c | 0x1000 | 4,096 bytes | Minimal loader code (PlayGame subroutine) |
.rdata | 0x1d8 | 0x2000 | 4,096 bytes | Read-only data & export descriptor |
.data | 0x154 | 0x3000 | 4,096 bytes | Global state variables |
.rsrc | 0x500060 | 0x4000 | 5,246,976 bytes | Encrypted ZIP container with WannaCry assets |
.reloc | 0x2ac | 0x505000 | 4,096 bytes | Relocation delta table |
Embedded Archive Extraction & Decryption Password
Located at byte offset 0x3c6d6 within the .rsrc section is the PK ZIP file header (PK\x03\x04). At offset 0x45634, the binary contains the hardcoded password string used to decompress the bundled assets:
WNcry@2ol7
Upon invocation of PlayGame, launcher.dll unpacks this internal ZIP archive, dropping the primary decryptor UI (tasksche.exe), helper utilities (taskse.exe, taskhsvc.exe), the spreader service (mssecsvc.exe), and localized ransom notes (msg/m_*.wnry) across 28 languages.
Extracted Indicators & Mutex Telemetry
Strings recovered from the payload match WannaCry's known operational signatures:
Infection Mutex: Global\MsWinZonesCacheCounterMutexA
Service Display: mssecsvc2.0
Service Binary: mssecsvc.exe
File Extension: .wnry
File Magic: WANACRY
Hardcoded Bitcoin Extortion Wallets
The binary contains the three infamous static cryptocurrency destination wallets assigned to victims for ransom payments:
115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94
Detection Engineering
YARA Detection Rule
rule MAL_PE_WannaCry_Launcher_DLL {
meta:
description = "Detects WannaCry ransomware launcher.dll payload deployed via DoublePulsar SMB exploitation"
author = "Malware On Tap"
date = "2026-09-28"
reference = "https://malwareontap.com/fresh-pour/september282026"
hash_sha256 = "ec481093436e1c5a03aaed1a4bc70b6aff99a75e6b1757fb19ec2a676fab0155"
strings:
$export = "PlayGame" ascii
$dll_name = "launcher.dll" ascii
$zip_pwd = "WNcry@2ol7" ascii
$mutex = "Global\\MsWinZonesCacheCounterMutexA" ascii wide
$service = "mssecsvc2.0" ascii wide
$btc1 = "115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn" ascii
$btc2 = "12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw" ascii
$btc3 = "13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94" ascii
condition:
uint16(0) == 0x5a4d and
uint32(uint32(0x3c)) == 0x00004550 and
filesize > 5MB and filesize < 6MB and
$export and $dll_name and $zip_pwd and
($mutex or $service or 1 of ($btc*))
}
Indicators of Compromise (IOCs)
| Artifact / Identifier | Type | Value / Context |
|---|---|---|
launcher.dll | SHA256 | ec481093436e1c5a03aaed1a4bc70b6aff99a75e6b1757fb19ec2a676fab0155 |
launcher.dll | SHA1 | 1c6ad5ec3774aeedf2837494f633eecc9e983a80 |
launcher.dll | MD5 | afc8cc2c81345acf3a1f4add32c460bf |
| Attacker Remote IP | IPv4 | 186.193.28.12 (AS53078 Acesse Comunicação Ltda, BR) |
| Target Destination | Port | 445/TCP (smbd honeypot emulator) |
| Exported Function | PE Export | PlayGame (Ordinal 1, RVA 0x1114) |
| Infection Mutex | Mutex | Global\MsWinZonesCacheCounterMutexA |
| Spreader Service | Service Name | mssecsvc2.0 (mssecsvc.exe) |
| Archive Password | Secret | WNcry@2ol7 |
| Extortion Wallet 1 | Bitcoin | 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn |
| Extortion Wallet 2 | Bitcoin | 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw |
| Extortion Wallet 3 | Bitcoin | 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 |
