Skip to main content

One post tagged with "wannacry"

View All Tags

WannaCry in the Wild: Intercepting a DoublePulsar Injection & Launcher.dll Payload

· 6 min read

Overview​

Nearly a decade after its historic global outbreak in May 2017, the automated scanning and exploitation apparatus behind WannaCry (WanaCrypt0r 2.0) remains an active fixture of the IPv4 background noise. Threat actors and automated worm bots continue spraying vulnerable endpoints with NSA-leaked EternalBlue (MS17-010) exploits and DoublePulsar kernel backdoor payloads.

On September 28, 2026 at 08:33 UTC, Malware on Tap's honeypot sensor(s) intercepted an active exploitation sequence originating from Brazil (186.193.28.12). The sensor's SMB emulation engine captured 2,584 frames of raw SMBv1 traffic, assembling a 5.02 MB PE32 DLL payload (launcher.dll, SHA256: ec481093436e1c5a03aaed1a4bc70b6aff99a75e6b1757fb19ec2a676fab0155).


HONEYPOT INCIDENT DOSSIER

WannaCry / DoublePulsar Opportunistic SMB Spreader

An opportunistic SMBv1 reconnaissance and exploitation sequence attempting in-memory DoublePulsar backdoor injection to deliver the WannaCry launcher.dll payload onto port 445/TCP.

Attack ProtocolSMBv1 (Port 445/TCP) → smbd
Primary Artifactlauncher.dll (5,267,459 bytes)
Origin & Network Signals
Attacker Endpoint
186.193.28.12AS53078 (Acesse Comunicação Ltda)Brazil (BR)
Exploitation Signature
MS17-010 (EternalBlue)DoublePulsar (MID 0xfeff)SMB_COM_TRANSACTION2

Attack Progression & Protocol Analysis​

The attacker bot orchestrated a sequential multi-stage probe across five discrete TCP connections before initiating payload transfer:

1. SMB Dialect Negotiation & Session Setup

The client advertises standard legacy dialects (PC NETWORK PROGRAM 1.0, LANMAN1.0, Windows for Workgroups 3.1a, NT LM 0.12). Connection 10010 completes anonymous authentication and establishes session state without credentials.

Phase: Reconnaissance / Dialect Discovery

2. DoublePulsar Verification (MID 0xfeff)

Rather than reinjecting raw kernel shellcode via buffer overflow, the bot tests whether a DoublePulsar ring-0 hook is already present by sending a crafted SMB_COM_TRANSACTION2 request with MultiplexID = 0xfeff.

Phase: Persistence Verification

3. High-Throughput Payload Ingestion

Upon receiving affirmative responses from the SMB emulator, Connection 10016 transfers 2,584 consecutive frames spanning 10.59 MB of raw bistream data, decodes the incoming chunks and flushes the completed binary to disk.

Phase: In-Memory Dropper Injection

Binary Deep Dive: launcher.dll​

Static dissection of the dropped binary (afc8cc2c81345acf3a1f4add32c460bf) confirms that it is the canonical 32-bit launcher.dll component designed to bootstrap the core ransomware encryptor (tasksche.exe).

PE Header & Export Characteristics​

Parsing the portable executable headers reveals strict alignment with the original May 2017 outbreak binaries:

PE Format: PE32 (x86 32-bit Dynamic Link Library)
Compilation Timestamp: 1494505297 (Thu, 11 May 2017 12:21:37 UTC)
Image Base: 0x10000000
Entry Point: 0x11e9
Export Table: launcher.dll (1 exported function)
Ordinal 1: PlayGame (RVA 0x1114)

The exported symbol PlayGame is the signature entry point executed by DoublePulsar's user-mode APC injector or via command-line execution:

rundll32.exe launcher.dll,PlayGame

Section Breakdown & Embedded Resource .rsrc​

The section table demonstrates an extraordinarily bloated resource section comprising 99.5% of the entire binary footprint:

SectionVirtual SizeVirtual RVARaw Data SizeCharacteristics / Role
.text0x28c0x10004,096 bytesMinimal loader code (PlayGame subroutine)
.rdata0x1d80x20004,096 bytesRead-only data & export descriptor
.data0x1540x30004,096 bytesGlobal state variables
.rsrc0x5000600x40005,246,976 bytesEncrypted ZIP container with WannaCry assets
.reloc0x2ac0x5050004,096 bytesRelocation delta table

Embedded Archive Extraction & Decryption Password​

Located at byte offset 0x3c6d6 within the .rsrc section is the PK ZIP file header (PK\x03\x04). At offset 0x45634, the binary contains the hardcoded password string used to decompress the bundled assets:

WNcry@2ol7

Upon invocation of PlayGame, launcher.dll unpacks this internal ZIP archive, dropping the primary decryptor UI (tasksche.exe), helper utilities (taskse.exe, taskhsvc.exe), the spreader service (mssecsvc.exe), and localized ransom notes (msg/m_*.wnry) across 28 languages.


Extracted Indicators & Mutex Telemetry​

Strings recovered from the payload match WannaCry's known operational signatures:

Infection Mutex: Global\MsWinZonesCacheCounterMutexA
Service Display: mssecsvc2.0
Service Binary: mssecsvc.exe
File Extension: .wnry
File Magic: WANACRY

Hardcoded Bitcoin Extortion Wallets​

The binary contains the three infamous static cryptocurrency destination wallets assigned to victims for ransom payments:

  • 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn
  • 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw
  • 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94

Detection Engineering​

YARA Detection Rule​

rule MAL_PE_WannaCry_Launcher_DLL {
meta:
description = "Detects WannaCry ransomware launcher.dll payload deployed via DoublePulsar SMB exploitation"
author = "Malware On Tap"
date = "2026-09-28"
reference = "https://malwareontap.com/fresh-pour/september282026"
hash_sha256 = "ec481093436e1c5a03aaed1a4bc70b6aff99a75e6b1757fb19ec2a676fab0155"
strings:
$export = "PlayGame" ascii
$dll_name = "launcher.dll" ascii
$zip_pwd = "WNcry@2ol7" ascii
$mutex = "Global\\MsWinZonesCacheCounterMutexA" ascii wide
$service = "mssecsvc2.0" ascii wide
$btc1 = "115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn" ascii
$btc2 = "12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw" ascii
$btc3 = "13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94" ascii
condition:
uint16(0) == 0x5a4d and
uint32(uint32(0x3c)) == 0x00004550 and
filesize > 5MB and filesize < 6MB and
$export and $dll_name and $zip_pwd and
($mutex or $service or 1 of ($btc*))
}

Indicators of Compromise (IOCs)​

Artifact / IdentifierTypeValue / Context
launcher.dllSHA256ec481093436e1c5a03aaed1a4bc70b6aff99a75e6b1757fb19ec2a676fab0155
launcher.dllSHA11c6ad5ec3774aeedf2837494f633eecc9e983a80
launcher.dllMD5afc8cc2c81345acf3a1f4add32c460bf
Attacker Remote IPIPv4186.193.28.12 (AS53078 Acesse Comunicação Ltda, BR)
Target DestinationPort445/TCP (smbd honeypot emulator)
Exported FunctionPE ExportPlayGame (Ordinal 1, RVA 0x1114)
Infection MutexMutexGlobal\MsWinZonesCacheCounterMutexA
Spreader ServiceService Namemssecsvc2.0 (mssecsvc.exe)
Archive PasswordSecretWNcry@2ol7
Extortion Wallet 1Bitcoin115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn
Extortion Wallet 2Bitcoin12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw
Extortion Wallet 3Bitcoin13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94
Indicators of Compromise (IOCs)
IOCs (domains, IP addresses, files, hashes, etc.) from this analysis are available on GitHub.
View on GitHub →