{"id":"faabc72c2848caf771c29c6cddfd5254","title":"WannaCry — WannaCry · 木马/恶意软件 · PE64","md5":"faabc72c2848caf771c29c6cddfd5254","sha256":"48ed2a2fc7652fc12c6edfc2efbef6d65a9f85bf5874dbaf275301775265e136","family":"WannaCry","apt":"Lazarus(APT38)","verdict":null,"sample_type":"木马/恶意软件","lang":"C++","file_format":"PE64","compiler":"MSVC","published_at":"2026-07-02T16:00:00.000Z","summary":"This sample is the WannaCry ransomware DLL component, compiled with MSVC 2010 as a x86-64 PE DLL. It contains the infamous killswitch domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com), Microsoft Crypto API calls (CryptAcquireContextA, CryptGenRandom, CryptProtectMemory) for file encryption, and embedded resource payloads including launcher.dll, mssecsvr.exe, and eee.exe. Attributed to Lazarus Group (APT38) — North Korean state-sponsored threat actor. WannaCry exploited the EternalBlue (MS17-010) SMB vulnerability to propagate across networks without user interaction.","url":"https://zseceye.com/report/faabc72c2848caf771c29c6cddfd5254","json_url":"https://zseceye.com/report/faabc72c2848caf771c29c6cddfd5254.json","html_url":"https://zseceye.com/report/faabc72c2848caf771c29c6cddfd5254","hash_urls":{"md5":"https://zseceye.com/hash/faabc72c2848caf771c29c6cddfd5254","sha256":"https://zseceye.com/hash/48ed2a2fc7652fc12c6edfc2efbef6d65a9f85bf5874dbaf275301775265e136"},"search_urls":{"md5":"https://zseceye.com/?q=faabc72c2848caf771c29c6cddfd5254","sha256":"https://zseceye.com/?q=48ed2a2fc7652fc12c6edfc2efbef6d65a9f85bf5874dbaf275301775265e136"},"sample_download_url":"https://zseceye.com/report/faabc72c2848caf771c29c6cddfd5254/sample","sample_filename":"48ed2a2fc7652fc1.zip","iocs":[],"ips":[]}