Skip to content

Instantly share code, notes, and snippets.

What would you like to do?

WannaCry|WannaDecrypt0r NSA-Cybereweapon-Powered Ransomware Worm

  • Virus Name: WannaCrypt, WannaCry, WanaCrypt0r, WCrypt, WCRY
  • Vector: All Windows versions before Windows 10 are vulnerable if not patched for MS-17-010. It uses EternalBlue MS17-010 to propagate.


Malware samples

Binary blob in PE crypted with pass 'WNcry@2ol7'

Informative Tweets

Cryptography details

  • encrypted via AES
  • AES key generated with a CSPRNG
  • AES key is encrypted by RSA

Bitcoin ransom addresses

C&C centers

  • gx7ekbenv2riucmf.onion
  • 57g7spgrzlojinas.onion
  • xxlvbrloxvriy2c5.onion
  • 76jdd2ir2embyv47.onion
  • cwwnhwhlz52ma.onion


All language ransom messages available here:

m_bulgarian, m_chinese (simplified), m_chinese (traditional), m_croatian, m_czech, m_danish, m_dutch, m_english, m_filipino, m_finnish, m_french, m_german, m_greek, m_indonesian, m_italian, m_japanese, m_korean, m_latvian, m_norwegian, m_polish, m_portuguese, m_romanian, m_russian, m_slovak, m_spanish, m_swedish, m_turkish, m_vietnamese


This comment has been minimized.

Copy link

@roycewilliams roycewilliams commented May 14, 2017

Very active fork here, updates being crowdsourced:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment