Wana Crypt0r has been most effective—not only does the ransomware loop through every open RDP session on a system and run the ransomware as that user, but the initial component that gets dropped on systems appears to be a worm that contains and runs the ransomware, spreading itself using the It doesn’t actually download anything there, just tries to connect. This was probably some kind of kill switch or anti-sandbox technique.

Whichever it is, it has backfired on the authors of the worm, as the domain has been sinkholed and the host in question now resolves to an IP address that hosts a website.

If it was run with two arguments or more—in other words, if it was run as a service—execution eventually falls through to the worm function.

The initialization function called first calls to initialize the crypto API so it can use a cryptographically-secure pseudo-random number generator.

If it detects the presence of to load the relevant payload DLL.

Something that many security researchers have feared has indeed come true.

Threat actors have integrated a critical exploit taking advantage of a popular communication protocol used by Windows systems, crippling thousands of computers worldwide with ransomware.

If the exploitation attempts take over 10 minutes, then the exploitation thread is stopped.

