Using Ghidra to disassemble the WannaCry ransomware and hunt for the infamous killswitch URL — then tracing the entry point, service creation, and propagation path down to EternalBlue.
Loading full write-up…