Reversing WannaCry

Using Ghidra to disassemble the WannaCry ransomware and hunt for the infamous killswitch URL — then tracing the entry point, service creation, and propagation path down to EternalBlue.

WannaCry ransomware write-up heading

Loading full write-up…