• Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Home Research/How to do it

Meet WannaKey, A Tool Developed By A French Researcher To Decrypt WannaCry On Windows XP

Paul Balo by Paul Balo
May 20, 2017
in Research/How to do it, Security, Software
Share on FacebookShare on Twitter

The WannaCrypt ransomware attack is still ongoing – sort of and since then some silent heroes have emerged including the 22 year old UK based MalwareTech person (identity undisclosed) who was able to slow down the spread of the malware but now it looks like we have another one from France. Adrien Guinet has developed what he called WannaKey and has since published how it works on GitHub.

WannaKey tries to recover the private RSA key used by WannaCry to encrypt system files and as he puts it. Guinet says WannaKey “does so by searching for them in the wcry.exe process. This is the process that generates the RSA private key. The main issue is that the CryptDestroyKey and CryptReleaseContext does not erase the prime numbers from memory before freeing the associated memory.”

[xyz-ihs snippet=”WannaKey-for-XP”]

But this only works for Windows XP machines we talked about earlier that were actually the worst hit in the attacks. Microsoft started issuing the patches to XP users for free during the attacks after it had previously asked businesses to pay $1,000 for support. The other caveat is that WannaCry might only be effective if the machine hasn’t been rebooted after the malware infection. So that’s it, Windows XP that’s has not been rebooted since it was attacked.

WannaKey searches for prime numbers of the private key in wcry.exe (the process for generating WannaCry’s private key which is needed to lock out a user) which remains in the memory unless you reboot of course because you see, Microsoft designed its APIs using the “CryptDestroyKey and CryptReleaseContext which does not erase the prime numbers from memory before freeing the associated memory.” This is the reason the patch doesn’t work for other Windows models because this memory is erased whether your reboot or not and this will definitely make someone who believes Windows XP is still the most secure in the Windows family happy even though Microsoft encourages business and individual users alike to switch to its newest/newer models to ensure security of their files.

Guinet adds that “If you are lucky, that is the associated memory hasn’t been reallocated and erased, these prime numbers might still be in memory. That’s what this software tries to achieve.”

There you for Windows XP users, try it out if you haven’t rebooted your machine since WannaCry started spreading but there’s another option of course and that’s to pay the $300 ransom which I advise against.

Guinet is now working on making WannaKey more user friendly.

[xyz-ihs snippet=”WannaKey-UI”]

Related Posts:

  • CeeYjMDncRmSGNPVY3oH7B
    Microsoft Tests New AI-Powered Windows Search
  • l28420241204183946
    Microsoft Ends Supports For Outdated Hardware With…
  • key-visual2
    Google Password-less Sign-in Standard Introduces…
  • Screenshot 2024-10-03 at 15.34.40
    GitHub Copilot Surpasses 15 Million Users
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
  • Simple Approach To Convert NSF To CSV File Format
  • 1738537437848
    ChatGPT Deep Research Now Links to GitHub Repos
  • 16466817280064
    Solana Ecosystem Hit By Hack Draining Millions in…

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: francemalwaresoftwarewannacrywannakeywindowswindows xp
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

BROWSE BY CATEGORIES

Select Category

    Receive top tech news directly in your inbox

    subscription from
    Loading

    Freshly Squeezed

    • Theranos for Code: Inside Builder.ai’s $1.5 Billion AI-Washing Scam June 8, 2025
    • Jamf Expands AI Assistant and Tools for Apple IT Teams June 7, 2025
    • Alphabet CEO Plans Continued Engineering Hiring for AI Growth June 7, 2025
    • Perplexity CEO Criticises Google’s AI and Assistant Strategy June 7, 2025
    • Microsoft Launches Copilot Shopping App with Native Checkout June 7, 2025
    • Google Chrome Achieves Record Performance with New Optimisations June 7, 2025

    Browse Archives

    June 2025
    MTWTFSS
     1
    2345678
    9101112131415
    16171819202122
    23242526272829
    30 
    « May    

    Quick Links

    • About TechBooky
    • Advertise Here
    • Contact us
    • Submit Article
    • Privacy Policy
    • Login

    © 2021 Design By Tech Booky Elite

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    • African
    • Artificial Intelligence
    • Gadgets
    • Metaverse
    • Tips
    • About TechBooky
    • Advertise Here
    • Submit Article
    • Contact us

    © 2021 Design By Tech Booky Elite

    Discover more from TechBooky

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Ok