On 12 May 2017 a worm locked machines around the world. Inside the sample was a nonsense domain nobody had registered: iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
The logic was simple. If that name answered, that sample stopped. If it did not, it kept going.
Marcus Hutchins registered it that day. Public WHOIS still shows Creation Date 2017-05-12T15:08:04Z. Registrar: Cloudflare.
On 30 August 2026 I queried it live. The A records were 104.16.166.228 and 104.16.167.228. HTTP HEAD came back 200, Server cloudflare.
For that sample, one domain registration was enough. Not every variant used the same name. I did not run malware. An HTTP 200 today does not mean the worm is still spreading.
Sources
- How to Accidentally Stop a Global Cyber AttacksMarcus Hutchins, 13 May 2017.
- WannaCrypt ransomware worm targets out-of-date systemsMicrosoft Security Blog, 12 May 2017.

