Threat Intelligence|

What stopped the worm was a domain registration.

On 12 May 2017 a worm locked machines around the world. Inside the sample was a nonsense domain nobody had registered: iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com

The logic was simple. If that name answered, that sample stopped. If it did not, it kept going.

Marcus Hutchins registered it that day. Public WHOIS still shows Creation Date 2017-05-12T15:08:04Z. Registrar: Cloudflare.

On 30 August 2026 I queried it live. The A records were 104.16.166.228 and 104.16.167.228. HTTP HEAD came back 200, Server cloudflare.

The English recording of the live check on 30 August 2026.

For that sample, one domain registration was enough. Not every variant used the same name. I did not run malware. An HTTP 200 today does not mean the worm is still spreading.

Sources