WanaCrypt0r is a ransomware infection that has spread through many corporate networks. The worm uses the ETERNALBLUE SMB vulnerability (MS17-010) to spread itself using the vulnerability. The domain has been sinkholed and the host in question now resolves to an IP address that hosts a website. The second argument to InternetOpenA is 1 (INTERNET_OPEN_TYPE_DIRECT), so the worm will still work on any system that requires a proxy to access the Internet.”]
Source: https://blog.malwarebytes.com/threat-analysis/2017/05/the-worm-that-spreads-wanacrypt0r/

