18 months after the initial WannaCry Ransomware outbreak, the malware continues to exist on thousands, if not hundreds of thousands of infected computers.
When WannaCry first appeared, security researcher Marcus Hutchins made a very important discovery. He discovered that an unregistered domain was acting as a killswitch for the malware, which he then registered. When the malware managed to connect to that domain, it did not start the file encryption process. However, the malware continued to spread in the background, while also checking to see if the killswitch domain was registered or not.
Feels like a nice time to do a quick end of year look at our WannaCry data. I'll be posting some graphs and different metrics in this thread. Big shoutout to the crew at @Cloudflare, they've been providing us with assistance with the kill switch since the beginning almost.
— Jamie Hankins (@2sec4u) December 21, 2018
In a Twitter post last Friday, a security researcher published data from the killswitch domain. Cloudflare is now responsible for hosting so that the webserver is always available. In the event that someone launched a DDoS attack on the webserver that holds the domain, chaos would ensue. All infected systems that are not encrypted (because the malware can communicate with the killswitch domain) would be encrypted and would have to pay the ransom.
According to the data, CloudFlare, responsible for Hosting, receives more than 17 million requests per week, from 630,000 unique IPs from 194 different countries. Below is a chart with the countries that have the most infected systems. At the top are China, Indonesia and Vietnam.

The same Tweet also contained another graph showing the frequency of requests sent during the week. What is visible is that on weekdays the requests are almost double, which indicates that many corporate systems are infected.
![]()
