🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e4e2815f898ec108e9d22d375ac40ffb77a27fc98ef080e8c57408f2b9aa033. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WannaCry


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: 2e4e2815f898ec108e9d22d375ac40ffb77a27fc98ef080e8c57408f2b9aa033
SHA3-384 hash: a0986177072e2f12a5a211db8aeee868d7552ca165c9bde7aa66a9083bf4fde555f676b8c8b207f76341c00abe487699
SHA1 hash: 3b682b89e40f87d30978d170c89213146fc04d06
MD5 hash: 00544fe01bc3fd222855d83761f49c65
humanhash: september-mars-island-early
File name:2e4e2815f898ec108e9d22d375ac40ffb77a27fc98ef080e8c57408f2b9aa033
Download: download sample
Signature WannaCry
File size:3'514'368 bytes
First seen:2022-10-12 14:00:11 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 68f013d7437aa653a8a98a05807afeb1 (28 x WannaCry, 1 x Worm.Ramnit)
ssdeep 49152:nQqMSPbcBVQeC6SAARdhnvxJM0H9PAMEcaEau3K:QqPoBhC6SAEdhvxWa9P593K
TLSH T12CF533B4AA20BB5DF2960CF81460C17D262A1EB1B69F561BD6A01D833C14FAF9FC05DD
TrID 38.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.5% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
13.0% (.EXE) Win64 Executable (generic) (10523/12/4)
8.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
Reporter petikvx
Tags:WannaCry

Intelligence


File Origin
# of uploads :
1
# of downloads :
286
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
MalwareBazaar
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd.exe greyware ransomware shell32.dll wanna wannacry
Result
Threat name:
Wannacry
Detection:
malicious
Classification:
rans
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Detected Wannacry Ransomware
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Ransomware.WannaCry
Status:
Malicious
First seen:
2019-09-02 18:19:00 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
43 of 46 (93.48%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Verdict:
Informative
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
2e4e2815f898ec108e9d22d375ac40ffb77a27fc98ef080e8c57408f2b9aa033
MD5 hash:
00544fe01bc3fd222855d83761f49c65
SHA1 hash:
3b682b89e40f87d30978d170c89213146fc04d06
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:WannaCry_Ransomware
Author:Florian Roth (with the help of binar.ly)
Description:Detects WannaCry Ransomware
Reference:https://goo.gl/HG2j5T
Rule name:Win32_Ransomware_WannaCry
Author:ReversingLabs
Description:Yara rule that detects WannaCry ransomware.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments