🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f48a8d80cc55a1fbe9a210b60b07f3677b736b8a02d5408697d9df54a276776. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WannaCry


Vendor detections: 14


Intelligence 14 IOCs YARA 11 File information Comments

SHA256 hash: 3f48a8d80cc55a1fbe9a210b60b07f3677b736b8a02d5408697d9df54a276776
SHA3-384 hash: 5585e3618f50042344ef4bf4b757215e76ae5db4c1f4aaf2685f9da4d0b7baaa7ee09458fd63d7b40108c8c676c8a7b8
SHA1 hash: 0a31ea9a024ecf6536283e1eda1f48458b10cbed
MD5 hash: eb4f4c455604f0f1ce111fbefecd9e21
humanhash: minnesota-nebraska-november-ack
File name:LisectAVT_2403002A_26.exe
Download: download sample
Signature WannaCry
File size:3'723'271 bytes
First seen:2024-07-25 00:00:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9ecee117164e0b870a53dd187cdd7174 (82 x WannaCry, 1 x Worm.Virut)
ssdeep 98304:y763opJtK5ZcSUDcn6SAcdZvxWa9P593:y763atKZcxcnZAcMadz
Threatray 1'083 similar samples on MalwareBazaar
TLSH T195063368622CD6BCE1051DB400B3C63AA6763C6556FF6A0F8B504DA73D53B6F7BC0A42
TrID 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.7% (.EXE) Win64 Executable (generic) (10523/12/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Reporter Anonymous
Tags:exe WannaCry


Avatar
Anonymous
this malware sample is very nasty!

Intelligence


File Origin
# of uploads :
1
# of downloads :
393
Origin country :
CN CN
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
Encryption Generic Infostealer Network Stealth
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Sending an HTTP GET request to an infection source
Creating a service
Launching a service
Restart of the analyzed sample
Searching for synchronization primitives
Connection attempt
Sending a custom TCP request
Query of malicious DNS domain
Connection attempt to an infection source
Enabling autorun for a service
Forced shutdown of a system process
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd crypto epmicrosoft_visual_cc lolbin microsoft_visual_cc overlay packed ransomware shell32 wannacry
Result
Threat name:
Wannacry
Detection:
malicious
Classification:
rans.expl.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
Changes security center settings (notifications, updates, antivirus, firewall)
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Detected Wannacry Ransomware
Drops executables to the windows directory (C:\Windows) and starts them
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Query firmware table information (likely to detect VMs)
Tries to download HTTP data from a sinkholed server
Yara detected Wannacry ransomware
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1481028 Sample: LisectAVT_2403002A_26.exe Startdate: 25/07/2024 Architecture: WINDOWS Score: 100 28 www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com 2->28 36 Tries to download HTTP data from a sinkholed server 2->36 38 Multi AV Scanner detection for domain / URL 2->38 40 Malicious sample detected (through community Yara rule) 2->40 42 6 other signatures 2->42 8 LisectAVT_2403002A_26.exe 7 2->8         started        12 LisectAVT_2403002A_26.exe 2->12         started        15 svchost.exe 2->15         started        17 6 other processes 2->17 signatures3 process4 dnsIp5 26 C:\Windows\tasksche.exe, PE32 8->26 dropped 52 Drops executables to the windows directory (C:\Windows) and starts them 8->52 19 tasksche.exe 8->19         started        30 192.168.2.102 unknown unknown 12->30 32 192.168.2.103 unknown unknown 12->32 34 98 other IPs or domains 12->34 54 Connects to many different private IPs via SMB (likely to spread or exploit) 12->54 56 Connects to many different private IPs (likely to spread or exploit) 12->56 58 Changes security center settings (notifications, updates, antivirus, firewall) 15->58 22 MpCmdRun.exe 2 15->22         started        60 Query firmware table information (likely to detect VMs) 17->60 file6 signatures7 process8 signatures9 44 Detected Wannacry Ransomware 19->44 46 Antivirus detection for dropped file 19->46 48 Multi AV Scanner detection for dropped file 19->48 50 Machine Learning detection for dropped file 19->50 24 conhost.exe 22->24         started        process10
Threat name:
Win32.Ransomware.WannaCry
Status:
Malicious
First seen:
2024-07-25 00:01:06 UTC
File Type:
PE (Exe)
Extracted files:
2
AV detection:
24 of 24 (100.00%)
Threat level:
  5/5
Result
Malware family:
wannacry
Score:
  10/10
Tags:
family:wannacry discovery ransomware worm
Behaviour
Modifies data under HKEY_USERS
System Location Discovery: System Language Discovery
Drops file in Windows directory
Drops file in System32 directory
Creates a large amount of network flows
Executes dropped EXE
Contacts a large (3224) amount of remote hosts
Wannacry
Unpacked files
SH256 hash:
891fa5f91382fd21322df4b0137f6c865d96fe376c88f6849592cd4942254520
MD5 hash:
3df2667ef94776eeb272a1404801f118
SHA1 hash:
0741698e6d3460284494b239bf6bac7d9e0d3a99
Detections:
WannaCry WannaCry_Ransomware Win32_Ransomware_WannaCry ransomware_windows_wannacry
SH256 hash:
3f48a8d80cc55a1fbe9a210b60b07f3677b736b8a02d5408697d9df54a276776
MD5 hash:
eb4f4c455604f0f1ce111fbefecd9e21
SHA1 hash:
0a31ea9a024ecf6536283e1eda1f48458b10cbed
Detections:
WannaCry WannaCry_Ransomware_Gen WannaCry_Ransomware Win32_Ransomware_WannaCry ransomware_windows_wannacry
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_indirect_function_call_3
Author:Didier Stevens (https://DidierStevens.com)
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:WannaCry_Ransomware
Author:Florian Roth (Nextron Systems) (with the help of binar.ly)
Description:Detects WannaCry Ransomware
Reference:https://goo.gl/HG2j5T
Rule name:WannaCry_Ransomware_Gen
Author:Florian Roth (Nextron Systems) (based on rule by US CERT)
Description:Detects WannaCry Ransomware
Reference:https://www.us-cert.gov/ncas/alerts/TA17-132A
Rule name:WannaCry_Ransomware_Gen_RID302B
Author:Florian Roth (based on rule by US CERT)
Description:Detects WannaCry Ransomware
Reference:https://www.us-cert.gov/ncas/alerts/TA17-132A
Rule name:Win32_Ransomware_WannaCry
Author:ReversingLabs
Description:Yara rule that detects WannaCry ransomware.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

WannaCry

Executable exe 3f48a8d80cc55a1fbe9a210b60b07f3677b736b8a02d5408697d9df54a276776

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WININET.dll::InternetCloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::GetStartupInfoA
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileA
KERNEL32.dll::MoveFileExA
WIN_CRYPT_APIUses Windows Crypt APIADVAPI32.dll::CryptAcquireContextA
ADVAPI32.dll::CryptGenRandom
WIN_SVC_APICan Manipulate Windows ServicesADVAPI32.dll::ChangeServiceConfig2A
ADVAPI32.dll::CreateServiceA
ADVAPI32.dll::OpenSCManagerA
ADVAPI32.dll::OpenServiceA
ADVAPI32.dll::RegisterServiceCtrlHandlerA
ADVAPI32.dll::StartServiceA

Comments