🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 43a49befd0174dbcc2594eda6c46169015501f04017a9dba6ea4b51bbe991bb3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WannaCry


Vendor detections: 13


Intelligence 13 IOCs YARA 10 File information Comments

SHA256 hash: 43a49befd0174dbcc2594eda6c46169015501f04017a9dba6ea4b51bbe991bb3
SHA3-384 hash: d49c6fe9bfc28065f8372bac8910920973e21da1854fcfc906f5a641a00c6f813bdbc07571fc6f8e3b1300b6199bfa87
SHA1 hash: dfa0fb5f07274147b2ad50fbb0ed5d6a0975aef4
MD5 hash: 10c0774abb195b1a1ae8b93d6b1e068a
humanhash: orange-oklahoma-alanine-venus
File name:43a49befd0174dbcc2594eda6c46169015501f04017a9dba6ea4b51bbe991bb3
Download: download sample
Signature WannaCry
File size:5'267'459 bytes
First seen:2026-01-04 07:32:57 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 2e5708ae5fed0403e8117c645fb23e5b (1'124 x WannaCry, 7 x Worm.Virut, 2 x Expiro)
ssdeep 24576:zbLgdg5HyRNKFqCfD3JHjP/vX5BNY10Ts2JFSftF:zn9SGqCfTpfW10T/fet
Threatray 1'150 similar samples on MalwareBazaar
TLSH T1AF36AF21BB889861D21A13B05CF7CB66A77DFC218730474B3698B72D4E315E16F31E9A
TrID 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.7% (.EXE) Win64 Executable (generic) (10522/11/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
Reporter Butter1
Tags:dll eternalblue honeypot SMB WannaCry

Intelligence


File Origin
# of uploads :
1
# of downloads :
133
Origin country :
AU AU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
99.1%
Tags:
wannacry madi
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a custom TCP request
Verdict:
Malicious
File Type:
dll x32
First seen:
2017-08-26T14:16:00Z UTC
Last seen:
2023-10-15T20:14:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
9 match(es)
Tags:
.Net Corrupted Executable Html Office Document PE (Portable Executable) PE Memory-Mapped (Dump)
Threat name:
Win32.Ransomware.WannaCry
Status:
Malicious
First seen:
2017-08-26 17:48:18 UTC
File Type:
PE (Dll)
Extracted files:
13
AV detection:
33 of 36 (91.67%)
Threat level:
  5/5
Result
Malware family:
wannacry
Score:
  10/10
Tags:
family:wannacry discovery ransomware worm
Behaviour
Modifies data under HKEY_USERS
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Drops file in Windows directory
Creates a large amount of network flows
Executes dropped EXE
Contacts a large (3366) amount of remote hosts
Wannacry
Wannacry family
Unpacked files
SH256 hash:
43a49befd0174dbcc2594eda6c46169015501f04017a9dba6ea4b51bbe991bb3
MD5 hash:
10c0774abb195b1a1ae8b93d6b1e068a
SHA1 hash:
dfa0fb5f07274147b2ad50fbb0ed5d6a0975aef4
SH256 hash:
1ffedc76c91a83a4c6aecf31748839e54aa09e9ae4e7d1a202c0592f304e4f6d
MD5 hash:
d3d923de17b5fede4f63f70a5c593e65
SHA1 hash:
8dfe5274fc35837f8c73e3f7cc398aec0649b326
SH256 hash:
e26a1ff8ad661365a94f9f3222a3ad9b5983e40674946af6c08790cdcf0d7457
MD5 hash:
c2b767808005780aa8c7fbd8d699f4d8
SHA1 hash:
74a36574572ee6ab9d83821d7ab8c1d193d09fcd
Detections:
Win32_Ransomware_WannaCry ransomware_windows_wannacry WannaCry_Ransomware WannaCry_Ransomware_Gen
SH256 hash:
8defe4eae50719c1a30fa5f5de0e3379b6c526b4105b284ea017fd815dcde81d
MD5 hash:
cb06f4e5b87a3851b5e257ad1046fd02
SHA1 hash:
5d264b9ca2faa9efec3795b00a866084a23320e3
SH256 hash:
94e82367b6a8ff534ce38f6e9b9d21542199e5ba8361816281120bde29b9909c
MD5 hash:
e9dec6ce5c7f7ae59c64103e7d5ecddb
SHA1 hash:
a66bc5363ce29e2796f6bfbc339eacaa9017abc9
SH256 hash:
9f039754e30521900a2daf6a409148a8bb174ac2b1c99e3f1615c5b6af76bcda
MD5 hash:
2e1324507f74933f6e46c6157a73acd0
SHA1 hash:
e26eb1a9f6fa1f241e2d09ccd4f8c2bf99e23b0f
SH256 hash:
9f4a409e68f53a5cf4de4029ce347167605bb753d1140eda9a66079c55a11fdf
MD5 hash:
06db9ff8304f9fc7fb3cd7aa8c6f9fe2
SHA1 hash:
2b1bf782d6cbf73c9fd3d86922d059625522f998
Detections:
WannaCry_Ransomware
SH256 hash:
f063119e1a33f5fc82158989df3a0c131b018253d3aae5a58ef4f337e2f59809
MD5 hash:
1dfb91536032e5ea47d1250279c5a2a9
SHA1 hash:
a9ac2b2575561306636b4c0e3a67bda2285c6448
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Armadillov1xxv2xx
Author:malware-lu
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:NET
Author:malware-lu
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:SUSP_Imphash_Mar23_2
Author:Arnim Rupp (https://github.com/ruppde)
Description:Detects imphash often found in malware samples (Zero hits with with search for 'imphash:x p:0' on Virustotal)
Reference:Internal Research
Rule name:Sus_All_Windows_PE_Malware
Author:DiegoAnalytics
Description:Detects Windows PE malware of all types, avoids non-executables like .html
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:WannaCry_Ransomware
Author:Florian Roth (Nextron Systems) (with the help of binar.ly)
Description:Detects WannaCry Ransomware
Reference:https://goo.gl/HG2j5T

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments