🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 47abbb7ad1ca5dea21674694dbe2dd59ebd4be8ce2fc15554c68574614f3d136. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WannaCry


Vendor detections: 11


Intelligence 11 IOCs YARA 5 File information Comments

SHA256 hash: 47abbb7ad1ca5dea21674694dbe2dd59ebd4be8ce2fc15554c68574614f3d136
SHA3-384 hash: e1b588a13524f935c2cca5275f772fce38a1ea109fb6362f5c7f545febeee7196c72e6c55958cb6c9583cf07dbcff99b
SHA1 hash: 653b95b24480dd60982e95e19f15c736321cbade
MD5 hash: ef0821209a3166e8142f5d170708b114
humanhash: maine-cold-georgia-double
File name:finebi.exe
Download: download sample
Signature WannaCry
File size:355'840 bytes
First seen:2025-03-15 14:49:35 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c864305433533795ac05928b3fb12106 (1 x WannaCry)
ssdeep 3072:SjPCKdrzvvdB2w12EgWVzgBMscgbSuDhPfdOSqFtpwP2lnJB0P4LdbdjCGLdLsxv:SrdHvvdYw3VIMscWSutPqFtnsP6dx6
TLSH T1B77439813421CEB8F827A078824251F5DAAA7C715B51D9FF023576FEDE376D0BA3A250
TrID 44.4% (.EXE) Win64 Executable (generic) (10522/11/4)
21.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon b2734d96b24973b2 (1 x WannaCry)
Reporter kafan_shengui
Tags:CobaltStrike exe WannaCry

Intelligence


File Origin
# of uploads :
1
# of downloads :
845
Origin country :
CA CA
Vendor Threat Intelligence
Malware family:
cobaltstrike
ID:
1
File name:
finebi.exe
Verdict:
Malicious activity
Analysis date:
2025-03-15 14:47:51 UTC
Tags:
cobaltstrike backdoor

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
70%
Tags:
shellcode emotet
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Connection attempt
Sending an HTTP GET request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context cobaltstrike crypto microsoft_visual_cc
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
68 / 100
Signature
Antivirus detection for URL or domain
Contains functionality to detect sleep reduction / modifications
Joe Sandbox ML detected suspicious sample
Performs DNS queries to domains with low reputation
Suricata IDS alerts for network traffic
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Verdict:
Malicious
Tags:
red_team_tool cobalt_strike
YARA:
malware_CobaltStrike_v3v4
Unpacked files
SH256 hash:
47abbb7ad1ca5dea21674694dbe2dd59ebd4be8ce2fc15554c68574614f3d136
MD5 hash:
ef0821209a3166e8142f5d170708b114
SHA1 hash:
653b95b24480dd60982e95e19f15c736321cbade
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CobaltStrike
Author:JPCERT/CC Incident Response Group
Description:detect CobaltStrike Beacon in memory
Reference:https://blogs.jpcert.or.jp/en/2018/08/volatility-plugin-for-detecting-cobalt-strike-beacon.html
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:malware_CobaltStrike_v3v4
Author:JPCERT/CC Incident Response Group
Description:detect CobaltStrike Beacon in memory
Reference:https://blogs.jpcert.or.jp/en/2018/08/volatility-plugin-for-detecting-cobalt-strike-beacon.html
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (GUARD_CF)high
CHECK_TRUST_INFORequires Elevated Execution (level:requireAdministrator)high
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::AllocateAndInitializeSid
ADVAPI32.dll::FreeSid
ADVAPI32.dll::OpenThreadToken
ADVAPI32.dll::ImpersonateNamedPipeClient
ADVAPI32.dll::RevertToSelf
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::AdjustTokenPrivileges
ADVAPI32.dll::CheckTokenMembership
ADVAPI32.dll::DuplicateTokenEx
ADVAPI32.dll::GetTokenInformation
ADVAPI32.dll::ImpersonateLoggedOnUser
WIN32_PROCESS_APICan Create Process and ThreadsADVAPI32.dll::CreateProcessAsUserA
KERNEL32.dll::CreateRemoteThread
KERNEL32.dll::CreateProcessA
ADVAPI32.dll::CreateProcessWithTokenW
ADVAPI32.dll::CreateProcessWithLogonW
KERNEL32.dll::OpenProcess
ADVAPI32.dll::OpenProcessToken
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetStartupInfoW
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CopyFileA
KERNEL32.dll::CreateFileMappingA
KERNEL32.dll::CreateFileA
KERNEL32.dll::MoveFileA
KERNEL32.dll::GetFileAttributesA
KERNEL32.dll::FindFirstFileA
WIN_BASE_USER_APIRetrieves Account InformationKERNEL32.dll::GetComputerNameA
ADVAPI32.dll::GetUserNameA
ADVAPI32.dll::LogonUserA
ADVAPI32.dll::LookupAccountSidA
ADVAPI32.dll::LookupPrivilegeValueA
WIN_CRYPT_APIUses Windows Crypt APIADVAPI32.dll::CryptAcquireContextA
ADVAPI32.dll::CryptGenRandom

Comments