MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a3a09d7b98a5a2bf7d87da376c74e0d98f7bf0262c2c07caa14db68ac026b0c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WannaCry


Vendor detections: 13


Intelligence 13 IOCs YARA 4 File information Comments

SHA256 hash: 4a3a09d7b98a5a2bf7d87da376c74e0d98f7bf0262c2c07caa14db68ac026b0c
SHA3-384 hash: c9579801ee7cee7ab58d2f626a29b1b239d8c6223181a27ff1fe08de73aab0c060cfabada532b850487713981084e70a
SHA1 hash: 85ba0c21b48ca1a1c84c51315b2accb9e0724902
MD5 hash: 4015cf1950b7134bd0b98734eb3326ac
humanhash: vermont-alaska-solar-shade
File name:4a3a09d7b98a5a2bf7d87da376c74e0d98f7bf0262c2c07caa14db68ac026b0c
Download: download sample
Signature WannaCry
File size:5'298'176 bytes
First seen:2026-05-28 09:15:14 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 0cdadfa1098d845dd3b4cf92625b5f04 (28 x WannaCry)
ssdeep 98304:DIdPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2H:DIdPe1Cxcxk3ZAEUadzR8yc4H
Threatray 1'045 similar samples on MalwareBazaar
TLSH T19A363394726C90FCE0450EB844B38D19F7733C5A6BBA4A1F4BC0867F0E53B9BAA94751
TrID 39.7% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
21.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
8.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
8.3% (.EXE) Win64 Executable (generic) (6522/11/2)
6.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
Reporter pawscobbler
Tags:dionaea exe WannaCry


Avatar
pawscobbler
Captured by Dionaea honeypot automation

Intelligence


File Origin
# of uploads :
1
# of downloads :
134
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
_4a3a09d7b98a5a2bf7d87da376c74e0d98f7bf0262c2c07caa14db68ac026b0c.dll
Verdict:
No threats detected
Analysis date:
2026-05-28 09:18:47 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
shellcode wannacry
Result
Verdict:
Malware
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug crypto microsoft_visual_cc overlay overlay packed ransomware ransomware smb wannacry
Verdict:
Malicious
File Type:
dll x64
First seen:
2018-09-15T06:39:00Z UTC
Last seen:
2025-05-16T03:06:00Z UTC
Hits:
~1000
Detections:
Trojan-Ransom.Win32.Wanna.zbu HEUR:Worm.Win32.Generic HEUR:Exploit.Win32.MS17-010.gen Trojan.Win32.Eb.b Trojan.Win32.Eb.a Trojan-Ransom.Win32.Wanna.m Trojan-Ransom.Win32.Wanna.ak HEUR:Trojan.Win32.Generic HEUR:Trojan.Win32.EquationDrug.gen Trojan.Win32.EquationDrug.sb Exploit.Win32.MS17-010.kpn Trojan.Win32.Eb.s HEUR:Trojan-Ransom.Win32.Wanna.gen Exploit.Win32.MS17-010.cb Exploit.Win32.MS17-010.bf
Gathering data
Threat name:
Win64.Ransomware.WannaCry
Status:
Malicious
First seen:
2026-05-28 09:16:03 UTC
File Type:
PE+ (Dll)
Extracted files:
2
AV detection:
27 of 36 (75.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
4a3a09d7b98a5a2bf7d87da376c74e0d98f7bf0262c2c07caa14db68ac026b0c
MD5 hash:
4015cf1950b7134bd0b98734eb3326ac
SHA1 hash:
85ba0c21b48ca1a1c84c51315b2accb9e0724902
Detections:
triage_wanacrypt0r_ransomware triage_wannacry_ransomware
SH256 hash:
20e80726f1b3e4ac68c7dbb5a586678ced16efc98c80b2957a36aaef11173ae9
MD5 hash:
5bb7fdd60f369c96d3a77d134e530847
SHA1 hash:
549daaff0eb121f793e4a6ffd914bf59e69fdeea
Detections:
triage_wannacry_ransomware
SH256 hash:
379119555970fd0c71da4c940957244fe1a53cb219e812b53410b62e079a16b9
MD5 hash:
955454dd1de9d6ac38bbbef155e6a21d
SHA1 hash:
0f7aca7ff73f19d4ec9d6a809f0a80e96f1d0e01
Detections:
triage_wanacrypt0r_ransomware triage_wannacry_ransomware
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:WannaCry_Ransomware
Author:Florian Roth (Nextron Systems) (with the help of binar.ly)
Description:Detects WannaCry Ransomware
Reference:https://goo.gl/HG2j5T

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments