🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5d7fa45d2fcb10893ee5bdbfc4b16bdeeffd34aa5791331332a8bbb1015cb63b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WannaCry


Vendor detections: 13


Intelligence 13 IOCs YARA 8 File information Comments

SHA256 hash: 5d7fa45d2fcb10893ee5bdbfc4b16bdeeffd34aa5791331332a8bbb1015cb63b
SHA3-384 hash: cfb37e19df88bdb67aac75fea104c65ff0e3d6ee854e93cedac8a305ae4d01c4ee709fe6cf855f0af46a99643f854b86
SHA1 hash: 7a23e2ef0682cfb8813a27dc559da187f9e178f5
MD5 hash: 07a5d326b196d166dc0618e7c25ac2b5
humanhash: oranges-bluebird-jig-equal
File name:07a5d326b196d166dc0618e7c25ac2b5
Download: download sample
Signature WannaCry
File size:5'267'459 bytes
First seen:2025-01-15 17:10:55 UTC
Last seen:2025-01-15 17:39:39 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 2e5708ae5fed0403e8117c645fb23e5b (1'124 x WannaCry, 7 x Worm.Virut, 2 x Expiro)
ssdeep 98304:d8qPoBhz1aRxcSUDk36SAEdhvxWa9P593R8s3:d8qPe1Cxcxk3ZAEUadzR8s
TLSH T19836E052D2850EA4D5E10AF61269DB50A77F2F5582AFB23E2621402F1CB7F1C9DE4F2C
TrID 41.1% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
22.2% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
11.8% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
7.5% (.EXE) Win64 Executable (generic) (10522/11/4)
4.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
Magika pebin
Reporter mentality
Tags:dll exe WannaCry

Intelligence


File Origin
# of uploads :
2
# of downloads :
250
Origin country :
CA CA
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
wannacry madi
Result
Verdict:
Malware
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd crypto crypto filecoder lolbin microsoft_visual_cc overlay packed packed ransomware rundll32 smb threat wanna wannacry wannacrypt wannacryptor
Result
Threat name:
Wannacry
Detection:
malicious
Classification:
rans.expl.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Detected Wannacry Ransomware
Drops executables to the windows directory (C:\Windows) and starts them
Found Tor onion address
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Uses cmd line tools excessively to alter registry or file data
Yara detected Wannacry ransomware
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1592069 Sample: txWVWM8Kx4.dll Startdate: 15/01/2025 Architecture: WINDOWS Score: 100 132 Malicious sample detected (through community Yara rule) 2->132 134 Antivirus / Scanner detection for submitted sample 2->134 136 Multi AV Scanner detection for dropped file 2->136 138 5 other signatures 2->138 12 loaddll32.exe 1 2->12         started        14 cmd.exe 2->14         started        16 mssecsvc.exe 2->16         started        20 cmd.exe 2->20         started        process3 dnsIp4 22 cmd.exe 1 12->22         started        24 rundll32.exe 12->24         started        27 conhost.exe 12->27         started        29 rundll32.exe 1 12->29         started        31 tasksche.exe 1 33 14->31         started        110 192.168.2.102 unknown unknown 16->110 112 192.168.2.103 unknown unknown 16->112 114 98 other IPs or domains 16->114 128 Connects to many different private IPs via SMB (likely to spread or exploit) 16->128 130 Connects to many different private IPs (likely to spread or exploit) 16->130 33 tasksche.exe 20->33         started        signatures5 process6 signatures7 35 rundll32.exe 22->35         started        146 Drops executables to the windows directory (C:\Windows) and starts them 24->146 37 mssecsvc.exe 1 24->37         started        148 Antivirus detection for dropped file 31->148 150 Multi AV Scanner detection for dropped file 31->150 152 Machine Learning detection for dropped file 31->152 41 icacls.exe 1 31->41         started        43 attrib.exe 1 31->43         started        154 Found Tor onion address 33->154 156 Uses cmd line tools excessively to alter registry or file data 33->156 45 icacls.exe 1 33->45         started        47 attrib.exe 1 33->47         started        process8 file9 49 mssecsvc.exe 1 35->49         started        106 C:\WINDOWS\qeriuwjhrf (copy), PE32 37->106 dropped 144 Drops executables to the windows directory (C:\Windows) and starts them 37->144 52 tasksche.exe 2 37->52         started        55 conhost.exe 41->55         started        57 conhost.exe 43->57         started        59 conhost.exe 45->59         started        61 conhost.exe 47->61         started        signatures10 process11 file12 104 C:\Windows\tasksche.exe, PE32 49->104 dropped 63 tasksche.exe 36 49->63         started        140 Found Tor onion address 52->140 142 Uses cmd line tools excessively to alter registry or file data 52->142 67 tasksche.exe 52->67         started        69 attrib.exe 52->69         started        71 icacls.exe 52->71         started        signatures13 process14 file15 108 C:\ProgramData\dsvqhifq359\tasksche.exe, PE32 63->108 dropped 116 Detected Wannacry Ransomware 63->116 118 Antivirus detection for dropped file 63->118 120 Multi AV Scanner detection for dropped file 63->120 122 Machine Learning detection for dropped file 63->122 73 tasksche.exe 63->73         started        76 icacls.exe 1 63->76         started        78 attrib.exe 1 63->78         started        124 Found Tor onion address 67->124 126 Uses cmd line tools excessively to alter registry or file data 67->126 80 icacls.exe 1 67->80         started        82 attrib.exe 1 67->82         started        84 conhost.exe 69->84         started        86 conhost.exe 71->86         started        signatures16 process17 signatures18 158 Found Tor onion address 73->158 160 Uses cmd line tools excessively to alter registry or file data 73->160 88 icacls.exe 1 73->88         started        90 attrib.exe 1 73->90         started        92 conhost.exe 76->92         started        94 conhost.exe 78->94         started        96 conhost.exe 80->96         started        98 conhost.exe 82->98         started        process19 process20 100 conhost.exe 88->100         started        102 conhost.exe 90->102         started       
Threat name:
Win32.Ransomware.WannaCry
Status:
Malicious
First seen:
2017-05-22 15:23:02 UTC
File Type:
PE (Dll)
Extracted files:
5
AV detection:
36 of 38 (94.74%)
Threat level:
  5/5
Result
Malware family:
wannacry
Score:
  10/10
Tags:
family:wannacry defense_evasion discovery ransomware worm
Behaviour
Modifies data under HKEY_USERS
Suspicious behavior: CmdExeWriteProcessMemorySpam
Suspicious use of WriteProcessMemory
Views/modifies file attributes
System Location Discovery: System Language Discovery
Drops file in Windows directory
Drops file in System32 directory
Creates a large amount of network flows
File and Directory Permissions Modification: Windows File and Directory Permissions Modification
Executes dropped EXE
Modifies file permissions
Contacts a large (3346) amount of remote hosts
Wannacry
Wannacry family
Unpacked files
SH256 hash:
331e14a6594b700b6167690430c9da72fee72d408dd1b8c5cb155c0199033d0a
MD5 hash:
79409b6f48460807480e4a574312d85f
SHA1 hash:
5d9f64ccf13081441f2785a535e02312236445d9
Detections:
WannaCry Win32_Ransomware_WannaCry ransomware_windows_wannacry WannaCry_Ransomware
SH256 hash:
9fc72255d127146ec06164ce6857e096cfa2f6d29c737c052d7daa5c31f6d40c
MD5 hash:
a75a57a712300662ce3ff1447a0c4805
SHA1 hash:
2776c0c48702b330435294a570d75eadd1109c30
Detections:
WannaCry Win32_Ransomware_WannaCry ransomware_windows_wannacry WannaCry_Ransomware WannaCry_Ransomware_Gen
SH256 hash:
5d7fa45d2fcb10893ee5bdbfc4b16bdeeffd34aa5791331332a8bbb1015cb63b
MD5 hash:
07a5d326b196d166dc0618e7c25ac2b5
SHA1 hash:
7a23e2ef0682cfb8813a27dc559da187f9e178f5
Detections:
WannaCry
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Armadillov1xxv2xx
Author:malware-lu
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:NET
Author:malware-lu
Rule name:SUSP_Imphash_Mar23_2
Author:Arnim Rupp (https://github.com/ruppde)
Description:Detects imphash often found in malware samples (Zero hits with with search for 'imphash:x p:0' on Virustotal)
Reference:Internal Research
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:WannaCry_Ransomware
Author:Florian Roth (Nextron Systems) (with the help of binar.ly)
Description:Detects WannaCry Ransomware
Reference:https://goo.gl/HG2j5T

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessA
KERNEL32.dll::CloseHandle
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileA

Comments