🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a732dfc06e3c406c0efb385c7ca51d4c4be76faabddf4fcb5185115eb74fbc96. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WannaCry


Vendor detections: 14


Intelligence 14 IOCs YARA 10 File information Comments

SHA256 hash: a732dfc06e3c406c0efb385c7ca51d4c4be76faabddf4fcb5185115eb74fbc96
SHA3-384 hash: af46e4e29c297746bf15e2fdfee7525b22da017631933762c232b0f6deb7aa48f9b8f21de24dfc4e46089597a38a3313
SHA1 hash: fa1794c45c893ae6c4e1784b93c56ce8283b634b
MD5 hash: 50277f214d447d0890c53466fb68af0e
humanhash: white-bluebird-mobile-floor
File name:50277f214d447d0890c53466fb68af0e
Download: download sample
Signature WannaCry
File size:5'267'459 bytes
First seen:2025-01-15 15:07:39 UTC
Last seen:2025-01-15 15:31:41 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 2e5708ae5fed0403e8117c645fb23e5b (1'124 x WannaCry, 7 x Worm.Virut, 2 x Expiro)
ssdeep 98304:M8qPoBhz1aRxcSUDk36SANKx/ag6iVp2H:M8qPe1Cxcxk3ZA0Yu4H
Threatray 1'057 similar samples on MalwareBazaar
TLSH T1E236AD42A3F95618F2F63F3059BA16706F7ABC92AD7DC60E1280516E1DB1E40CDB1B63
TrID 41.1% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
22.2% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
11.8% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
7.5% (.EXE) Win64 Executable (generic) (10522/11/4)
4.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
Magika pebin
Reporter mentality
Tags:dll exe WannaCry

Intelligence


File Origin
# of uploads :
2
# of downloads :
162
Origin country :
CA CA
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
wannacry madi
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
apt cmd crypto crypto explorer lolbin microsoft_visual_cc overlay overlay packed ransomware remote smb wannacry
Result
Threat name:
Wannacry
Detection:
malicious
Classification:
rans.expl.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Detected Wannacry Ransomware
Drops executables to the windows directory (C:\Windows) and starts them
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Wannacry ransomware
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1591979 Sample: Qj9gUbJBkY.dll Startdate: 15/01/2025 Architecture: WINDOWS Score: 100 50 Malicious sample detected (through community Yara rule) 2->50 52 Antivirus / Scanner detection for submitted sample 2->52 54 Multi AV Scanner detection for dropped file 2->54 56 4 other signatures 2->56 9 loaddll32.exe 1 2->9         started        11 mssecsvc.exe 2->11         started        process3 dnsIp4 15 cmd.exe 1 9->15         started        17 rundll32.exe 9->17         started        20 conhost.exe 9->20         started        22 rundll32.exe 1 9->22         started        42 192.168.2.102 unknown unknown 11->42 44 192.168.2.103 unknown unknown 11->44 46 98 other IPs or domains 11->46 68 Connects to many different private IPs via SMB (likely to spread or exploit) 11->68 70 Connects to many different private IPs (likely to spread or exploit) 11->70 signatures5 process6 signatures7 24 rundll32.exe 15->24         started        48 Drops executables to the windows directory (C:\Windows) and starts them 17->48 26 mssecsvc.exe 1 17->26         started        process8 file9 30 mssecsvc.exe 1 24->30         started        38 C:\WINDOWS\qeriuwjhrf (copy), PE32 26->38 dropped 66 Drops executables to the windows directory (C:\Windows) and starts them 26->66 33 tasksche.exe 26->33         started        signatures10 process11 file12 40 C:\Windows\tasksche.exe, PE32 30->40 dropped 35 tasksche.exe 30->35         started        process13 signatures14 58 Detected Wannacry Ransomware 35->58 60 Antivirus detection for dropped file 35->60 62 Multi AV Scanner detection for dropped file 35->62 64 Machine Learning detection for dropped file 35->64
Threat name:
Win32.Ransomware.WannaCry
Status:
Malicious
First seen:
2020-09-21 14:21:33 UTC
File Type:
PE (Dll)
Extracted files:
4
AV detection:
36 of 38 (94.74%)
Threat level:
  5/5
Result
Malware family:
wannacry
Score:
  10/10
Tags:
family:wannacry discovery ransomware worm
Behaviour
Modifies data under HKEY_USERS
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Drops file in Windows directory
Drops file in System32 directory
Creates a large amount of network flows
Executes dropped EXE
Contacts a large (3215) amount of remote hosts
Wannacry
Wannacry family
Unpacked files
SH256 hash:
001e463b2fb688fe072302c378a4cb4f9e81fe6ccded9c4a76e374b32cf68bc5
MD5 hash:
0e0079234d2c35bee919a0dc9ba7828a
SHA1 hash:
e6dcd048e13ba0fcc5d3e701014bdeae05f48995
SH256 hash:
d310fd32a780d2978e5f34bd70a309661ccd9a2df9996357a02a871ff35a131a
MD5 hash:
c6e92c6ed2e9e493e490001c4d4c8996
SHA1 hash:
18f29ac7b184ae98ee1c0f798723b6f48485c4b8
Detections:
WannaCry IcedID_init_loader Win32_Ransomware_WannaCry ransomware_windows_wannacry WannaCry_Ransomware
SH256 hash:
0a54aad986469f3015c019e4fcd5cf0d27a6f98688e272c67ee8b862b3fd18f3
MD5 hash:
37e83c242780259951e18e4492b93594
SHA1 hash:
26daa14a22083417b6e294f7a20ebd666c6fcdd1
Detections:
WannaCry IcedID_init_loader Win32_Ransomware_WannaCry ransomware_windows_wannacry WannaCry_Ransomware WannaCry_Ransomware_Gen
SH256 hash:
a732dfc06e3c406c0efb385c7ca51d4c4be76faabddf4fcb5185115eb74fbc96
MD5 hash:
50277f214d447d0890c53466fb68af0e
SHA1 hash:
fa1794c45c893ae6c4e1784b93c56ce8283b634b
Detections:
WannaCry
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:APT_DustSquad_PE_Nov19_2
Author:Arkbird_SOLG
Description:Detection Rule for APT DustSquad campaign Nov19
Reference:https://twitter.com/Rmy_Reserve/status/1197448735422238721
Rule name:Armadillov1xxv2xx
Author:malware-lu
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:IcedID_init_loader
Author:@bartblaze
Description:Identifies IcedID (stage 1 and 2, initial loaders).
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:SUSP_Imphash_Mar23_2
Author:Arnim Rupp (https://github.com/ruppde)
Description:Detects imphash often found in malware samples (Zero hits with with search for 'imphash:x p:0' on Virustotal)
Reference:Internal Research
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:WannaCry_Ransomware
Author:Florian Roth (with the help of binar.ly)
Description:Detects WannaCry Ransomware
Reference:https://goo.gl/HG2j5T
Rule name:WannaCry_Ransomware
Author:Florian Roth (Nextron Systems) (with the help of binar.ly)
Description:Detects WannaCry Ransomware
Reference:https://goo.gl/HG2j5T

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessA
KERNEL32.dll::CloseHandle
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileA

Comments