MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab31092c90dbe2968d95d0ce959365ecdc49ba4384c5f794ebcfb75bab83ab6b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Ransomware.WannaCry


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ab31092c90dbe2968d95d0ce959365ecdc49ba4384c5f794ebcfb75bab83ab6b
SHA3-384 hash: 1e91574b9b739690a4399081672e4a282e56bd22bccf7da962a8811cf88cce2fc12f2bc92f42f1bca00b1a06979f1a51
SHA1 hash: 227e23512f24d046fbb1a7fef84cb369845b4408
MD5 hash: e0920ea44b12ca7e37ee5ee88e9e29ff
humanhash: magnesium-michigan-foxtrot-cardinal
File name:E0920EA44B12CA7E37EE5EE88E9E29FF
Download: download sample
Signature Ransomware.WannaCry
File size:33'549'739 bytes
First seen:2022-11-30 15:56:03 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: infected
ssdeep 786432:V/CyJ98/pUEUjJprn7YTB/jddy/Dhrbe5uGYjc:VTW+jJpQdC1zG0c
TLSH T15777330549D27C73E5EBBBD437AEDB75124031C6E08056E7EA77AB5C06230C2ADCDAA1
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter EstisRemiel
Tags:Ransomware.WannaCry zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
377
Origin country :
HK HK
File Archive Information

This file archive contains 56 file(s), sorted by their relevance:

File name:smb-gab_1g0l.zip
File size:31'157 bytes
SHA256 hash: 35145343e17d8192da80e025e6a03f257758997dac1e24debb4fda1eeef3193d
MD5 hash: fc71102b44ee6d101320d911fb9c723f
MIME type:application/zip
Signature Ransomware.WannaCry
File name:146581f0b3fbe00026ee3ebe68797b0e57f39d1d8aecc99fdc3290e9cfadc4fc.zip
File size:131'363 bytes
SHA256 hash: a307a9e165d0bd0a539f5787cfc94c5abffd6f1924ff774452d72acb2a8bcf3a
MD5 hash: c36ed03893b5e85e68ea426c836d95b9
MIME type:application/zip
Signature Ransomware.WannaCry
File name:Pepex-b5.7z
File size:12'394 bytes
SHA256 hash: 0c6c11a76d6352c20c654110dfca2e5df660ee189ef1b1d95152a5f3ecf7a354
MD5 hash: 40071e143705bebee0095895210b7651
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:smb-3kn32w1v.zip
File size:222'169 bytes
SHA256 hash: bb8f0b0dcaf7a656a24b6ab92bb693a9b0231ba797eb11aabdfbe39cd0504ebb
MD5 hash: f1e80d247f862752f1db9fd16411f4f8
MIME type:application/zip
Signature Ransomware.WannaCry
File name:786ab616239814616642ba4438df78a9.zip
File size:33'295 bytes
SHA256 hash: 7054f0fc4f068acc20f1ac31c46457bcba08c08a10a781372b7bd3b8c6591caa
MD5 hash: c992914a447bd4b3ee3aff2acbc12089
MIME type:application/zip
Signature Ransomware.WannaCry
File name:8200755cbedd6f15eecd8207eba534709a01957b172d7a051b9cc4769ddbf233.zip
File size:1'398'634 bytes
SHA256 hash: 0b60463468b744f72f50c20f7f8e5ad0801e86123f22d770b8cef64c7ef53caa
MD5 hash: a51916afc1509fc0cdad7cbb6ec38521
MIME type:application/zip
Signature Ransomware.WannaCry
File name:cf8533849ee5e82023ad7adbdbd6543cb6db596c53048b1a0c00b3643a72db30.zip
File size:4'887'694 bytes
SHA256 hash: 66dcdc7e16a2ab92f41580667c5a7e9c8b22da293290fd198cfb2aa004292cba
MD5 hash: 5cd92c0bf1c10da824e6bf3bbd0fb27b
MIME type:application/zip
Signature Ransomware.WannaCry
File name:fa73963e516d9be0cc8ae60d7a1cd8bc6ac01f464b2c772ddb97739d4d1ff38d.zip
File size:68'248 bytes
SHA256 hash: 495a459881560883953012cec282045c1f388aef5f367c18d1e211adbf3e04ff
MD5 hash: 588172ebd486fb3d8736e213228b51c4
MIME type:application/zip
Signature Ransomware.WannaCry
File name:smb-ncqut0ao.7z
File size:39'434 bytes
SHA256 hash: 24dd7e5726cca55aa41a3a93dc5b26c667221f26d6a4f9a067d9abdacdcb7eb1
MD5 hash: 9f6dde4ca0e588962881f386e82df770
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:smb-fvd4o59p.zip
File size:581'103 bytes
SHA256 hash: 7bfff759d3af458f238aee319e7fda631586e53a440086348656c454ba52ff96
MD5 hash: 2fbb6354a556b84d844c2bba947de526
MIME type:application/zip
Signature Ransomware.WannaCry
File name:smb-__lltt96.7z
File size:738'538 bytes
SHA256 hash: 2af07ba65a6ed083b72678224e3f74353400410888e40db610de02713051767c
MD5 hash: fd7489a11e82ddaa42097e7bf3e00f58
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:smb-w34bi9ly.tmp
File size:14'848 bytes
SHA256 hash: 93079c69a79d0d66c50b5750cacbb3a13f0883488235bd3f6b8ca0292da0ed86
MD5 hash: 64b4345a946bc9388412fedd53fb21cf
MIME type:application/x-dosexec
Signature Ransomware.WannaCry
File name:3Rd-LevelHexEatracted.7z
File size:38'346 bytes
SHA256 hash: c6d06e65924c10cb88343addeb1fd952e7411fec2634e4a50f2de9bbbf0c1571
MD5 hash: 813670abcfa5b0e5804ab541efc2abd7
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:smb-7teux2sm.zip
File size:31'770 bytes
SHA256 hash: 542189e321cb0c3a7d0b25ebdb4d9926e0770e49c30791264855b0b9152a95ab
MD5 hash: c28e52d6f37f64d79d4f43fbde9c300a
MIME type:application/zip
Signature Ransomware.WannaCry
File name:4c1dc737915d76b7ce579abddaba74ead6fdb5b519a1ea45308b8c49b950655c (1)
File size:806'912 bytes
SHA256 hash: 4c1dc737915d76b7ce579abddaba74ead6fdb5b519a1ea45308b8c49b950655c
MD5 hash: a92f13f3a1b3b39833d3cc336301b713
MIME type:application/x-dosexec
Signature Ransomware.WannaCry
File name:5b2aa53001c0884222bebf931b8235e80cc798c46e3e28c5a4026ccd5590fabf.zip
File size:68'255 bytes
SHA256 hash: 16922b999d861d5f0755bd4ce134cc71af6308fee16989fa98e449fc9fa0433a
MD5 hash: 420d54d24c9998471ac78fc0a703fb35
MIME type:application/zip
Signature Ransomware.WannaCry
File name:49cccd30a564410d1f9bbce89fa15890.zip
File size:46'137 bytes
SHA256 hash: 97e3fb3fb0b77ba5ecce0d1d10d6408e3316baff66d7893605aab190578bafa1
MD5 hash: 857e4709e6c467c1885f157cb7b1d0d7
MIME type:application/zip
Signature Ransomware.WannaCry
File name:02ca4397da55b3175aaa1ad2c99981e792f66151.zip
File size:1'469'909 bytes
SHA256 hash: fb6e7c535103161ad907f9ce892ca0f33bd07e4e49c21834c3880212dbd5e053
MD5 hash: 473eca3ac6347266138667622d78ea18
MIME type:application/zip
Signature Ransomware.WannaCry
File name:smb-id9dl67p.bin
File size:71'168 bytes
SHA256 hash: 32e73d18c8fe88483018ada54dd1a15625e8bc929ab0b640a7eab70135dca9a6
MD5 hash: f7f6c7c1c7681fb92690b6566e893e69
MIME type:application/x-dosexec
Signature Ransomware.WannaCry
File name:ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa.bin.zip
File size:3'481'574 bytes
SHA256 hash: 219f4e1e62fa50d0e407a6ae5c49344e1a888f97e7131be118d6c312217e69cc
MD5 hash: 0ee82d7d2714e2ddf579080c5460fea3
MIME type:application/zip
Signature Ransomware.WannaCry
File name:smb-0e89k3id.zip
File size:78'740 bytes
SHA256 hash: 060b8a227885388a7b9f821807e9c58555456a15579d380eb47d9a3c362b85ba
MD5 hash: 6433f54abf4e649ae5c076da97252fd6
MIME type:application/zip
Signature Ransomware.WannaCry
File name:149979213411fcac20f7cbc1a26e1521b80073aff05d4c0f967046ef5f23b13a.zip
File size:18'942 bytes
SHA256 hash: 043bc5f8da479077084c4ec75e5c1182254366d135373059906bb6fed0bf5148
MD5 hash: e366fda31628c5d9da83cfcdb7ac9fc4
MIME type:application/zip
Signature Ransomware.WannaCry
File name:smb-82rfim2h.zip
File size:98'889 bytes
SHA256 hash: bda40b09b1c865f03ebdf7ae738fe5def09b5717e9738016c78a92530d77f572
MD5 hash: 028495b2895149594da760f7b9baa5df
MIME type:application/zip
Signature Ransomware.WannaCry
File name:Pepex-M2.7z
File size:120'810 bytes
SHA256 hash: b1ea7e47ed79202977abf73f1c53929d90a351258dc417a9b78ecc77ac5184ec
MD5 hash: 1defe06c41b7d2fecc8e2cdc20dd22b1
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:697158bcade7373ccc9e52ea1171d780988fc845d2b696898654e18954578920.zip
File size:3'150'985 bytes
SHA256 hash: d30cd1e5c765f6cb2ddfc16c8f1611ef575ef6b8fd7030930bca9433f8edbe25
MD5 hash: 40879d7587eed9df399dc5ec0e18d305
MIME type:application/zip
Signature Ransomware.WannaCry
File name:README.md
File size:990 bytes
SHA256 hash: d1279d1216c61b62e32defadaa8bacb8ff3c01fe2aaab594e9ed3ce609abf1a6
MD5 hash: 421879896b87f74e3c82870380931f65
MIME type:text/plain
Signature Ransomware.WannaCry
File name:29c7e87350cb03428fc108b03856095b.7z
File size:73'098 bytes
SHA256 hash: 1348f7a005e008bce6dd05e9e747f7f12190994d3ec15379489c169269ff2a60
MD5 hash: 0ee1c795623b54eff141cf1be74c3776
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:smb-onil0o36.zip
File size:31'886 bytes
SHA256 hash: 7e829dee117892c06a095c76c0c6d210550bd3372300d26d96b141a2e3629d5f
MD5 hash: 8cf0853fd2b7aef2cb1495f6b9ce5117
MIME type:application/zip
Signature Ransomware.WannaCry
File name:027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745-20170707033827.zip
File size:314'127 bytes
SHA256 hash: 2416260eadf0d674f89097a2d29083d7db3fcd2ed6758849c984cc325baaa0a8
MD5 hash: f865edbb0f45c47b5c85ebd796290b51
MIME type:application/zip
Signature Ransomware.WannaCry
File name:smb-e7_udot9.7z
File size:10'666 bytes
SHA256 hash: fd39137c11daf4d8c11cd8694e25573eb840db8e9f7f17266708b49d955c2d4c
MD5 hash: b26de71f61fa6530ee2b614d1b1c1d40
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:b17911ddeab973db51362721c940d882.7z
File size:72'922 bytes
SHA256 hash: e36cfd96cc919072ed8f055e807662e6d7239908e340a0a25d57569d0b7028ea
MD5 hash: c05215923eba4bd33e65d23dc144b8cd
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:Pepex-M3.7z
File size:367'882 bytes
SHA256 hash: c1f3339c69d76d891d01564f23eedf195b2c82ef1bea7a015865523c6fac78cc
MD5 hash: e9679d99667820ca67f4050234b65168
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:smb-b4tq2hti.zip
File size:1'004'632 bytes
SHA256 hash: 853af15aa9a2e12e88e80bbf1e78cb9650c1152aa9f75e990fdd7b6a6d38ca05
MD5 hash: 142ae9cf53dd0990ded59a0ab4f8e32b
MIME type:application/zip
Signature Ransomware.WannaCry
File name:smb-37n0gip7.7z
File size:26'634 bytes
SHA256 hash: ca7cb2bd87b622738cd898710d69bfd79e3b7602f3395e9f2c72f9ea49b15cb5
MD5 hash: 856f7d5760486decc69dfd962dcb4839
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:satan.zip
File size:146'558 bytes
SHA256 hash: 595e2825095b12ddfba4ee6f98f4f6cb1ff1fbc37a3b3191b2fc203d486ba163
MD5 hash: d309e1391579364a758c67fafb3b6e8a
MIME type:application/zip
Signature Ransomware.WannaCry
File name:Pepex-b4.7z
File size:12'330 bytes
SHA256 hash: 18d0b7477f053b1ac5a164c1975c70edd76f96586b514e2ea70f4cb42ae1fce5
MD5 hash: b837c03fafb47e6b97aeb6b81b650e94
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:smb-1bd_c8y5.7z
File size:67'962 bytes
SHA256 hash: 06a8370354d3fc8651382c54b59a8cb71be0fd34b079b7d4109efe9a1df35370
MD5 hash: 86f5d7a7d05708668a28c87600f1b71f
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:414af3620d0843f07318a2a33f65667d
File size:92 bytes
SHA256 hash: 2001a8807340683d73fb5631d308c305972637e0765f382a4854d86c82c9d9bf
MD5 hash: 414af3620d0843f07318a2a33f65667d
MIME type:application/octet-stream
Signature Ransomware.WannaCry
File name:smb-7rwkaozq.zip
File size:29'134 bytes
SHA256 hash: cecfc61b99a62ef90e9fd30ba1c51e86a7448f32f417c3e88632b85b6e6b19d5
MD5 hash: 8fca15bcc3db34d88015a1293f14d1a4
MIME type:application/zip
Signature Ransomware.WannaCry
File name:86e0eac8c5ce70c4b839ef18af5231b5f92e292b81e440193cdbdc7ed108049f.zip
File size:283'973 bytes
SHA256 hash: c3ae24dd6b0e570611ea13b4f24e3b50ce0c6906c9ce3ba72105e4c91a660b1c
MD5 hash: 57b74cedb501ecda4ffa647d051ed167
MIME type:application/zip
Signature Ransomware.WannaCry
File name:grandcab.bin
File size:496'128 bytes
SHA256 hash: 233437b647f9482a8a3ba51d0af69039bb58fb48609704a39db1f709a0e6aca6
MD5 hash: 97a449fed7d800a8a635592605ff8a67
MIME type:application/x-dosexec
Signature Ransomware.WannaCry
File name:smb-d1674sc2.zip
File size:641'729 bytes
SHA256 hash: 5104a641086328185e0d41db0dffc8f16a68e06c459d77c377e510c4560c2362
MD5 hash: f398754395031016fad88823e457fa0c
MIME type:application/zip
Signature Ransomware.WannaCry
File name:Pepex-b7.7z
File size:12'330 bytes
SHA256 hash: 94015caa3459ed6eb03564b9b231ed7dead63c230ac9bef6fbf9611d6364174c
MD5 hash: b5bb3b301ac0dddc2a94087ce506eaf8
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:1d4322dbad293847de14eca09bee5056eaede7ce178490e101642bf1f5875e37.zip
File size:19'904 bytes
SHA256 hash: 58038ba64962ce0ba94e0e0c4dc0356e607d5a1a6aaa64662eb6731cb7e87ba5
MD5 hash: df4e3d17b109e81cff23d215ad8366dd
MIME type:application/zip
Signature Ransomware.WannaCry
File name:mssecsvc_41b5ba4bf74e65845fa8c9861ca34508.zip
File size:3'595'622 bytes
SHA256 hash: c8c53f25f6118bb1645a12b198fe1cb8b99ceb417df5a1d0a210ac720fba33de
MD5 hash: 6d807a28556c844e807fee5bec250f79
MIME type:application/zip
Signature Ransomware.WannaCry
File name:022aeb126d2d80e683f7f2a3ee920874.zip
File size:31'926 bytes
SHA256 hash: c31f8475394784c03c9fea88b77c2056e892fe39adc38347bc56414e21a2e1cf
MD5 hash: 75d14a5e3819d1545bf4a81b36cffe66
MIME type:application/zip
Signature Ransomware.WannaCry
File name:smb-5ebgzza0.7z
File size:1'100'522 bytes
SHA256 hash: ad20ae0224b45bd5348cfcd12ebd7167ced48efcc0d363926714017263dee8e3
MD5 hash: 12fe4cffc1b16cbe363df071e266bc75
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:46c7424076e7421298191c1e439c7ed8
File size:92 bytes
SHA256 hash: c0ee36b8ee8fa41c1c9091c510b30a2a3ce2ae1c753af7616f89589ad115a325
MD5 hash: 46c7424076e7421298191c1e439c7ed8
MIME type:application/octet-stream
Signature Ransomware.WannaCry
File name:Pepex-b3.7z
File size:12'394 bytes
SHA256 hash: ff6692072587ab0b04a79586242b5cb96ecc807063abfeadd44babe7176e1d02
MD5 hash: 034e0d68231f21a749c590a8f00558aa
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:mssecsvc_0c694193ceac8bfb016491ffb534eb7c.zip
File size:3'599'084 bytes
SHA256 hash: 1bd50736a69035c57577b3534a88864b79b236b5b0e265051c41c150dd48ab81
MD5 hash: c429ae0c4e3b0088968d6d74dc90e50d
MIME type:application/zip
Signature Ransomware.WannaCry
File name:Pepex-M.7z
File size:364'250 bytes
SHA256 hash: 00521f3d6f2c7c75972591ddc8549ddd535af8f8ca31957425f788624305c17d
MD5 hash: 50bb99047704992893577554cb475e29
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:smb-5cgc70g1.7z
File size:199'098 bytes
SHA256 hash: 9f7a185d2633f9c279344540cb17c3802f4bd4e51c24470d8f35cc368dc46c31
MD5 hash: 311170a71a2fe1560198d3f0474de1d9
MIME type:application/x-7z-compressed
Signature Ransomware.WannaCry
File name:32f24601153be0885f11d62e0a8a2f0280a2034fc981d8184180c5d3b1b9e8cf.bin
File size:3'723'264 bytes
SHA256 hash: 32f24601153be0885f11d62e0a8a2f0280a2034fc981d8184180c5d3b1b9e8cf
MD5 hash: d5dcd28612f4d6ffca0cfeaefd606bcf
MIME type:application/x-dosexec
Signature Ransomware.WannaCry
File name:smb-b_8ti77_.zip
File size:53'649 bytes
SHA256 hash: 370dbbcf8dcdeacf63a821d3a006c01da79fed3c309f88ec3c8b7764924645da
MD5 hash: 99ec9f463bdedd73f4cd4074ac369ba9
MIME type:application/zip
Signature Ransomware.WannaCry
File name:smb-zlm7d8hi.tmp
File size:122'880 bytes
SHA256 hash: 55120454e6afa0416c07b905d38434768542cd93b36279bcdbc0a894854b7d11
MD5 hash: 558b05e59b333aef5224e1da7d03f2e9
MIME type:application/x-dosexec
Signature Ransomware.WannaCry
File name:smb-e0y16y2p.bin
File size:368'640 bytes
SHA256 hash: 7472fde428c121d359c24053910c77bc35a1581cafcae279088b608a11070610
MD5 hash: 509b46bd594e2b5cb48aaf07784d3a00
MIME type:application/x-dosexec
Signature Ransomware.WannaCry
Vendor Threat Intelligence
Gathering data
Gathering data
Threat name:
Win32.Ransomware.GandCrab
Status:
Malicious
First seen:
2022-11-30 15:58:34 UTC
File Type:
Binary (Archive)
Extracted files:
257
AV detection:
18 of 41 (43.90%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments