🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9b4fc5b0f8bbf8127f324b77a8df5e4aba915f2baae8e50293de0312b884491. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WannaCry


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: c9b4fc5b0f8bbf8127f324b77a8df5e4aba915f2baae8e50293de0312b884491
SHA3-384 hash: e84b13c32d5c999271161359f9b0dae72b6c7b7a4919c14f763ff359928fa44b2fd92c3ec661c601292f9353217193d6
SHA1 hash: afc4416c04bab7aaf10b379de21cef19e7ac7c06
MD5 hash: 1bca854b6c30584fa8957767ce029569
humanhash: hydrogen-october-dakota-princess
File name:c9b4fc5b0f8bbf8127f324b77a8df5e4aba915f2baae8e50293de0312b884491
Download: download sample
Signature WannaCry
File size:1'562'226 bytes
First seen:2022-10-12 10:00:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 24576:tihdmMJdhAdlv/jkQg6eX6SASkvdhAdlvm:9MJdhMv/jkQo6SAFdhMvm
TLSH T13A752390B2B1937DD76508B084CA927633E1D1B5AEFF2F42B74449253893F42D3E1B9A
TrID 38.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.5% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
13.0% (.EXE) Win64 Executable (generic) (10523/12/4)
8.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
Reporter petikvx
Tags:WannaCry

Intelligence


File Origin
# of uploads :
1
# of downloads :
308
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd.exe overlay packed ransomware shell32.dll wanna wannacry
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Ransomware.WannaCry
Status:
Malicious
First seen:
2022-10-12 10:01:10 UTC
File Type:
PE (Exe)
AV detection:
25 of 26 (96.15%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Gathering data
Unpacked files
SH256 hash:
c9b4fc5b0f8bbf8127f324b77a8df5e4aba915f2baae8e50293de0312b884491
MD5 hash:
1bca854b6c30584fa8957767ce029569
SHA1 hash:
afc4416c04bab7aaf10b379de21cef19e7ac7c06
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:WannaCry_Ransomware
Author:Florian Roth (with the help of binar.ly)
Description:Detects WannaCry Ransomware
Reference:https://goo.gl/HG2j5T

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments