🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d388424c0a34f9d700cbafb96839f09a945d12d34b457cd64b4e82738fcf8801. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WannaCry


Vendor detections: 13


Intelligence 13 IOCs YARA 7 File information Comments

SHA256 hash: d388424c0a34f9d700cbafb96839f09a945d12d34b457cd64b4e82738fcf8801
SHA3-384 hash: e9164c2a0af6d8b4b03b2fc3aae1dfe10c2d969cdc71161736496831cb5f8405aadc6509f20bd6193ee4c82bcb490206
SHA1 hash: f605c351811668526456a1832bad7973605e2af1
MD5 hash: 7d4c4401e1fe00bc5f751ddfabcf0e8d
humanhash: finch-undress-paris-eleven
File name:7d4c4401e1fe00bc5f751ddfabcf0e8d
Download: download sample
Signature WannaCry
File size:5'267'459 bytes
First seen:2025-01-14 19:59:34 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 2e5708ae5fed0403e8117c645fb23e5b (1'124 x WannaCry, 7 x Worm.Virut, 2 x Expiro)
ssdeep 49152:SnAQqMSPbcBVQej/1INRx+TSqTdX1HkQo6SAARdhHE:+DqPoBhz1aRxcSUDk36SAEdhk
TLSH T14236F119E7F4C274F05A9530A1B70EBE5635FC808AE24A4F1654FD5E3D73A28DEA3A01
TrID 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.7% (.EXE) Win64 Executable (generic) (10522/11/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
Reporter mentality
Tags:dll exe WannaCry

Intelligence


File Origin
# of uploads :
1
# of downloads :
167
Origin country :
CA CA
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
wannacry madi
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd crypto crypto lolbin microsoft_visual_cc overlay ransomware smb wannacry wannacrypt wannacryptor
Result
Threat name:
Wannacry
Detection:
malicious
Classification:
rans.expl.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Detected Wannacry Ransomware
Drops executables to the windows directory (C:\Windows) and starts them
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Tries to download HTTP data from a sinkholed server
Yara detected Wannacry ransomware
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1591285 Sample: 87c6RORO31.dll Startdate: 14/01/2025 Architecture: WINDOWS Score: 100 43 www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com 2->43 61 Tries to download HTTP data from a sinkholed server 2->61 63 Suricata IDS alerts for network traffic 2->63 65 Malicious sample detected (through community Yara rule) 2->65 67 6 other signatures 2->67 9 loaddll32.exe 1 2->9         started        11 mssecsvc.exe 2->11         started        signatures3 process4 dnsIp5 15 rundll32.exe 9->15         started        17 rundll32.exe 9->17         started        20 cmd.exe 1 9->20         started        22 conhost.exe 9->22         started        45 192.168.2.102 unknown unknown 11->45 47 192.168.2.103 unknown unknown 11->47 49 98 other IPs or domains 11->49 77 Connects to many different private IPs via SMB (likely to spread or exploit) 11->77 79 Connects to many different private IPs (likely to spread or exploit) 11->79 signatures6 process7 signatures8 24 mssecsvc.exe 7 15->24         started        59 Drops executables to the windows directory (C:\Windows) and starts them 17->59 28 mssecsvc.exe 7 17->28         started        30 rundll32.exe 1 20->30         started        process9 file10 37 C:\Windows\tasksche.exe, PE32 24->37 dropped 69 Antivirus detection for dropped file 24->69 71 Multi AV Scanner detection for dropped file 24->71 73 Machine Learning detection for dropped file 24->73 32 tasksche.exe 24->32         started        39 C:\WINDOWS\qeriuwjhrf (copy), PE32 28->39 dropped 75 Drops executables to the windows directory (C:\Windows) and starts them 28->75 35 tasksche.exe 28->35         started        41 C:\Windows\mssecsvc.exe, PE32 30->41 dropped signatures11 process12 signatures13 51 Detected Wannacry Ransomware 32->51 53 Antivirus detection for dropped file 32->53 55 Multi AV Scanner detection for dropped file 32->55 57 Machine Learning detection for dropped file 32->57
Threat name:
Win32.Ransomware.WannaCry
Status:
Malicious
First seen:
2023-02-26 11:11:38 UTC
File Type:
PE (Dll)
Extracted files:
4
AV detection:
36 of 38 (94.74%)
Threat level:
  5/5
Result
Malware family:
wannacry
Score:
  10/10
Tags:
family:wannacry discovery ransomware worm
Behaviour
Modifies data under HKEY_USERS
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Drops file in Windows directory
Drops file in System32 directory
Creates a large amount of network flows
Executes dropped EXE
Contacts a large (3247) amount of remote hosts
Wannacry
Wannacry family
Unpacked files
SH256 hash:
f38ac7e13323086989e78780c6785c664de6392db19779e96ef30bdb769d4ac6
MD5 hash:
087be2d4c652dd35156789e4044a5815
SHA1 hash:
bb9e590891e467a28a511e491e082f88c9bca1ef
Detections:
WannaCry Win32_Ransomware_WannaCry ransomware_windows_wannacry WannaCry_Ransomware
SH256 hash:
1f1fc0cf6f281dc3ec78c86fb3e42986f5a769af28e2c27512bb557680f507ff
MD5 hash:
47fe23c22356c88404a7b0b9a508effb
SHA1 hash:
b210745a7391b7d1b9169e1594239bbecdc76ba2
Detections:
WannaCry Win32_Ransomware_WannaCry ransomware_windows_wannacry WannaCry_Ransomware WannaCry_Ransomware_Gen
SH256 hash:
d388424c0a34f9d700cbafb96839f09a945d12d34b457cd64b4e82738fcf8801
MD5 hash:
7d4c4401e1fe00bc5f751ddfabcf0e8d
SHA1 hash:
f605c351811668526456a1832bad7973605e2af1
Detections:
WannaCry
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Armadillov1xxv2xx
Author:malware-lu
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:SUSP_Imphash_Mar23_2
Author:Arnim Rupp (https://github.com/ruppde)
Description:Detects imphash often found in malware samples (Zero hits with with search for 'imphash:x p:0' on Virustotal)
Reference:Internal Research
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:WannaCry_Ransomware
Author:Florian Roth (Nextron Systems) (with the help of binar.ly)
Description:Detects WannaCry Ransomware
Reference:https://goo.gl/HG2j5T

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessA
KERNEL32.dll::CloseHandle
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileA

Comments