File name:

wcr-dropbox.exe

Full analysis: https://app.any.run/tasks/3a43c5c3-0ef1-49d5-93b5-369a83c1da30
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: March 15, 2025, 15:34:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
wannacry
ransomware
stealer
autorun-reg
wannacryptor
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

5C7FB0927DB37372DA25F270708103A2

SHA1:

120ED9279D85CBFA56E5B7779FFA7162074F7A29

SHA256:

BE22645C61949AD6A077373A7D6CD85E3FAE44315632F161ADC4C99D5A8E6844

SSDEEP:

3072:Y059femWRwTs/dbelj0X8/j84pcRXPlU3Upt3or4H84lK8PtpLzLsR/EfcZ:+5RwTs/dSXj84mRXPemxdBlPvLzLeZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • WANNACRY mutex has been found

      • wcr-dropbox.exe (PID: 7416)
    • Changes the autorun value in the registry

      • wcr-dropbox.exe (PID: 7416)
    • Actions looks like stealing of personal data

      • wcr-dropbox.exe (PID: 7416)
    • WannaCry Ransomware is detected

      • wcr-dropbox.exe (PID: 7416)
    • Writes a file to the Word startup folder

      • wcr-dropbox.exe (PID: 7416)
    • RANSOMWARE has been detected

      • wcr-dropbox.exe (PID: 7416)
    • Modifies files in the Chrome extension folder

      • wcr-dropbox.exe (PID: 7416)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • wcr-dropbox.exe (PID: 7416)
    • Starts a Microsoft application from unusual location

      • wcr-dropbox.exe (PID: 7416)
      • !WannaDecryptor!.exe (PID: 7564)
    • Executable content was dropped or overwritten

      • wcr-dropbox.exe (PID: 7416)
    • Starts CMD.EXE for commands execution

      • wcr-dropbox.exe (PID: 7416)
    • Executing commands from a ".bat" file

      • wcr-dropbox.exe (PID: 7416)
    • Reads security settings of Internet Explorer

      • !WannaDecryptor!.exe (PID: 7564)
    • The process executes VB scripts

      • cmd.exe (PID: 7436)
  • INFO

    • Checks supported languages

      • wcr-dropbox.exe (PID: 7416)
      • !WannaDecryptor!.exe (PID: 7564)
    • The sample compiled with english language support

      • wcr-dropbox.exe (PID: 7416)
    • Autorun file from Registry key

      • wcr-dropbox.exe (PID: 7416)
    • Reads the computer name

      • wcr-dropbox.exe (PID: 7416)
      • !WannaDecryptor!.exe (PID: 7564)
    • Reads security settings of Internet Explorer

      • cscript.exe (PID: 7488)
    • Reads the machine GUID from the registry

      • wcr-dropbox.exe (PID: 7416)
    • Create files in a temporary directory

      • wcr-dropbox.exe (PID: 7416)
    • Creates files in the program directory

      • wcr-dropbox.exe (PID: 7416)
    • Creates files or folders in the user directory

      • wcr-dropbox.exe (PID: 7416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:07:14 00:03:18+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 28672
InitializedDataSize: 196608
UninitializedDataSize: -
EntryPoint: 0x6f9a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.1.7600.16385
ProductVersionNumber: 6.1.7600.16385
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: dvdplay placeholder Application
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: dvdplay
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: dvdplay
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #WANNACRY wcr-dropbox.exe cmd.exe no specs conhost.exe no specs cscript.exe no specs !wannadecryptor!.exe no specs sppextcomobj.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7416"C:\Users\admin\Desktop\wcr-dropbox.exe" C:\Users\admin\Desktop\wcr-dropbox.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
dvdplay placeholder Application
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\users\admin\desktop\wcr-dropbox.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7436C:\WINDOWS\system32\cmd.exe /c 76561742052891.batC:\Windows\SysWOW64\cmd.exewcr-dropbox.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7444\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7488cscript //nologo c.vbsC:\Windows\SysWOW64\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\syswow64\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7564!WannaDecryptor!.exe fC:\Users\admin\Desktop\!WannaDecryptor!.exewcr-dropbox.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Sync
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\users\admin\desktop\!wannadecryptor!.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7624C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7660"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
728
Read events
723
Write events
5
Delete events
0

Modification events

(PID) Process:(7416) wcr-dropbox.exeKey:HKEY_CURRENT_USER\SOFTWARE\WannaCryptor
Operation:writeName:wd
Value:
C:\Users\admin\Desktop
(PID) Process:(7416) wcr-dropbox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Update Task Scheduler
Value:
"C:\Users\admin\Desktop\wcr-dropbox.exe" /r
(PID) Process:(7564) !WannaDecryptor!.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7564) !WannaDecryptor!.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7564) !WannaDecryptor!.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
5
Suspicious files
1 077
Text files
130
Unknown types
0

Dropped files

PID
Process
Filename
Type
7488cscript.exeC:\Users\admin\Desktop\!WannaDecryptor!.exe.lnkbinary
MD5:615212476726D7835042C9537B3290CA
SHA256:CC129128D652E5879452FD8EA9DBF52611E973E0E31EF95FC9EA019AA48DFB7A
7416wcr-dropbox.exeC:\Users\admin\Desktop\m.wrytext
MD5:980B08BAC152AFF3F9B0136B616AFFA5
SHA256:402046ADA270528C9AC38BBFA0152836FE30FB8E12192354E53B8397421430D9
7416wcr-dropbox.exeC:\Users\admin\Desktop\!Please Read Me!.txttext
MD5:AFA18CF4AA2660392111763FB93A8C3D
SHA256:227082C719FD4394C1F2311A0877D8A302C5B092BCC49F853A5CF3D2945F42B0
7416wcr-dropbox.exeC:\Users\admin\Desktop\babyplay.jpg.WCRYTbinary
MD5:DE8CE1983A6E690462272A6465C755F7
SHA256:FCFF50DEB7C50397FE14C9C5BE326755161B9A2B6D4F61B11B979D915FF109AA
7416wcr-dropbox.exeC:\Users\admin\Desktop\causeeffective.rtf.WCRYbinary
MD5:2E726895B9B60894CB6FBADA88CE5D0B
SHA256:C134194C79614CB45E66DA69E4E327464FAFC02BC9F6601F056F5391EF636DBD
7436cmd.exeC:\Users\admin\Desktop\c.vbstext
MD5:2C69421394B3CF1E8531E5BA60824C2F
SHA256:89CDEBC8A19455D87815A80CEE66AE366C3391D6A776F21753248CF2DC857554
7416wcr-dropbox.exeC:\Users\admin\Desktop\00000000.pkybinary
MD5:A9E9463776DB4BB4FF30713B4559FCCB
SHA256:BBB930FE7524187D163AE24D04E2B0301EAB92F27215AB81493829B2CD0B958F
7416wcr-dropbox.exeC:\Users\admin\Desktop\!WannaDecryptor!.exeexecutable
MD5:CF1416074CD7791AB80A18F9E7E219D9
SHA256:78E3F87F31688355C0F398317B2D87D803BD87EE3656C5A7C80F0561EC8606DF
7416wcr-dropbox.exeC:\Users\admin\Desktop\u.wryexecutable
MD5:CF1416074CD7791AB80A18F9E7E219D9
SHA256:78E3F87F31688355C0F398317B2D87D803BD87EE3656C5A7C80F0561EC8606DF
7416wcr-dropbox.exeC:\Users\admin\Desktop\t.wrybinary
MD5:5557EE73699322602D9AE8294E64CE10
SHA256:A7DD727B4E0707026186FCAB24FF922DA50368E1A4825350BD9C4828C739A825
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
20
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
google.com
  • 172.217.18.14
whitelisted

Threats

No threats detected
No debug info