File name: | wannaCry.exe |
Full analysis: | https://app.any.run/tasks/e7032829-ce00-4a07-ae44-6450e3683450 |
Verdict: | Malicious activity |
Analysis date: | October 05, 2022, 06:11:35 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 84C82835A5D21BBCF75A61706D8AB549 |
SHA1: | 5FF465AFAABCBF0150D1A3AB2C2E74F3A4426467 |
SHA256: | ED01EBFBC9EB5BBEA545AF4D01BF5F1071661840480439C6E5BABE8E080E41AA |
SSDEEP: | 98304:QqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2g3x:QqPe1Cxcxk3ZAEUadzR8yc4gB |
.exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
---|---|---|
.exe | | | Win64 Executable (generic) (37.3) |
.dll | | | Win32 Dynamic Link Library (generic) (8.8) |
.exe | | | Win32 Executable (generic) (6) |
.exe | | | Generic Win/DOS Executable (2.7) |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 2010-Nov-20 09:05:05 |
Detected languages: |
|
CompanyName: | Microsoft Corporation |
FileDescription: | DiskPart |
FileVersion: | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName: | diskpart.exe |
LegalCopyright: | © Microsoft Corporation. All rights reserved. |
OriginalFilename: | diskpart.exe |
ProductName: | Microsoft® Windows® Operating System |
ProductVersion: | 6.1.7601.17514 |
e_magic: | MZ |
---|---|
e_cblp: | 144 |
e_cp: | 3 |
e_crlc: | - |
e_cparhdr: | 4 |
e_minalloc: | - |
e_maxalloc: | 65535 |
e_ss: | - |
e_sp: | 184 |
e_csum: | - |
e_ip: | - |
e_cs: | - |
e_ovno: | - |
e_oemid: | - |
e_oeminfo: | - |
e_lfanew: | 248 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
NumberofSections: | 4 |
TimeDateStamp: | 2010-Nov-20 09:05:05 |
PointerToSymbolTable: | - |
NumberOfSymbols: | - |
SizeOfOptionalHeader: | 224 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 4096 | 27056 | 28672 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.40424 |
.rdata | 32768 | 24432 | 24576 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.66357 |
.data | 57344 | 6488 | 8192 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.45575 |
.rsrc | 65536 | 3448736 | 3448832 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.99987 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 3.52974 | 904 | Latin 1 / Western European | English - United States | RT_VERSION |
2058 | 7.99991 | 3446325 | Latin 1 / Western European | English - United States | XIA |
1 (#2) | 5.03919 | 1263 | Latin 1 / Western European | English - United States | RT_MANIFEST |
ADVAPI32.dll |
KERNEL32.dll |
MSVCRT.dll |
USER32.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2376 | "C:\Users\admin\AppData\Local\Temp\wannaCry.exe" | C:\Users\admin\AppData\Local\Temp\wannaCry.exe | — | Explorer.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: DiskPart Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3056 | attrib +h . | C:\Windows\system32\attrib.exe | — | wannaCry.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3100 | icacls . /grant Everyone:F /T /C /Q | C:\Windows\system32\icacls.exe | — | wannaCry.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3828 | taskdl.exe | C:\Users\admin\AppData\Local\Temp\taskdl.exe | — | wannaCry.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: SQL Client Configuration Utility EXE Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
4016 | C:\Windows\system32\cmd.exe /c 254601664950308.bat | C:\Windows\system32\cmd.exe | — | wannaCry.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2156 | cscript.exe //nologo m.vbs | C:\Windows\system32\cscript.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3932 | taskdl.exe | C:\Users\admin\AppData\Local\Temp\taskdl.exe | — | wannaCry.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: SQL Client Configuration Utility EXE Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3444 | @[email protected] co | C:\Users\admin\AppData\Local\Temp\@[email protected] | — | wannaCry.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Load PerfMon Counters Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2252 | cmd.exe /c start /b @[email protected] vs | C:\Windows\system32\cmd.exe | — | wannaCry.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3388 | @[email protected] vs | C:\Users\admin\AppData\Local\Temp\@[email protected] | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Load PerfMon Counters Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (2376) wannaCry.exe | Key: | HKEY_CURRENT_USER\Software\WanaCrypt0r |
Operation: | write | Name: | wd |
Value: C:\Users\admin\AppData\Local\Temp | |||
(PID) Process: | (3388) @[email protected] | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (3388) @[email protected] | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (3388) @[email protected] | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (3388) @[email protected] | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | — | Key: | HKEY_LOCAL_MACHINE\BCD00000000\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\250000e0 |
Operation: | write | Name: | Element |
Value: 0100000000000000 | |||
(PID) Process: | — | Key: | HKEY_LOCAL_MACHINE\BCD00000000\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\16000009 |
Operation: | write | Name: | Element |
Value: 00 | |||
(PID) Process: | — | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
Operation: | write | Name: | yyibsxxiapw107 |
Value: "C:\Users\admin\AppData\Local\Temp\tasksche.exe" |
PID | Process | Filename | Type | |
---|---|---|---|---|
2376 | wannaCry.exe | C:\Users\admin\AppData\Local\Temp\b.wnry | image | |
MD5:C17170262312F3BE7027BC2CA825BF0C | SHA256:D5E0E8694DDC0548D8E6B87C83D50F4AB85C1DEBADB106D6A6A794C3E746F4FA | |||
2376 | wannaCry.exe | C:\Users\admin\AppData\Local\Temp\msg\m_french.wnry | text | |
MD5:4E57113A6BF6B88FDD32782A4A381274 | SHA256:9BD38110E6523547AED50617DDC77D0920D408FAEED2B7A21AB163FDA22177BC | |||
2376 | wannaCry.exe | C:\Users\admin\AppData\Local\Temp\msg\m_bulgarian.wnry | text | |
MD5:95673B0F968C0F55B32204361940D184 | SHA256:40B37E7B80CF678D7DD302AAF41B88135ADE6DDF44D89BDBA19CF171564444BD | |||
2376 | wannaCry.exe | C:\Users\admin\AppData\Local\Temp\msg\m_czech.wnry | text | |
MD5:537EFEECDFA94CC421E58FD82A58BA9E | SHA256:5AFA4753AFA048C6D6C39327CE674F27F5F6E5D3F2A060B7A8AED61725481150 | |||
2376 | wannaCry.exe | C:\Users\admin\AppData\Local\Temp\c.wnry | abr | |
MD5:AE08F79A0D800B82FCBE1B43CDBDBEFC | SHA256:055C7760512C98C8D51E4427227FE2A7EA3B34EE63178FE78631FA8AA6D15622 | |||
2376 | wannaCry.exe | C:\Users\admin\AppData\Local\Temp\msg\m_dutch.wnry | text | |
MD5:7A8D499407C6A647C03C4471A67EAAD7 | SHA256:2C95BEF914DA6C50D7BDEDEC601E589FBB4FDA24C4863A7260F4F72BD025799C | |||
2376 | wannaCry.exe | C:\Users\admin\AppData\Local\Temp\msg\m_chinese (simplified).wnry | text | |
MD5:0252D45CA21C8E43C9742285C48E91AD | SHA256:845D0E178AEEBD6C7E2A2E9697B2BF6CF02028C50C288B3BA88FE2918EA2834A | |||
2376 | wannaCry.exe | C:\Users\admin\AppData\Local\Temp\msg\m_english.wnry | text | |
MD5:FE68C2DC0D2419B38F44D83F2FCF232E | SHA256:26FD072FDA6E12F8C2D3292086EF0390785EFA2C556E2A88BD4673102AF703E5 | |||
2376 | wannaCry.exe | C:\Users\admin\AppData\Local\Temp\msg\m_italian.wnry | text | |
MD5:30A200F78498990095B36F574B6E8690 | SHA256:49F2C739E7D9745C0834DC817A71BF6676CCC24A4C28DCDDF8844093AAB3DF07 | |||
2376 | wannaCry.exe | C:\Users\admin\AppData\Local\Temp\msg\m_croatian.wnry | text | |
MD5:17194003FA70CE477326CE2F6DEEB270 | SHA256:3F33734B2D34CCE83936CE99C3494CD845F1D2C02D7F6DA31D42DFC1CA15A171 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1028 | taskhsvc.exe | 154.35.175.225:443 | — | RETHEMHOSTING | US | malicious |
1028 | taskhsvc.exe | 5.45.111.149:443 | — | netcup GmbH | DE | suspicious |
1028 | taskhsvc.exe | 51.254.136.195:443 | — | OVH SAS | FR | suspicious |