Dropped Files | ZeroBOX
Name e06efcebbe63b6e5_desert.jpg.wncry
Submit file
Filepath c:\users\public\pictures\sample pictures\desert.jpg.wncry
Size 826.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f0890280dba658ad5a17afbd84a25661
SHA1 309f373e066ba20312acb090c081a35aa8e20c18
SHA256 e06efcebbe63b6e57113fcc1a52cb7a423c2b85706193a82ff4afabfbc1e5567
CRC32 6ED4CE06
ssdeep 24576:CJTp1RseMxYh3k8CHILlCkhVSQ89e4xtUKGnRT:CTp1ixYBKy3seAUKGnRT
Yara None matched
VirusTotal Search for analysis
Name 456a8f72173cf95d_57.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\57.WNCRYT
Size 3.6KB
Type Python script, ASCII text executable, with CRLF line terminators
MD5 150f4242c45318643014512f3bbc5c03
SHA1 088baacfdbf62d1066ce136e284b3883dd20bd66
SHA256 456a8f72173cf95dfad2db9c85cf7e1eeb47d6e45bb3ccdf400508968feefcf6
CRC32 6D1A6F45
ssdeep 96:8/aXTVgd9rPU0HKZrGeVn3cKxrpLo9E5INfUkQViiz:fDVQd1K5Gqndd9oq+SE6
Yara None matched
VirusTotal Search for analysis
Name 1bb9d018533c9acf_hibsys.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\hibsys.WNCRYT
Size 128.0MB
Processes 2632 (WannaCry.exe) 2748 (taskdl.exe)
Type VISX image file
MD5 e605f5c4e80100278cf57b2a4c5270ad
SHA1 3aee548102eb9b243daad27b03b6c39a882d6bc8
SHA256 6b28b2d18521f8e5a2a2cb158a1ef3f90820f2bc3f2cfe0302a8295143ef90f0
CRC32 1C3E1B65
ssdeep 3:rn/3RXQXRABM:rnfWXRA6
Yara
  • Suspicious_Obfuscation_Script_2 - Suspicious obfuscation script (e.g. executable files)
VirusTotal Search for analysis
Name 19cb87050b0fb410_594.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\594.WNCRYT
Size 374.0B
Type Zip archive data, at least v1.0 to extract
MD5 cafb05d8c8640330d6405fde07e3a6c0
SHA1 e756d1adb29a7637664a92a0d5600d6686942b9f
SHA256 19cb87050b0fb410da3b88df752c2e1bdaeec77ac052b04febef31a68823cfcb
CRC32 AB52F1C0
ssdeep 6:59TKlb1PPA/X7h1FPA//4G3DXzyIrSl//7JTXG/a+9Kn7XG/n1CJ1NnDt8lOD:5BW1PoP7h1FoX4KeIrG/FTXGy+WXGP1A
Yara
  • zip_file_format - ZIP file format
VirusTotal Search for analysis
Name 597edd6229f37421_484.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\484.WNCRYT
Size 353.0B
Type C source, ASCII text, with CRLF line terminators
MD5 73f54e74a625fb975d43af713014c933
SHA1 c88c995928de277655b9ebf2b7385a1413f417fb
SHA256 597edd6229f37421a2490f4967c4d4cad46a4177565c72aa631af086ce8a1602
CRC32 5604D8E6
ssdeep 6:hMaYxjQ6zhe8YVwHFteGNEXJQ7e1MmpRLlAferZnD3FjQ6dQ:hMayhOYZNE5Q7ezdlAfOZnrU
Yara None matched
VirusTotal Search for analysis
Name c716b1050abb1c87_kw_gb.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\kw_gb.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b2176befdec0faa2d1dd258327ddff4b
SHA1 5069ba38c2584d7372d711b1f1124404343768b6
SHA256 c716b1050abb1c87e7d0d0a7c0051225545529e520b1a68b3110c305957da002
CRC32 7D41449B
ssdeep 12:bkEZYb2lf1tijFNR/rO6tcuYdu1073H24MHAvKzgu1zUwLuN:bk2ldYThrO6quYUiW4MHA48
Yara None matched
VirusTotal Search for analysis
Name d632e9dbacdcd8f6_356.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\356.WNCRYT
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 343fa15c150a516b20cc9f787cfd530e
SHA1 369e8ac39d762e531d961c58b8c5dc84d19ba989
SHA256 d632e9dbacdcd8f6b86ba011ed6b23f961d104869654caa764216ea57a916524
CRC32 3C5BAF10
ssdeep 768:wjof+RdBZJ2g653hvqs+Rcb+SBMdK4tztHDyecRa6Xs9X/jPlu6tKvUfsQscD:wjE+132lhisKZdltWeks9Ru6nsQscD
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name d192f7b954c04fbf_exec.png.wncry
Submit file
Filepath c:\python27\click\click\click_image\exec.png.wncry
Size 696.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 6d42542320d0ce4f32830af230f397c2
SHA1 c5d2322bd4d9c1d4a47c4ca43a59dbfbc25e1822
SHA256 d192f7b954c04fbf83a712255f77dfe643df5f241ad8c672c74602617cf4b7ba
CRC32 D274EB09
ssdeep 12:bkExhlGegu8UPHfAKI8iQTQC1Nc9cl9TiScVc7SbEYlgULHd230tpKKjA/:bkUG7ufP/AKlrHEEQScVcm1CUL0qjA/
Yara None matched
VirusTotal Search for analysis
Name cc3672969c1dd223_92.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\92.WNCRYT
Size 1.2KB
Type ASCII text
MD5 68882cca0886535a613ecfe528bb81fc
SHA1 6abf519f6e4845e6f13f272d628de97f2d2cd481
SHA256 cc3672969c1dd223eadd9a226e00cac731d8245532408b75ab9a70e9edd28673
CRC32 8BD5B1E5
ssdeep 24:4azu8byFouxpZzWsu0biMe5pF9g1tT9egQTqrS8QWmWFUvIvWI3:46CFB/ZzWsu0vpHlrS8QLWFSeWI3
Yara None matched
VirusTotal Search for analysis
Name 86811a09975b9eaf_eo.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\eo.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c01053186a0d3b75b6255ada7eaa1e4c
SHA1 c80ab4dccb4551d4b7b9bbbffe3618118f79a5ae
SHA256 86811a09975b9eaf4c9663ec13be2ba5d03e2c016e69f7f2de3f25301b9a2ec9
CRC32 47023ADF
ssdeep 24:bkFbvr6t8+gw/ze15lnMsMAOHPWurtNOcNiwU+YrIn7sC14MixByw/bLNWzxl/M:bkFLd0ze5nMsM1vvHOcFJsC1hgYw/l4g
Yara None matched
VirusTotal Search for analysis
Name f99da45138a8aebf_674.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\674.WNCRYT
Size 279.0B
Type ASCII text
MD5 4b8e5b6eb7c27a02dbc0c766479b068d
SHA1 e97a948ffe6c8de99f91987155df0a81a630950e
SHA256 f99da45138a8aebfd92747fc28992f0c315c6c4ad97710eaf9427263bffa139c
CRC32 A3EF5C6F
ssdeep 6:SlSyEtJLlpuoo6dmoEpb53FD/LoEpLE3vG5oEpLE3v6X5oEpba+3vnFDoAov:4EnLzu8KF3FD/1w3vMw3v6T/3v9dy
Yara None matched
VirusTotal Search for analysis
Name 1cf0c958d0c5af88_263.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\263.WNCRYT
Size 1.7KB
Type C source, ASCII text, with CRLF line terminators
MD5 4aa6cecafe8b5b0363bded2a70c71788
SHA1 fc1ce25f42c7d4a1fafb1b0a76ba36eb09c133fe
SHA256 1cf0c958d0c5af88e5124ee3844fb16d6cb369e076a115231f6c3b98d1fc337d
CRC32 96873F0F
ssdeep 24:g2KeaX90KvX+L1qRdj3jT9krdbWbA6GkK6ey+v8iD5bJ7qK3DilP+fyPDD:g2Kl908+85tzb5pK7n4K5KP
Yara None matched
VirusTotal Search for analysis
Name f81a574e722a3538_keycert.passwd.pem.wncry
Submit file
Filepath c:\python27\lib\test\keycert.passwd.pem.wncry
Size 4.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7e92859776716955ac27e8c72f840083
SHA1 fb5196975d5237b9fa874a1792a96b1ff17a4f6c
SHA256 f81a574e722a3538313ae0a6123741412ea8da94313a520ffe86352bc9e2503e
CRC32 F9695196
ssdeep 96:o3z6G+u3y3E5P2lPAhCX08KjdSamn4zdQYiKmdOIvZkTkfcSsZ:6z6NuCyelPAhGo0amnwdAKmdB5f6
Yara None matched
VirusTotal Search for analysis
Name 320af85b7903e16a_1.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1.WNCRYT
Size 885.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5e153e8e0366d2701bf1e7e4c00bbc81
SHA1 d73672fd8873edb093cf73c022ba3644c774db83
SHA256 320af85b7903e16a62feac55f0a76f3a01b4d68c9221eb79fa79647bdc4c672e
CRC32 F8846545
ssdeep 24576:ToF/lIscAmoF/lIscAmoF/lIscAmoF/lt:TctIscfctIscfctIscfctt
Yara None matched
VirusTotal Search for analysis
Name 81617edc3fe2e6b0_asdl.h.wncry
Submit file
Filepath c:\python27\include\asdl.h.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1f8f905c02f1c2f2802d862284dd640e
SHA1 f329b5919ada8e662b577955ba67fa4c611b2bf6
SHA256 81617edc3fe2e6b08915d7a83314593b7082b5b9b931e1e84c322d16a81528bf
CRC32 B9E55513
ssdeep 24:bkr/gpYjOveu/Brogc5wSGdXb/8RUYFBdRCBZnKERag65Hn2w1ujfCthoqbg3IyN:bk82jOz5suL/PYFrcZ96J2bjq79gZ1v
Yara None matched
VirusTotal Search for analysis
Name 367eba9c97ae8906_open.png.wncry
Submit file
Filepath c:\python27\click\click\click_image\open.png.wncry
Size 760.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e916ac9c8779eb4d63d64d6d3b734365
SHA1 2d73477828e22294cb8f025c1a8c20d9e749d3ce
SHA256 367eba9c97ae8906ecb4e2f9754bede85936f2d0758daebefb2531ad92009f4e
CRC32 7898D69C
ssdeep 12:bkELo/Dd5YbA8t57SQjoawuHgiK0+4PE/B/t/eisF1TJNuMDtmxniqGjUlDa72gC:bkN/Dd5YbA6TlwGH+4MtTsFvMMhmxniU
Yara None matched
VirusTotal Search for analysis
Name 8945d9f65c608be1_161.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\161.WNCRYT
Size 3.7KB
Type ASCII text, with CRLF line terminators
MD5 9bb798da6ac0a6441becb0a4ea40930f
SHA1 93b45a60a3c61b9aa82caa75e3e5b958440dce4b
SHA256 8945d9f65c608be16fb19d46b6322e7ff7691403f932d6e5b67bc06cc0fa6083
CRC32 2F29ECC7
ssdeep 96:X33OuB31Lu72QEVJ3R0wP+rXXYt5nzKgnRNDqQ2567LlBc:X37vLm3G3xPMIvzKx0Lw
Yara None matched
VirusTotal Search for analysis
Name 5ba21fbb0964f936_65.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\65.WNCRYT
Size 1.1KB
Type ASCII text
MD5 8ba06d529c955048e5ddd7c45459eb2e
SHA1 33263b236dbff36fc92163ec61d62b9370384fec
SHA256 5ba21fbb0964f936ad7d15362d1ed6d4931cc8c8f9ff2d4d91190e109be74431
CRC32 D4F54CEB
ssdeep 24:RsMiJHxRHuyPP3GtIHw1Gg9QH+sUW8Ok4F+d1o36qjFD:KMiJzfPvGt7ICQH+sfIte36AFD
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_~SDF83A.tmp
Empty file or file not found
Filepath C:\Users\test22\Desktop\~SDF83A.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 59799ea96923129c_zh_cn.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\zh_cn.msg.wncry
Size 600.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e1df762461a3b78236b8e33d07a46840
SHA1 cb0c7acb7d27b06085e1d76325470ee1ecdbfc7f
SHA256 59799ea96923129cef3e35d004d1705ebe9fc087e2847d200b7746a0390d2aac
CRC32 58252A1B
ssdeep 12:bkEe4cSQBvBXoAkORB41qX77VdnRIYtUKWhQ+bZzdsbecg5aGPMBG+vH:bk54eptkORB41qXvVdn8Kkjq6Vb8
Yara None matched
VirusTotal Search for analysis
Name 66d653397cbb2dbb_zlib1.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\TaskData\Tor\zlib1.dll
Size 105.0KB
Processes 152 (@WanaDecryptor@.exe)
Type PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
MD5 fb072e9f69afdb57179f59b512f828a4
SHA1 fe71b70173e46ee4e3796db9139f77dc32d2f846
SHA256 66d653397cbb2dbb397eb8421218e2c126b359a3b0decc0f31e297df099e1383
CRC32 BB8A3384
ssdeep 1536:NlN3sTKU7xniaO9ADje81EQ3aL8WNdUCqfRnToIfBoIONIOqbW+xCvETe:DpsmU7xaiDjeJL5qf5TBfgHqbdxCv6e
Yara
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name d0faa9d7997d5696_648.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\648.WNCRYT
Size 251.0B
Type ASCII text
MD5 f60290cf48aa4edca938e496f43135fd
SHA1 0ee5a36277ea4e7a1f4c6d1d9ee32d90918da25c
SHA256 d0faa9d7997d5696bff92384144e0b9dfb2e4c38375817613f81a89c06ec6383
CRC32 A234CAE3
ssdeep 6:SlSyEtJLlpuoo6dmoPjbJFLoH+3v6rZoI+3vjb0f6HK:4EnLzu8NJF73v6rE3vbq
Yara None matched
VirusTotal Search for analysis
Name c4fcb181700357fe_36401687182996.bat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\36401687182996.bat
Size 342.0B
Processes 2632 (WannaCry.exe) 2924 (cmd.exe)
Type DOS batch file, ASCII text, with CRLF, CR line terminators
MD5 c024823d77cba5e076c252e5d1357347
SHA1 d1fd56a7931cf76deeb44131be67ca2c0cef2749
SHA256 c4fcb181700357fee9b8ffb0e58dbb7a39272e329c0f2ab037872d55d4cb8993
CRC32 C4BA63BD
ssdeep 6:hqn4+B9TmQpcLJ23fYgpPmQpcLJ23fY0F9a2T2ZLT2Ln:Q4+B9TOLM5OLMSrT2r
Yara None matched
VirusTotal Search for analysis
Name 20ae9df6ce4cf3bb_ast.h.wncry
Submit file
Filepath c:\python27\include\ast.h.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a2da9533ae8629e92b2e307e221af9ea
SHA1 b9dea57514257db1cedf8f214e245aa3be8ddfa3
SHA256 20ae9df6ce4cf3bbc0981c9bc9bbd0ec246bb783f1733eefd3a984b793ce27cf
CRC32 74E4B566
ssdeep 12:bkENotEgK/9MHwfQ6l1ESc134jd1Hom/ABf2W2SW615xKYlc9WmRT/K:bkWKNK/9MsJISct4jd1IsS595K7UWT/K
Yara None matched
VirusTotal Search for analysis
Name e60d5e3b59ecf1e5_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\setuptools-41.2.0.dist-info\top_level.txt.wncry
Size 328.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 8b2b95fdfd9da99430abcde477a15892
SHA1 105e712967ba6830cb720e1c2bb7367380e3b879
SHA256 e60d5e3b59ecf1e58cc0b4ea57846216829c9a5c4c3782b51b688c6457f66ea3
CRC32 2F44B882
ssdeep 6:bkEXD9W2z1Vftw9FKWLBvsuo1H5M+MG3VP3Rz51HM1fsjyV0mXhYXc0:bkEtVftwewsuiH19hBz7OwyV08kc0
Yara None matched
VirusTotal Search for analysis
Name f0ebea1846fb736d_rgb.txt.wncry
Submit file
Filepath c:\python27\tools\pynche\x\rgb.txt.wncry
Size 18.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ad2a845e4413fc16c9a5c882faebe43f
SHA1 42cf096c3de35d37c68e9ed6c81e4624a280b71e
SHA256 f0ebea1846fb736df88ebbc4ceef3ecbe1dfb0c026dba35af629369bb37e577d
CRC32 21610883
ssdeep 384:gd7z4MSuEotA7iS04IvvY4pVfS90UlY6pv4Q:6z4UXTkoE07uz
Yara None matched
VirusTotal Search for analysis
Name 6351ea971fa4e699_icon_16.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\icon_16.png.wncry
Size 424.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 82eed0e7f8ab08578542be7ce7115387
SHA1 eca1fc60ec26ca5856ffdbb806b51e65a9290bee
SHA256 6351ea971fa4e6997de2ca1403abf8d891dc6314d88ef489e3a90cfaed005ce5
CRC32 95812B13
ssdeep 12:bkExidHkauZpVbX11Qf+nJDFtGReBsMX4:bkmiHkauZpVXQfuz8RD
Yara None matched
VirusTotal Search for analysis
Name 54c59ebf5bffa7a6_roses.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\roses.jpg.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2421e9c8813032d90c1a289475742c93
SHA1 04a73a0feacd7ab654676b5028387fb103264928
SHA256 54c59ebf5bffa7a6ccadb61d1f8d9b844aa9b278fe40a790f05495e5a56f82f8
CRC32 1C0C5E41
ssdeep 48:bkgueP4PEUwzQJ9X7k+ZnU14Jr6f5vbg8PdBn+GU:ogB4PEUwzQrk+ZRJr+oGU
Yara None matched
VirusTotal Search for analysis
Name eb2e2b7a41854af6_116.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\116.WNCRYT
Size 1.8KB
Type ASCII text
MD5 791408bae710b77a27ad664ec3325e1c
SHA1 e760b143a854838e18ffb66500f4d312dd80634e
SHA256 eb2e2b7a41854af68cef5881cf1fbf4d38e70d2fab2c3f3ce5901aa5cc56fc15
CRC32 3B701F4C
ssdeep 24:4azu8ocYe48VcOVczyVczoRSVcqVcR0q4vTqBBiPNVcqVcR0q4vTqBBil:46R48h0qpBBkI0qpBBe
Yara None matched
VirusTotal Search for analysis
Name 0171178ae901e108_619.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\619.WNCRYT
Size 543.0B
Type JPEG image data, JFIF standard 1.01, resolution (DPI), density 1x1, segment length 16, baseline, precision 8, 16x16, frames 3
MD5 50e9104383c3f36fa9e9be6148e6fdf3
SHA1 9b19331a00f83f12fdc2feba2eb401f9732f8d44
SHA256 0171178ae901e108f56305aff7e36268a690bc49933a24b1aaa587fda00f4d3b
CRC32 C9143548
ssdeep 12:skORWjseewhaMj0UAX7QDZJezYdnX5vXpukCCnSc4NyF53:jTjsIhaBXE1JokhXpWfc6C53
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 7fa789e04753bb35_pwrdlogo100.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\images\pwrdlogo100.gif.wncry
Size 1.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e26a58c0bdfb23cca02ef80d4d4fae87
SHA1 54a1b98a3dbdd39981e83ab817d0f5edc0759ce9
SHA256 7fa789e04753bb35cfce3ca5cb3de0f47c09a02e6c619bb12688b1d318ac514c
CRC32 393E1A5F
ssdeep 48:bkLMWXvXgGpFB01QzySC9b179az/d8XaEk+MO:oLMWXvXgQOsCJ1Mzq9
Yara None matched
VirusTotal Search for analysis
Name 097de9f7d71a5063_533.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\533.WNCRYT
Size 207.0B
Type MIME entity, ASCII text, with CRLF line terminators
MD5 4998c6e4cdb628d0e89e303747896512
SHA1 8db6de163d6876f757461c11f7d579faf7489427
SHA256 097de9f7d71a5063fb89c2e57c4e8e330df685665ad1b557da3b6adcea4fbcee
CRC32 9F113735
ssdeep 6:3XmMQ8a0CInAFxIfYwF02Q8a0uWn9p9mfYwFG:3XmMQY4FOfYwF02QYuW9uYwFG
Yara None matched
VirusTotal Search for analysis
Name 6195acb467739adb_de.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\de.msg.wncry
Size 4.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1686f0eec18f74f924f08e6752a30ad0
SHA1 a601335481e080696e77a56caad83cd1f20dfb88
SHA256 6195acb467739adbfe003774e39fdd4d1f890fcbf2dfe0eb4b2fcd3bb423a46f
CRC32 EE9EF0DD
ssdeep 96:osWqXqkaWS8R/ivwteuDRqsqgxpgqMIlmnOTvMzDaadYynpL:czPubIuDRqsBpJMIswvMzPCynB
Yara None matched
VirusTotal Search for analysis
Name 266287b75ef93b37_bn_in.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\bn_in.msg.wncry
Size 552.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 82ddf928c2210dc704a515be1bfd7eb4
SHA1 bcbc9895f9f49e4b0c075b1377dafffe7dff297f
SHA256 266287b75ef93b37bac7ddb4ae445d2503c6b5b397872135fd628a5df6336f64
CRC32 5D477446
ssdeep 12:bkEgDo/R+Q+3f89Ewy/HtdC9b2W5vFKobLE6E7oTgkmK:bk70/8QEf89Ez/W75fE6Tk1K
Yara None matched
VirusTotal Search for analysis
Name cfe867e18c427aa8_698.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\698.WNCRYT
Size 59.0B
Type GIF image data, version 87a, 9 x 9
MD5 9016b58ab81cedc76da7dc75a4e81950
SHA1 776c9ed182fd889fc2ab2d8367287786e4c90c1e
SHA256 cfe867e18c427aa88d5e2404a01aa22d042212222e8304b25275a400e650d1d8
CRC32 13EBAAF9
ssdeep 3:Mfsl0H/XTtK7CO2Wle:de877Je
Yara None matched
VirusTotal Search for analysis
Name 6b5ab8ae265db436_686.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\686.WNCRYT
Size 991.0B
Type ASCII text
MD5 4db24ba796d86adf0441d2e75de0c07e
SHA1 9935b36ff2b1c6dfde3ec375bc471a0e93d1f7e3
SHA256 6b5ab8ae265db436b15d32263a8870ec55c7c0c07415b3f9baac37f73bc704e5
CRC32 2E1DB2EB
ssdeep 12:4EnLzu8r4mc4Go/4mtVfqRvodJ3fjESBToOqe3lHvFgdF6A3ixTZ6OM5mSYoC6Vy:4azu88kGDiq1qhbJ75V9gZSpgmSm9
Yara None matched
VirusTotal Search for analysis
Name d81ba4e33d6b6320_th.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\th.msg.wncry
Size 2.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 aa3b9890536e9e1078c21e7587a42863
SHA1 773584aca98e898fb341ae826877e6f0130e2fb0
SHA256 d81ba4e33d6b6320e4452d21be749bfb62b84af780235e89571fcd858b3dcfd8
CRC32 29962319
ssdeep 48:bkZUN3oUMM9vrI6EbGjGLK8i0zcbyqCEnCjgdFFUShz5PxQ8FB+:oZYnlI6ECjGLnttqzCcd9z5pQ8y
Yara None matched
VirusTotal Search for analysis
Name 9d3d05864bb53c29_sh.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\sh.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 37cc0ac92ff38df75a2cdb0b49415aa4
SHA1 885a0fa225d5fd0c6df543187d48e48719d18e40
SHA256 9d3d05864bb53c29760c2cd38f94ee6dbdb892cd782921f3ca9a40f12bfe3ebc
CRC32 F8EEE654
ssdeep 24:bkYckRM4EjY9mDPPdwG2lClBv8fIgpptzGdS1ZuAo+1+WaOtXNk:bkYcwP39mDNuWv8fVpfB/J17W
Yara None matched
VirusTotal Search for analysis
Name 8023619f9ef0ce4b_557.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\557.WNCRYT
Size 7.0B
Type ASCII text
MD5 d3401109f4f08fb7f9c3f411ea9209f2
SHA1 a841bf4da24f2d960ad77a39767fea360f00807f
SHA256 8023619f9ef0ce4b038d20084a680c2746a25f342e964d062616f6f81032620c
CRC32 47461554
ssdeep 3:Sn:Sn
Yara None matched
VirusTotal Search for analysis
Name 263c39c403e40eb7_big5-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\big5-utf8.txt.wncry
Size 856.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 4793efbe49fdcd355966371a810d03f0
SHA1 9fb35900adb09f3f2f3ab2d9156ebaf7bc2ce9b8
SHA256 263c39c403e40eb70dd505866b4bb308ed0fd6a0817da9ec9b35a1f19ffd236a
CRC32 D3D55E11
ssdeep 24:bkdVlAa34EAhZCA0kJPk/KW4fdw1OvAt7QfTjvQ1Mj43q:bkdB3492kJeNOjvI7QfTjv/j43q
Yara None matched
VirusTotal Search for analysis
Name 725abef222aa097f_icon_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\icon_128.png.wncry
Size 4.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b53993beb7f658a78ae9d5c9c630decd
SHA1 51607d4ea4384400a147f9123973a6ef57ff51cc
SHA256 725abef222aa097f7c5636ddb71622daaf3451ccc9d9f29fa6143e673343a5d0
CRC32 8E37E687
ssdeep 96:oofH10c7Gpuqxa7yj+SPGdhPFY5CKkLpQ+/8Xb0L1ZMjwLwozFXDh7:VfH7GppCTSPGdJ6aC+/8LY7XnzFTB
Yara None matched
VirusTotal Search for analysis
Name 33937f4087a4d968_437.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\437.WNCRYT
Size 265.0KB
Type data
MD5 6db4c912c66a8baba4256964704a3159
SHA1 d7468802ea0cf70849af5fffbad0d8e9cf39a7f8
SHA256 33937f4087a4d968b782378203836628ee56797f2a09b5b04f9680b324fade10
CRC32 B8E0B661
ssdeep 48:3bgcUfoTxoxfo1xoyoOatvyWEfo4xoDfodxotoOa+fo8xo7+w9FOjD:LvkyCUd0MBgsi0elu/k
Yara None matched
VirusTotal Search for analysis
Name e13c854df9e328ea_thumbcache_sr.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows\explorer\thumbcache_sr.db.wncry
Size 312.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a6fd9b3180b4f7ed2b46db6188e50cd8
SHA1 6e6b8c927a67653f6f0d59021b90bbbfd0dcffe5
SHA256 e13c854df9e328eaf50d06a1a63660c201113c92bd45312d8b6cdebc695ce760
CRC32 BCD7F23F
ssdeep 6:bkE5TU7hMOf+s406/y3pDcn1o40WKdlDMNsDl+IseFJfOc5w3qjMz9yF15JD:bkEK1Me+s44pDYiXMNsDFnO3qYpm1P
Yara None matched
VirusTotal Search for analysis
Name 6d2cc6cd63e9a3a7_178.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\178.WNCRYT
Size 23.3KB
Type JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, baseline, precision 8, 800x600, frames 3
MD5 4a35afef77e01e022bfefc1d2c818b25
SHA1 eededa3e96155949c0fbb24728d0721f291976e2
SHA256 6d2cc6cd63e9a3a7c7b00ee34e38267b2abf6071824feb413dd6b40bd07ab0fa
CRC32 6B16F512
ssdeep 384:VLeNxQm1Ah+cCnrTFFuZ6It7aNw47Hgwo6dioI2+CZ7E66JENuLjLzC:VLqC9h+cCnrnuZ6IUNw40wo60oI2NNz3
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name f249dd1698ed1687_660.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\660.WNCRYT
Size 986.0B
Type ASCII text
MD5 996b699f6821a055b826415446a11c8e
SHA1 c382039ed7d2ae8d96cf2ea55fa328ae9cfd2f7d
SHA256 f249dd1698ed1687e13654c04d08b829193027a2fecc24222ec854b59350466a
CRC32 C196987B
ssdeep 12:4EnLzu87mY5mvAqO6RxmtV5qHbMj6aywE1ZD4ScMfRDc6VZTEpSecbLwJQT1Y4:4azu874/RqEXsSpffTBtbQQT1t
Yara None matched
VirusTotal Search for analysis
Name e3209eef68d0f375_readme.bmp.wncry
Submit file
Filepath c:\users\test22\documents\readme.bmp.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b2b9e070396fcbe7b7a5bd8e840fc401
SHA1 9751a2976ce9b622154255fe2efb9b575752f084
SHA256 e3209eef68d0f3753b2df19e15f41fd1f1739704214a337c6211337d4590a67a
CRC32 C3BBA691
ssdeep 6:bkEoX++gfBe49k3Bpa+FplRklurHtFoP7rrGOlkIDhPQvUihQLlBUG:bkEy+tBDkdworHtFoD2IDhPQvUihQlr
Yara None matched
VirusTotal Search for analysis
Name bc061a5e252ae47c_250.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\250.WNCRYT
Size 3.9KB
Type C source, ASCII text, with CRLF line terminators
MD5 f2635aff3ccf59fc14bf4ef3f0d70862
SHA1 789b93936b2d14ba4cd96e47d98a2f9f6277d569
SHA256 bc061a5e252ae47c0c5e02689c1ff978986522e8153d7b526ee91536531b41e3
CRC32 23E20004
ssdeep 48:pYiDJToXS7dcoN1uKXHZUJfCpkMDM3ZfH47MJZoqPJ6HVpXV0viqy9ASyHTmKY0:KiDJUoOKX+AkMDmP4MoqYHbKviqnSJ0
Yara None matched
VirusTotal Search for analysis
Name de1ffc93d4834a7a_505.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\505.WNCRYT
Size 382.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 5166454de8cd8fe1c41bd1ce6d138bd9
SHA1 4d08d6803fa91bd7d48d2124ca104cf9101dbe2b
SHA256 de1ffc93d4834a7a9cd7ce964243ba1bd3e0093cbacf41624f6c4afccb956f16
CRC32 C4DEE5FF
ssdeep 6:kQs169XkIedFyY7tD4JKm6+AcR5+bBWVpf0d+WH38VFy2jfr0icSr+x:k116arny0x4JKmVN+gVB0d+Aey2jf0x
Yara None matched
VirusTotal Search for analysis
Name f4535724b43b5439_323.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\323.WNCRYT
Size 1.0KB
Type ASCII text
MD5 6a12bb5bdec7c02b0509e1aaf9a3b11d
SHA1 172b91679d371f0baf91855558ae003dd5b8491e
SHA256 f4535724b43b5439d3bb21f69041c3a70aa7f9fbfd23dc9421e0b5b55f9996b3
CRC32 EF920893
ssdeep 24:J95NKX7iulGgWGfAX6X5GXFXvdgdsmLdkb0drdZpp7:FNKX7iulGgWGfAKJGVf+mmR62RZpp7
Yara None matched
VirusTotal Search for analysis
Name f23bd09f424f7e20_479.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\479.WNCRYT
Size 243.0B
Type C source, ASCII text, with CRLF line terminators
MD5 e48dab5e89ba3964660e66d69824e7e7
SHA1 f1120679f219d185cb9209b5b36e5506c5a0e516
SHA256 f23bd09f424f7e20bbf0be3113ec2871adc80dee7443d43a1c7ef8e3f0229b59
CRC32 40D6CC9E
ssdeep 6:BEQ0vjQ6zheIz2yaHQWfcq+VFDyXag5jQ6dnMyy:BE3hDcwBVvUMyy
Yara None matched
VirusTotal Search for analysis
Name 3b328ce11308b544_553.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\553.WNCRYT
Size 10.0B
Type ASCII text
MD5 976a74560e622525cbe62eda76af31cc
SHA1 8b6116058d74ea1c64055947e9529b1dbbdfe3cd
SHA256 3b328ce11308b5449970340a611834d0f1cadea3ec5ac1bef51431b117817f99
CRC32 2471DE80
ssdeep 3:3QWlon:Tlo
Yara None matched
VirusTotal Search for analysis
Name 5545048c4f1f94a2_615.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\615.WNCRYT
Size 355.0B
Type Non-ISO extended-ASCII text, with CRLF, NEL line terminators
MD5 17e48d2803260bffd24291fde1139ee4
SHA1 f1ee040bfdbdda28a0c051d28bd4317ac8c3ee67
SHA256 5545048c4f1f94a2a4b1ccdbbc50b78fd64d206f675ffadeb28c17a1a0a57965
CRC32 66694218
ssdeep 6:4UvMGGEF7x4PNL+kdsrIvKtZ4JnHPdo5tFeK7HaNX82LMk8U3lGfYldy:gGGEZx4PNKJrIvKtZ4JH1uLeKraNXB47
Yara None matched
VirusTotal Search for analysis
Name 4091c70b47e5014b_328.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\328.WNCRYT
Size 1.4KB
Type ASCII text
MD5 6b2ac717481603be39972305766f46d0
SHA1 34e376f5c1e12e47663f6f7dabe2de297848a858
SHA256 4091c70b47e5014b28921dcc6199503fccb3d17581523a290ae4c63a352523a3
CRC32 2B1C328B
ssdeep 24:M65JxMlqSxtX7p7ruM1pPxyBCXfuXMfyBE7odQzdEYgo/GtyVKLmXjgpOUpuup3v:B3Jkd7yMj5eC2OeEsMlYiKSTIOEu23v
Yara None matched
VirusTotal Search for analysis
Name 6513beab8b2ff7d1_142.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\142.WNCRYT
Size 4.1KB
Type ASCII text
MD5 139bc00416c426a552879ab5295105a0
SHA1 2c66c715e44bcb6ef6396d1197e9848fa3196f6f
SHA256 6513beab8b2ff7d13d6ae1455f088aec5eff911288889162330df7f70b90c9ed
CRC32 CCF10B6B
ssdeep 96:13LqlagtGIvz8MFU9RvjwKAN98qqU007Qt:6/KRrwKYtIt
Yara None matched
VirusTotal Search for analysis
Name cb5da96b3dfcf439_m_norwegian.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_norwegian.wnry
Size 36.7KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 ff70cc7c00951084175d12128ce02399
SHA1 75ad3b1ad4fb14813882d88e952208c648f1fd18
SHA256 cb5da96b3dfcf4394713623dbf3831b2a0b8be63987f563e1c32edeb74cb6c3a
CRC32 C1BC52DA
ssdeep 384:SheftipUENLFsPzy3EFHjHdy2MG2D7mgwroXeo75Y3kmA31dv61Qy5:Shef3jHdGG23KrDZrS14N
Yara None matched
VirusTotal Search for analysis
Name 410fd53c9634965c_usertile26.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 3d404187efd7b9fb9810d112bd8cc368
SHA1 4c18184896e46369b2af6de3d84c25f44d3f051e
SHA256 410fd53c9634965c2b56efbf7a774d79014c98a2cd1d767adc51636e97428c5d
CRC32 35DA4942
ssdeep 768:Wf+7KfT2OwULEbJoGn9kxvFPT45bf+bldvy0KJ2hgJU+ocyWpStuKYUMISqjE:b7K5wULENvgFPsFfMvk2idySS1MISqY
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 2e87d398bdf79f57_help.txt.wncry
Submit file
Filepath c:\python27\lib\idlelib\help.txt.wncry
Size 12.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b6cf3be8eafb57fe059cbf56d4299048
SHA1 8ebc41381a29cfd34a297582aadb4fe1e7aa5d02
SHA256 2e87d398bdf79f57fd1e191c63af8b2d410954733cb274917b3831df73ae4887
CRC32 A4D01A2F
ssdeep 384:BLiXXFpDxSYhXkCd4Kg4aNP9GOyiH6qaQ:BLiXXF5x9hXD4KgivhQ
Yara None matched
VirusTotal Search for analysis
Name 6a28d5b18c796948_thumbcache_idx.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows\explorer\thumbcache_idx.db.wncry
Size 12.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f20763dfac1e965df8f130a762d7ec7b
SHA1 4795188f439981e5920b747fdba519417d57d3b2
SHA256 6a28d5b18c7969489227813fd5b1e5974f84208eb33514cbba34c70b0b3c166e
CRC32 0BB6E9BA
ssdeep 384:Rcbj1H3motoYeR2cQ3GHyhRvaDN+PYkPmIC:RcPL+5DQ3bRvK0/BC
Yara None matched
VirusTotal Search for analysis
Name 4a468603fdcb7a2e_taskdl.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\taskdl.exe
Size 20.0KB
Processes 2632 (WannaCry.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4fef5e34143e646dbf9907c4374276f5
SHA1 47a9ad4125b6bd7c55e4e7da251e23f089407b8f
SHA256 4a468603fdcb7a2eb5770705898cf9ef37aade532a7964642ecd705a74794b79
CRC32 E969EF31
ssdeep 96:Udocv5e0e1wWtaLYjJN0yDGgI2u9+w5eOIMviS0jPtboyn15EWBwwWwT:6oL0edtJN7qvAZM6S0jP1oynkWBwwWg
Yara
  • UPX_Zero - UPX packed file
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 1e70eced64329ef4_tulips.jpg.wncry
Submit file
Filepath c:\users\public\pictures\sample pictures\tulips.jpg.wncry
Size 606.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 064041b0df5ff5626a4590c70e97d012
SHA1 d490ee833a8bbe1bd7f97df0add8350477a1cded
SHA256 1e70eced64329ef468bb987242e8490c5296b9e9a8184169f3299a043ac3fdf0
CRC32 9A1A5568
ssdeep 12288:kgj/KYUhKvkji5/h0Htne/kMEE4/UIMAhEErdn8sVYsBvSjWe:FbKYUng2Nn2Wd8WFNi
Yara None matched
VirusTotal Search for analysis
Name f68bdcee04cfc2d4_hibsys.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\hibsys.WNCRYT
Size 128.0MB
Processes 2632 (WannaCry.exe) 884 (taskdl.exe)
Type VISX image file
MD5 e605f5c4e80100278cf57b2a4c5270ad
SHA1 3aee548102eb9b243daad27b03b6c39a882d6bc8
SHA256 6b28b2d18521f8e5a2a2cb158a1ef3f90820f2bc3f2cfe0302a8295143ef90f0
CRC32 1C3E1B65
ssdeep 3:rn/3RXQXRABM:rnfWXRA6
Yara
  • Suspicious_Obfuscation_Script_2 - Suspicious obfuscation script (e.g. executable files)
VirusTotal Search for analysis
Name 4d346b19d39bbfab_es_py.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_py.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 c7c2b6c436415d08777d05db0c6c5e7d
SHA1 ba1f734583d4c2f7309c2ba4abe7a3102c6bc1e2
SHA256 4d346b19d39bbfabd50976bb1d8dd3d481108b75ca0fcb4a4d6c84c4f47c0dfa
CRC32 737B37F9
ssdeep 12:bkEf6IxAnQJPDxzkzUGiIbOMZtILkaamRjmhCRLdBwg:bkYeQJrx61iIVIw6U+dBP
Yara None matched
VirusTotal Search for analysis
Name 6d58d7f39876ff0a_141.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\141.WNCRYT
Size 3.8KB
Type ASCII text
MD5 523dd23f26d7110cb9183ad16c837417
SHA1 bddbe76bc0c30cffadd1b8db178c480e896d9b65
SHA256 6d58d7f39876ff0a74be833e6e8cec8e2131152b821c6311b7d203ce340c8521
CRC32 D6C5F18F
ssdeep 48:G8D/jSf5s80vWC0x5kTvgXTfODYE9lAUt:G8rmB0Z0x5kTv4sbt
Yara None matched
VirusTotal Search for analysis
Name a2fd645275db0ddf_260.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\260.WNCRYT
Size 1.5KB
Type ASCII text, with CRLF line terminators
MD5 67249126d0dfe26b3b97790ff02668f0
SHA1 f5f7f44bb4f0e787fba6c22cbe25f582bbaef466
SHA256 a2fd645275db0ddfd86d4e4298fbc9c6ea56d2c3ec2f5de2a1c6a0a7078b3266
CRC32 BDA2A4B6
ssdeep 24:zDeS9IqjEb4gF3BJLwjtTQGIGpUMYpHqkdfrxI0DNhBypLcuFwN3yPlLkYOc:WKIqjEkg5o5/IIUMYpKkPTB6pcwwByP1
Yara None matched
VirusTotal Search for analysis
Name 12ddc5b1a1a18dca_nn.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\nn.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7fe23a0cb71970d3365fa150189c4a2b
SHA1 fb5888671bd1df45773e78591e0037b901010905
SHA256 12ddc5b1a1a18dca3b409214676e3560ad1b1cf2d2a255b4955538f43aacf077
CRC32 495E9141
ssdeep 24:bkWHpAO/MN0yS9GqK1jkVtuToOxe5YyDL3szpGRimLk6K/5cYRmYn3iV/X2SWI:bkVOU/S9/K1wDu0Ogh340fkv5cYoYyVX
Yara None matched
VirusTotal Search for analysis
Name 91d31e2d4c347dfa_273.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\273.WNCRYT
Size 4.7KB
Type C source, ASCII text, with CRLF line terminators
MD5 05d659e666c549d5d80cabe83a67341e
SHA1 4099b86f852a975ff530c5f212a2df890e5a019f
SHA256 91d31e2d4c347dfaea4dc740ae311c69941b7504f301fb025a66117549f59d81
CRC32 28291D93
ssdeep 96:Yscrdb8tCUP1e93/9vHcLkb+padOjBMjNnjujSWpk2VYjnYjS22OvxO:DCr99BQuzNr2Vwk22xO
Yara None matched
VirusTotal Search for analysis
Name cca118698df7a2c0_unicodeobject.h.wncry
Submit file
Filepath c:\python27\include\unicodeobject.h.wncry
Size 52.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 316f9d08b0f1065cc1508349664bffae
SHA1 4a915b70d8080b030f28d7839123944e58f698ab
SHA256 cca118698df7a2c0d617028434a3263d73166771162170b538fa694ba9e7684e
CRC32 EABBD1E4
ssdeep 1536:RMnmcGeniuXrBGpIgtZL+dxGtiq61fSPF:umRm1bBhgZqdxKNAyF
Yara None matched
VirusTotal Search for analysis
Name 2a640815300d1fdc_759.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\759.WNCRYT
Size 600.0B
Type ASCII text, with very long lines
MD5 de7dab2295c6596749b7a92d9f23cf23
SHA1 4b34868937685e197988d2397a2c9be9c13a5f1e
SHA256 2a640815300d1fdc6d975ce314dc79bd9f5e1cd433858c4d9ec7176a422555cb
CRC32 AB4856D7
ssdeep 12:2TlZLG9qHRI/cKlZL5wyBIYlZLG9t+lZLG9FJ/cKlZL5wy5hcID8INdecIQdodsM:2DGqxIjCyBfGtiGFJjCy3cRcO
Yara None matched
VirusTotal Search for analysis
Name 462a8ff8fd051a81_340.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\340.WNCRYT
Size 1.1KB
Type GIF image data, version 89a, 48 x 75
MD5 7013cfc23ed23bff3bda4952266fa7f4
SHA1 e5b1ded49095332236439538ecd9dd0b1fd4934b
SHA256 462a8ff8fd051a8100e8c6c086f497e4056ace5b20b44791f4aab964b010a448
CRC32 84DC0CA4
ssdeep 24:DOfHIzP8hqiF+oyPOmp3XHhPBlMVvG0ffWLpfc:DGoPM+o0OmZXHhOv5WRc
Yara None matched
VirusTotal Search for analysis
Name 37dbbe5678f18aea_254.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\254.WNCRYT
Size 5.0KB
Type C source, ASCII text, with CRLF line terminators
MD5 5242f8b1cba41c82b2642d7758b73441
SHA1 7f0003bfba5bf60af8123dcbe4b512d6f02cdb46
SHA256 37dbbe5678f18aea5797db6b6f9112086a8caa5bb2af3bffd94ffa060324adaa
CRC32 AC171AED
ssdeep 96:eTJGcsGHJsBuHsindAjsidjCHMs439hPIqDPnC4kIDE:Ss4HVdAj1jCsfkqTLkr
Yara None matched
VirusTotal Search for analysis
Name a73ff313560fd934_tm01793060[[fn=원본]].dotx.wncry
Submit file
Size 53.3KB
Type data
MD5 b55b6f8aac6cadba4d5fb5cdb6a00128
SHA1 9e4e705c3a0e4caee528c791083dcf2854c4924e
SHA256 a73ff313560fd934aa0d1f4aef41e5c804821f22bd47e22449154acf1989cad2
CRC32 551EB0B2
ssdeep 1536:5Y0/eWDr7Rjbydz3SVfSzKqsC1D6IIPUOXCx47i5:j/TDhbydVzKq91sPUnx4u5
Yara None matched
VirusTotal Search for analysis
Name 5691dd8fa065f2e4_14.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\14.WNCRYT
Size 469.9KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 7182e65a297ba1222b243a501ea461b9
SHA1 515a67f4315e09fd90c984fdfb048ac281117521
SHA256 5691dd8fa065f2e42b826553bcfdbb854d8348ff0b10aea39b6d7ecef01b021e
CRC32 BCF4A9F4
ssdeep 12288:RA/2LeDhf4ns19oaVNeA/2LeDhf4ns196:R8261g+nVNe8261g+6
Yara None matched
VirusTotal Search for analysis
Name bc2b0424cf27bef6_667.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\667.WNCRYT
Size 251.0B
Type ASCII text
MD5 3fcdf0fc39c8e34f6270a646a996f663
SHA1 6999e82148e1d1799c389bcc6c6952d5514f4a4b
SHA256 bc2b0424cf27bef67f309e2b6dffef4d39c46f15d91c15e83e070c7fd4e20c9c
CRC32 4410E3FC
ssdeep 6:SlSyEtJLlpuoo6dmoPhkgvNLoPxsF3v6aZoPhk9+3vR6HK:4EnLzu8NrvNEK3v6a2J3voq
Yara None matched
VirusTotal Search for analysis
Name 24c7988158783a5b_cstringio.h.wncry
Submit file
Filepath c:\python27\include\cstringio.h.wncry
Size 2.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5ba0b6d587f4061f75bdde461175ba92
SHA1 eab4c45e5b7864176574256bc43635ada07eb0d6
SHA256 24c7988158783a5b558109075917c4510d56ddb42bf8d50a7a05cac3abe0767e
CRC32 4359369C
ssdeep 48:bkWnf/93XPFYyWTsrGGwcrhFoSsc8AGex9Aw16m8CB:oWH9XPFNW4RrF1snRebVr
Yara None matched
VirusTotal Search for analysis
Name 3c66dcf490a629a6_tokenize_tests.txt.wncry
Submit file
Filepath c:\python27\lib\test\tokenize_tests.txt.wncry
Size 2.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1d14f2653976932f3bcb09f0e03033e6
SHA1 3b7b7f1df7817d4d7ae835afe2a2337c0f1e2d60
SHA256 3c66dcf490a629a6986a6cd3b16d801d40470ac5735b8d08fe61c9b37a1ee803
CRC32 102113EC
ssdeep 48:bkF4XkckMJPLSvphiLby50d4lCpx0HuuR2iYMkZFSGCF4VAyptodazc7/bTXo0w9:oFNcnhSHiC5u4DHuSYlZFS94VXp/zgXs
Yara None matched
VirusTotal Search for analysis
Name 0d5216ca5f84c64b_588.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\588.WNCRYT
Size 70.0B
Type ASCII text, with no line terminators
MD5 ba0c6b291074ab21ca5c94cebd6cbc77
SHA1 bcf376926898ec47853f7a92d8534ace7bd6a2e1
SHA256 0d5216ca5f84c64bd63fae69edc59341ff18d8b4b84e81107efaa29b19877dfa
CRC32 B23C4074
ssdeep 3:H3zYPkpemLLs:H3k4eEQ
Yara None matched
VirusTotal Search for analysis
Name 3a2fd59d55746bc3_31.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\31.WNCRYT
Size 498.4KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 319d390951c580bb04dadc3c7f2d1665
SHA1 1f7bbb2f224256d4542579d3d71715e9c0800436
SHA256 3a2fd59d55746bc304406defb751bb38475f20a5a504769cbbe4dbd546dc6c5b
CRC32 A1679054
ssdeep 12288:ngFtRuH4ePyrOY1rAbek+gFtRuH4ePyrOY1rAbei:nOePySYCbeNOePySYCbei
Yara None matched
VirusTotal Search for analysis
Name 1669275ec677b456_48.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\48.WNCRYT
Size 1.4KB
Type SMTP mail, Non-ISO extended-ASCII text, with CRLF line terminators
MD5 a63ee84abd2909d5b80a81322a767206
SHA1 0a26917f76f38184321f06f0f20befd7af1df013
SHA256 1669275ec677b4567ca6c0e80b6cebd0e34f8aabbd1418eec633c7f8ddb5e388
CRC32 1F2EB31C
ssdeep 24:SGKVLDjkSAhX4F39M2ZF4ZNpDMN/DQHkmHZvt7bT+K3WHSQ:ShV/fGXW39NZF4xDGD5yVz+K6
Yara None matched
VirusTotal Search for analysis
Name 74d0a5664891d8ee_fr_be.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\fr_be.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 5d58e8a7ed2a9e42efe8f493039d8d30
SHA1 5471f7cde7ddd30ef13f6b85820686ae381fe601
SHA256 74d0a5664891d8ee13b5e83b18a744f9a5e6626a5253bd9b3fae9dd9e4e0e881
CRC32 BB9677F5
ssdeep 12:bkEc1j52+usaxtLyQs0eB8QdQeisXmhlKbfDX1A9S4q4c:bkQ+CFy/1ROe2KbrXAtc
Yara None matched
VirusTotal Search for analysis
Name b539e7e1d3891cec_246.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\246.WNCRYT
Size 2.1KB
Type C source, ASCII text, with CRLF line terminators
MD5 8ca81177d1f3923922521bd77d8ebb3a
SHA1 b29f970e4a400dfe3445212d17cef04610317a68
SHA256 b539e7e1d3891cec8d09a996e8c8d96565035781f9d5c5a87207322b03ba9e3a
CRC32 0DC5968A
ssdeep 48:fArTaSrIrHbWrFTf9lrXXqOGiAFrM1l/hY/eDmbyEA:fsaTb4TfTX7AezW2z
Yara None matched
VirusTotal Search for analysis
Name 8bbc62bccb999bd5_757.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\757.WNCRYT
Size 302.0B
Type ASCII text
MD5 ddeff32b1dbf9402fe07f62c622fec51
SHA1 4aabd11bcb12471d8824d168aef1bcec4abcfdf7
SHA256 8bbc62bccb999bd5b94100d8d448ea6fcb59f0e9a234f4fbdb30ecb7d804eb71
CRC32 5BDC80A5
ssdeep 6:DpjpdGwdFAr6KJalXakPEF/ksqatVdoM7dRSMEN/K9DoBLLatVdMgNL:DpjpdRAuKsXaZF/lqqYMZPQ/KV8Y
Yara None matched
VirusTotal Search for analysis
Name fc75d9966fa22815_msg_34.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_34.txt.wncry
Size 600.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 5ea8b14eaf03827ddca9a801b3bc5639
SHA1 07045c90c89d89b5f858eccfa0d4611179d53e4b
SHA256 fc75d9966fa228150ba0695dd762bffb2904b8ee494d09d71aab5d4a3a33faba
CRC32 061FF0C5
ssdeep 12:bkExMNzjJyYY2DPMYX2H/IBHSoHrFYaUh/b2KSeab13YHVLhzCDPQhCBQ:bkgSvcYPghfIBHSyFYaUh/b2KS7b13YV
Yara None matched
VirusTotal Search for analysis
Name ad626d44da46d7a5_readme.hwp.wncry
Submit file
Filepath c:\users\test22\documents\readme.hwp.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 6f7d19c99a8f8a39770369576baffa3f
SHA1 cfa91a14f3dcf6de7759c6dbf26b770ee14e2a1f
SHA256 ad626d44da46d7a5762d3e1e4bdf92e51879b43092684ee672ef6e1ef791c228
CRC32 56724F4F
ssdeep 6:bkED9cTak06XGnbNemvQitUT9kSzNqh0CheS3j4kp/WjtUE4nGOlHUd:bkED9boGbNemvQSg6cSz4kEUEME
Yara None matched
VirusTotal Search for analysis
Name a8ee987ad4aeaba8_fsrtltbncjg.docx.wncry
Submit file
Filepath c:\users\test22\documents\fsrtltbncjg.docx.wncry
Size 754.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 704d6e6524397c2f1fb43e4c11adfed5
SHA1 1f8b843c1466e5986c1e402e57fc3c5dea5603b2
SHA256 a8ee987ad4aeaba81b48b1a559e713d256eb140cf6eaa2765ddb8ea2b2634196
CRC32 FD987BFC
ssdeep 12288:kcEm9jYagGzps51oNlA7v6q/a1WbpbGibq4mVcPrtoQvmbyX4LXiBjJSZbvkdqq:bEWjY5V51obqi91WbxGibhSheE9viqq
Yara None matched
VirusTotal Search for analysis
Name f28caebe9bc6aa5a_libssp-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\TaskData\Tor\libssp-0.dll
Size 90.4KB
Processes 152 (@WanaDecryptor@.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 78581e243e2b41b17452da8d0b5b2a48
SHA1 eaefb59c31cf07e60a98af48c5348759586a61bb
SHA256 f28caebe9bc6aa5a72635acb4f0e24500494e306d8e8b2279e7930981281683f
CRC32 B6902F60
ssdeep 1536:pEiL38qIuOFcErNX5d0tRCZiBP2DrbjgpfM2ydbv:aiLsqIHFPpdiU2q
Yara
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 4d25a73e279190d8_{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x0000000000000005.db.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\all\microsoft\windows\caches\{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x0000000000000005.db.wncry
Size 280.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 978d64b44f81c5882cd75a4030bed807
SHA1 43e690bae99870b5b421b0d7944d8d7c19e2ceaf
SHA256 4d25a73e279190d8b9e83bf71dd8042cfca653c2219b1fee48685374bfc7abe9
CRC32 5C2EDA8B
ssdeep 6:bkENBHMuDzliGyXpe5qJhIHCxYZnJNBjGtd6mxL+uR+qYqTlJDybz:bkENxVlBqpIqJyvB6T6YCJHqX2bz
Yara None matched
VirusTotal Search for analysis
Name 2a76bd685bf500ee_sq.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\sq.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ecb02dbf1601f8ef88587c80d289b1c4
SHA1 c41feab005659f4dca53aa90c47b9db532298274
SHA256 2a76bd685bf500eeb91631f4a62f9e6f645a11dfb1d4de3c34e152cdaf85839c
CRC32 D2FB5135
ssdeep 24:bkV0X7H4lw4tUqXCqS5JnOH32PuIBx79zgbdc0EraOENIFve2GoOH18:bkV0rmDSMuZPN9zgbmhanNIFvTGfHK
Yara None matched
VirusTotal Search for analysis
Name e7e85353e559a647_usertile36.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 8069e690a23c6c533e7209fc672f9b23
SHA1 7c4c896dd84d8cf02eac5f74282a18323a0304e3
SHA256 e7e85353e559a647deb852fe76bcfeb7e0bac16c43ea107f523ca158e36159e0
CRC32 77878802
ssdeep 1536:HjHP4RrVl4VepoSi8StBkdGBmmAdpCmaF/:bxJRd7kHUF/
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name e1fbf4847da467d6_es.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d19b7e259f4ad86879f84a5f009744fb
SHA1 9b1f178fca66b9e58587aa68baf2470e5a11328f
SHA256 e1fbf4847da467d69041918529efe8745be404189ae5c25b85e5ed1a56f69e7b
CRC32 452B476D
ssdeep 24:bkpP/1OT04Twh9xMfvdJSNuEiCc5bc8b9ROj1PsWBlIIL4x5r/FXwEjVM8241D:bkpP/1+SA1pRhhC0GxL4PRJDhD
Yara None matched
VirusTotal Search for analysis
Name 49300611716876ea_234.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\234.WNCRYT
Size 1.1KB
Type C source, ASCII text, with CRLF line terminators
MD5 6db3a4d691bfef1b49e980ecf1139800
SHA1 f2b2831e67af6c7ed9ae24c0c0b6f438e6c78b97
SHA256 49300611716876ea81c4720a39ea89195f92179b66e8315e67915e47ba430d2e
CRC32 A62CC1D3
ssdeep 24:Gem2eDIHQhjdtx6dksqkxFgsMUSxPH0r9ndRD6FGPIFGu1nD:GeReNhjdrazYrFUVdRDJPLcnD
Yara None matched
VirusTotal Search for analysis
Name fb22ce9e99e9ed26_515.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\515.WNCRYT
Size 342.0B
Type MIME entity, ASCII text, with CRLF line terminators
MD5 188acaf8fa28f5fc6b1acbf5f998129e
SHA1 107f106e7a24e232484af7ef535609a0f6c5f0f0
SHA256 fb22ce9e99e9ed269d97155f345c30f3e2076ad4b9839e5e3a7d8a28be6fd43b
CRC32 A1A1587B
ssdeep 6:3XmNpW0h2ueFEYUphDqwCQmf8+MEAQ67JLvpRSZSFyQXUImdYyN0BAix:3XmFbGEYUphD3pmf86AQclZXRmS2ix
Yara None matched
VirusTotal Search for analysis
Name 8db0fa775206c26e_320.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\320.WNCRYT
Size 6.9KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 eb0d0cb8a3c8aa2d29736719551fae10
SHA1 45711a8a5846f4aed75a4c7308448539756ec3e1
SHA256 8db0fa775206c26ec5137206e048071ee60d7043a336104a593cc17f56b47087
CRC32 D3719588
ssdeep 96:z13WJgMSnwxtno9Ir4HumyEoYkxiHQJR1p8dJbKgdfCAnCZ/7uFsFVmoRiDRcZ:pUtvN8jbrCAnu5DZ
Yara None matched
VirusTotal Search for analysis
Name 1d9ae6b958df81e1_openfold.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\openfold.gif.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 2cc88eb9090e7fe5125ad1257c213e75
SHA1 f514fb980cd94ae836a19c3cfbec225b96832fd4
SHA256 1d9ae6b958df81e1b75555886dafb43130aab2a7346fc35bb7c8ed81402aec6a
CRC32 430757CD
ssdeep 6:bkEQtM9SVFPrjSF3swqZgyZUFFqp78FEIbhnx5xmUe7Fo6MiClQJWcVH:bkEQtM9wFTjSVoYSuEixjUFo6Mi50M
Yara None matched
VirusTotal Search for analysis
Name b8d354519bd4eb10_636.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\636.WNCRYT
Size 251.0B
Type ASCII text
MD5 3045036d8f0663e26796e4e8aff144e2
SHA1 6c9066396c107049d861cd0a9c98de8753782571
SHA256 b8d354519bd4eb1004eb7b25f4e23fd3ee7f533a5f491a46d19fd520ed34c930
CRC32 C6296B1C
ssdeep 6:SlSyEtJLlpuoo6dmoQW53FD/LoQGuX3v6ZhLoQWa+3v3F0fJ:4EnLzu8283FD/LJ3v6Xc3v3F4
Yara None matched
VirusTotal Search for analysis
Name f53e543b9d124693_sources.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyautogui-0.9.50-py2.7.egg-info\sources.txt.wncry
Size 936.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 f8524ad3e8293c20a0e845c85765f0f9
SHA1 59f19e7106f16ac2b3a02135a8bb59b7263efff2
SHA256 f53e543b9d124693fda3eeac6cbc34b83381cfc096c604563840be3c8d543b8a
CRC32 371660BD
ssdeep 24:bkyjVWMRx7pGw/TyunWkrWq1Nt+jTPK2Q6EIf:bky5WMDkiZWFqzUjTCr1+
Yara None matched
VirusTotal Search for analysis
Name 8eb8c79c649963d3_429.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\429.WNCRYT
Size 241.5KB
Type ASCII text, with very long lines
MD5 39e56b5c079f21b77238cd058bbd9d31
SHA1 e634636d9a685884985fb4c76d7b24f18dcfe6cd
SHA256 8eb8c79c649963d3e4a63ae544934c1b59cdbfc69ae1bd575b0a1808fa0dd116
CRC32 522748E4
ssdeep 6144:fmsl6f5w+aibOINiT2PDL00yYmCEo7BK7SDN+SWs+hDi/cpgmTPW6SZ7y5pjW19C:fxl6f5w+aibOINiT2PDL00yYmCEo7BK/
Yara None matched
VirusTotal Search for analysis
Name 7e783610f87c50f3_527.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\527.WNCRYT
Size 432.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 40fa81afdeb551de63ed213a2f052e33
SHA1 84c5887c6b141bf25a341118cae78fff601e40f6
SHA256 7e783610f87c50f34e493a6ab790e2b9f54e2e8a3d307be30299b2d54eb7c16f
CRC32 2D7E3751
ssdeep 12:jhrptTjGT6K3fD/Qdmi75RMLRq2mMQlLcmL7lWF1sv:jhrpw9v+PMLRq2mvcmoF1O
Yara None matched
VirusTotal Search for analysis
Name bae2b9a2eb82b29a_243.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\243.WNCRYT
Size 3.2KB
Type C source, ASCII text, with CRLF line terminators
MD5 e587e4d5e86d5fbc6cedb2afc767502c
SHA1 2d4872e4700ea469bb83d5619e3b2ae678ec7c8b
SHA256 bae2b9a2eb82b29a162c996f027dc29c4d90fa74374f2260e9215ef3cf9c5dab
CRC32 1837FD31
ssdeep 48:hSqkWRgj6vVTXDGFLWJUGOf9pw7spRTHtYPH7HXEmInNpptx5pzNPz:IUKLGDOk7AY0N/tx5pzN7
Yara None matched
VirusTotal Search for analysis
Name 8329bcbadc7f8153_222.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\222.WNCRYT
Size 7.3KB
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 8c24c4084cdc3b7e7f7a88444a012bfc
SHA1 5ab806618497189342722d42dc382623ac3e1b55
SHA256 8329bcbadc7f81539a4969ca13f0be5b8eb7652b912324a1926fc9bfb6ec005a
CRC32 72E7DE4B
ssdeep 192:RCVPxjERdQe/lb9iLbRvhSXH3DsDw3zF55Mz6h:RcFERdXlRiLbujuw3zF55jh
Yara None matched
VirusTotal Search for analysis
Name ef1f66cd11ce00a4_icon_16.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\images\icon_16.png.wncry
Size 840.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 230736ce4b65f784afb52f37c1133624
SHA1 a3e877c855d56146b6f26a5c6aa4cc250ff140ba
SHA256 ef1f66cd11ce00a4b095ba3a3935b946f51de0be43a0a3253f59655e9bb97a82
CRC32 91D9BD67
ssdeep 24:bk17fdNXimTLyhwlinyJTo3AjAVHYDRL95fm/3diNHjrVd3vUjvao6V:bk17lNVLykTK0AmdL9sAnVFUjvGV
Yara None matched
VirusTotal Search for analysis
Name 19563225ce787569_652.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\652.WNCRYT
Size 251.0B
Type ASCII text
MD5 aeb569c12a50b8c4a57c8034f666c1b3
SHA1 24d8b096dd8f1cfa101d6f36606d003d4fcc7b4d
SHA256 19563225ce7875696c6aa2c156e6438292de436b58f8d7c23253e3132069f9a2
CRC32 2433BE74
ssdeep 6:SlSyEtJLlpuoo6dmo06GriP/FLoeW3v6rZo06T+3vrig6HK:4EnLzu8ZG+nFy3v6rAK3v+lq
Yara None matched
VirusTotal Search for analysis
Name 6d08b23a2647e2eb_msg_46.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_46.txt.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ff096d0ed8709be7adfdbd8027309092
SHA1 d9349d6bbf03de31717bda60a73879c1b7f14512
SHA256 6d08b23a2647e2ebe122bcdcfb21dcd3ef9382f278d8987b063d3db45ce740a7
CRC32 BC9430A2
ssdeep 24:bkuWcfIZjYmSwo6T2Rr/rGxsgfGqVBdqqOgOMzhnDlWa2OGceahPl5yDGZyHSpM:bku5gZ0mtGBjj8LVucjrWaIMfZ4
Yara None matched
VirusTotal Search for analysis
Name 15f67f4e04b08279_badcert.pem.wncry
Submit file
Filepath c:\python27\lib\test\badcert.pem.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 0cc31f8f4e5dd9c197485d09c8971217
SHA1 3bcaaf7c6f55b2404d8c31aadb135c2af774a4f6
SHA256 15f67f4e04b08279fc0673bee773ab1e662fcf9234c9ce9a9a708e38d789e3ce
CRC32 535ACF58
ssdeep 48:bkTx61b7589QKDFgtXObYgyNhEaGMYsLat/:o165758WK+tXYKhERW8/
Yara None matched
VirusTotal Search for analysis
Name 5a2eb85e7f9a2995_309.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\309.WNCRYT
Size 1.6KB
Type PEM certificate
MD5 3881a1a51e4c72ae0fccc1305b7bf15c
SHA1 62594afa497e619d4539c18fb134c9713b9424ba
SHA256 5a2eb85e7f9a29956c4a1ede39962cd9c451fd3008b0953878b1d6b0b90b2776
CRC32 42DB6C27
ssdeep 48:LrnfLQFhHt72hQVBkeBWILyH61fQYROEjZaG7HN0b2q:LrncLHteQMhILymfLU94NVq
Yara None matched
VirusTotal Search for analysis
Name 061598d929668c2a_451.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\451.WNCRYT
Size 20.7KB
Type Microsoft Word 2007+
MD5 76a8e594ecc9b7433fe6a5f47c7446e5
SHA1 0d71f7a28f355a774cac7eb97c250e1d75f7c8b8
SHA256 061598d929668c2a175411e1ca744c122ad9991b4954439c22eaf893a8105597
CRC32 439368A4
ssdeep 384:Pjl/vSY1IoRT7MLkle/Ro8I0RNp8va07hjKjPsP5Foxcz:4YfMLks/mlKNLYJK4Lz
Yara
  • zip_file_format - ZIP file format
  • docx - Word 2007 file format detection
VirusTotal Search for analysis
Name c19b6f81415b0072_python.h.wncry
Submit file
Filepath c:\python27\include\python.h.wncry
Size 4.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 abb9f375a0d7bf9ba28303d876b92993
SHA1 a3c4f7d9a2139d5730801ccd72749c9041bf0897
SHA256 c19b6f81415b007238e51312b4161889d57df0442db0a12df1795276bfb9fd6c
CRC32 2946492E
ssdeep 96:oLzp4F7O1y2d5983ylvwrapuIcHiYPV0pNlnYCmHz89Pp5lB:+Ccy2j983yV6NIczIDDmHz89p5lB
Yara None matched
VirusTotal Search for analysis
Name 6a5aa3da47a340e5_python-ast.h.wncry
Submit file
Filepath c:\python27\include\python-ast.h.wncry
Size 21.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 92e4e9a7d98534e3157d787ee710f3aa
SHA1 6f0b4fb7bd68e5c2cfae9fb7844d389c1ce1e015
SHA256 6a5aa3da47a340e54f4fc9edeb7be02eafef372a91805b46aa706ed27b4f2e80
CRC32 CDDB7FC3
ssdeep 384:1FbfEVJYoeUjvtUY5Qd17pqPIUTjoCzo5K5ve4l+dP1mIlwMXWTLbvpiQ:1FbcVJYSvtUz17shICkkl+dzeMGvbMQ
Yara None matched
VirusTotal Search for analysis
Name bb80d8fa49b35ddf_shift_jisx0213.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\shift_jisx0213.txt.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e5848c9c2e61ed4adcef6da2317d0d4b
SHA1 acf7874b23f85a7649ec36daa3982fedf7ae163d
SHA256 bb80d8fa49b35ddfb4af97a163d58259f9badbaea93177d9edebf54c6f356f2f
CRC32 B5C2716B
ssdeep 24:bk1FoW1AGdzGr20d7FPcIOt6zCPWj6iIwj38gBgSdz6CsNuk59/n:bkzoWSMZGFp3zCPWmiIwj38nSF6hUO
Yara None matched
VirusTotal Search for analysis
Name ce754c5aa146cf2a_ca.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ca.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 de568a65c0842b20ed10505ebb233fdb
SHA1 c37bcc1aa4b992bcf7c898263c685652c559c3cb
SHA256 ce754c5aa146cf2adb3ed3ce201be617dcde5b2ade37de802f4d9f8931fae937
CRC32 0E1EB0FB
ssdeep 24:bkxLkHzklVPkf1ewg6aofbtppMiSXFYW4C2dKOx+gVvCYt:bkxLkHAlVPWEwft/p3mV2Dl
Yara None matched
VirusTotal Search for analysis
Name ced194682b639c4f_427.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\427.WNCRYT
Size 23.3KB
Type ASCII text, with very long lines
MD5 1cbbc1c1dda3c0425d6372209c1b57ec
SHA1 720a5ce91916e2800f58ee8bc0dbd0af46df1714
SHA256 ced194682b639c4fbf9e8c47d3267c344a59a198b134665b18d75b5f95de9676
CRC32 D7BBBE76
ssdeep 384:g3LfuaPLFxumGkolmy+Qx61/bgjLMrK37akBOvLsvf5/eZi5WHJSR07WR+JQO8dV:g3LfuaPLFxumGkolmy+Qx61/bgjLMrK/
Yara None matched
VirusTotal Search for analysis
Name 34da4e43eaa6737e_qaxytxewuxzprzy.rtf.wncry
Submit file
Filepath c:\users\test22\documents\qaxytxewuxzprzy.rtf.wncry
Size 678.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e7a560e457ca05ba3fbb726554d12616
SHA1 d5e63134433bdf9d3b9bc2e00d1ec4957bc47763
SHA256 34da4e43eaa6737e9bffdbbffd78aa35a862827968c7a9e94a3d2f994f82ccef
CRC32 D55AA95D
ssdeep 12288:uagXekg3PG1Fkpidb5p4WwwMtp9JrRMOCtiSu0Nco6T/WKeu9CQa3mt:uagVqS2iF4YMvCOqib/WIS3mt
Yara None matched
VirusTotal Search for analysis
Name 7468df7b259b01c4_268.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\268.WNCRYT
Size 2.1KB
Type C source, ASCII text, with CRLF line terminators
MD5 5f339c14762177cbda7c1871c00454eb
SHA1 244dd723a96b6a6722875b6fd19b7e25efccfbed
SHA256 7468df7b259b01c43d7d21605c4649a4a36747ebf4749527bbeb4ff261dad652
CRC32 9C4B7836
ssdeep 48:Ia2teebx1fQAikOlXixVXLVXLVgbAmV7ZUFHgHYl6wPPDDw3E1fyTEV:Ia2tjbx1oAnIixVXLVXLVgbVV7ZUFHgI
Yara None matched
VirusTotal Search for analysis
Name 79d0e320160bf501_datetime.h.wncry
Submit file
Filepath c:\python27\include\datetime.h.wncry
Size 8.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fd3968722a266b49b6d5493aa5807e2f
SHA1 34583d1af1fe1901eed5e433caff6a863fe5c3f1
SHA256 79d0e320160bf5010f0faee672d49388d15de9937d666629c1b9167c9ce67d16
CRC32 0C83258D
ssdeep 192:GY1ETANBmdbDcYK9LePQSdcvSE0+suSqbrejXH:GehWDcZLePLavSE0+suHrAXH
Yara None matched
VirusTotal Search for analysis
Name abc0af1b56104ca2_previews_opt_out.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\previews_opt_out.db.wncry
Size 16.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ba8bf4b78c67f3e6a10ef5dccf3d087e
SHA1 a3e815f7eb9e4457ff41cc716eef583345ac4fee
SHA256 abc0af1b56104ca215891c2d0efa7efe831b5f6685f3ce6a0a42ee7f10e93801
CRC32 5784BADE
ssdeep 384:+kDX6GXpz2S086wHW6xNygODhehQR4Ubh47ChNAnDcGclXBWAlwwjW+SIUDJc8B:lrrCfsNsDB4kh4WXyOBflwwdSIUx
Yara None matched
VirusTotal Search for analysis
Name a204bda615c99f45_sources.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pytweening-1.0.3-py2.7.egg-info\sources.txt.wncry
Size 584.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 8e605f46995ab08e0e50dd0f205cae56
SHA1 5b752dcd80f44aa15680f9aa2257cdba53b745a4
SHA256 a204bda615c99f45b20eaead4427602d1b506df6d0d5b5c426fa89b726baff74
CRC32 EEBBC448
ssdeep 12:bkEsROaHjns+zYUKDLmT0XcwSXBKe2N8iU:bkpc+zcSwMRKej
Yara None matched
VirusTotal Search for analysis
Name 7d780165196d7619_cp949-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\cp949-utf8.txt.wncry
Size 776.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 bfa3be42b1beea418ac5e2fedda9a9dd
SHA1 0db685ea5492c9dbc624c5a9027e90a068a80cb0
SHA256 7d780165196d7619d641c3b049660970a98fb2d1ede86f5ad810d3765526c795
CRC32 46887705
ssdeep 24:bkOIvofzma0BSu2Uz7xg4sAAHF5zagdYl57sW2EdhL:bkO/fiaNDk7a4sA8Fx1d+26Z
Yara None matched
VirusTotal Search for analysis
Name f122f6155845faa6_571.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\571.WNCRYT
Size 320.0B
Type ASCII text
MD5 9328a6ccc4ebb2fd0f76dbc11b3d218a
SHA1 0099f76e0ab5295acf05a04674a271988a24c915
SHA256 f122f6155845faa6565724ccac1e042c121ee59d362fe7d450a6c05834bd1a68
CRC32 103D5CC5
ssdeep 6:1qQQ0QPmN8AFe9Z78hk4VcnJT5R4znJTLnznJznWNnJznWuROcnJznWMEZJCcnJb:1A0QPmN8AFe0hJcBW5ziMc4Ycfpn
Yara None matched
VirusTotal Search for analysis
Name 988c32e7a165b76e_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\128.png.wncry
Size 3.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1f11f55e1cb7dcab8bd578b7b736cb7e
SHA1 86aeb16fd7148ac34b6135ebf1e2cf5ebe001009
SHA256 988c32e7a165b76ea6604336e8974745e79395f86c85d071b1128d0b97143d8e
CRC32 3CD71D0C
ssdeep 96:o3iPkQdg6uNkDBJxSlYzNc/PhDaN8MffQw1ocnKxZN3L:uQdgCBrSi2Za2obaD3L
Yara None matched
VirusTotal Search for analysis
Name fd95b38a3bebd594_114.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\114.WNCRYT
Size 1.2KB
Type ASCII text
MD5 d5deb8effe6298858f9d1b9fad0ea525
SHA1 973df40d0464bce10eb5991806d9990b65ab0f82
SHA256 fd95b38a3bebd59468bdc2890bac59df31c352e17f2e77c82471e1ca89469802
CRC32 4F54B03E
ssdeep 24:4azu8lmZG0me3AEcGo49bJcpF9gT9PCbF5uld0vVcASAr8svJ5vk3:46TGAE8Q/PG5dv//Lk3
Yara None matched
VirusTotal Search for analysis
Name dad037f67e5057a8_516.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\516.WNCRYT
Size 236.0B
Type text/plain; charset="us-ascii", ASCII text, with CRLF line terminators
MD5 99edf61eb3bf925bf8c2de00674abeda
SHA1 04a34eb7ed94c2918470a6eb0091207e3066ca81
SHA256 dad037f67e5057a8a1ae9ecbd18694f5ec82a9afac2241166671600bc89cba66
CRC32 E4E15CBC
ssdeep 6:/eQ8KMW0Y0aoXmMWdQRiKi+6QfoEZhXf1Kue4EVK379BWYk5Ian:/eQeaoXmM76QfZHP1KumVK37zWTln
Yara None matched
VirusTotal Search for analysis
Name 85618c0cc7a741f4_251.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\251.WNCRYT
Size 5.8KB
Type C source, ASCII text, with CRLF line terminators
MD5 95bc610b7174fdad65c39da44608b075
SHA1 607d12af5f01311260ef57d387585454e6d27bfd
SHA256 85618c0cc7a741f4db27ab7801f9ce2e40f63c5691c0053ccbc8ee26d47a5464
CRC32 1C060905
ssdeep 96:os26x6k8um0lQohfg4D21CKbo5MvgDrPFZ27G1SbfTZYQF3QfkDKtkoQ5EEDHhv:dsk8/ah5MvgDrPFZ2yqfTZYQxQMDmkoO
Yara None matched
VirusTotal Search for analysis
Name b6fba6df93c4c541_pymath.h.wncry
Submit file
Filepath c:\python27\include\pymath.h.wncry
Size 7.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 17975ff75f44e91d39f7ddd2128269dd
SHA1 2640015b62e8f529b457731e475a90b4fbb8bd6a
SHA256 b6fba6df93c4c5416e75f05c7d8c44bd2b7e7720eadd7225cf5c4f0048fed1b8
CRC32 9B491D4C
ssdeep 192:PgdD3F+a6O8WQCOXa/7+WGuzVf4UmoY5Ce7w7qTHoLkc6WKGMv:P+p8vCuu6WGuzGUmoY5vJoL6GMv
Yara None matched
VirusTotal Search for analysis
Name daaa3d72c5b76313_test_doctest4.txt.wncry
Submit file
Filepath c:\python27\lib\test\test_doctest4.txt.wncry
Size 616.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 5f5020cf3e20b1a1a3072b5dd577d5c7
SHA1 03bba0755e376d460092867893525bfbb76f6989
SHA256 daaa3d72c5b7631399146cad2bf1b9035cbb172cac4adc1a2690267d72f1ad34
CRC32 76251B23
ssdeep 12:bkE/7qZb+3ZuzvmYu1WMsDbp3hmF/rqKHRtYynCGgkeXCaefTvO0zXb6:bkEqZb+DsMsXp3YFjEkeV4TvXXb6
Yara None matched
VirusTotal Search for analysis
Name 6c488d57b338ded0_pine_lumber.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\pine_lumber.jpg.wncry
Size 4.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d58215f8d3d50aec531609bc33f7f9ac
SHA1 f8c0a64bea32821d76f553f8e96dd8dac378094b
SHA256 6c488d57b338ded04063918e9186ccf37ed14cab500ac954536ec4bdb721dde3
CRC32 CB46A0BB
ssdeep 96:olm1D5EbuBHFIC+3dQrdReB0KAa/Kdgbnwj/PJXoRuB4RKwklT:QMGbk13/em5sKdg8/PxGGnwklT
Yara None matched
VirusTotal Search for analysis
Name cfbc5299faf453eb_75.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\75.WNCRYT
Size 1.1KB
Type UTF-8 Unicode text, with CRLF line terminators
MD5 b78c31d234a2c8445cb670a78358d2a8
SHA1 f765a69964677d5ef451254e23a779253b774cdb
SHA256 cfbc5299faf453eb4530a8f8133fb48f20012d8849120db3936e92fee97a16aa
CRC32 25F35346
ssdeep 24:tFIJD5Uft4dUAPJxd0bH8Gl5NFW4szQF+/LOiqM33N6+F6ka:tFI9540JxdvGXu4aPKiqMtLgka
Yara None matched
VirusTotal Search for analysis
Name 1c3500b439c02678_topbar_floating_button_hover.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\topbar_floating_button_hover.png.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 71ca71af55476c647d5113e3d39936fb
SHA1 b67ad4118ced874cfc518c707da87c5821268d84
SHA256 1c3500b439c02678d1829134eaf50df98bae7038d7ad0179cc104e10e58b37a7
CRC32 53CC4626
ssdeep 12:bkE9CA3sqfSpUn4ZI7WomF7+v397RVWmEu9eXStKzQ:bkYCAcqPn4i+B6397RrEu9eitoQ
Yara None matched
VirusTotal Search for analysis
Name 61862c34d562b184_458.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\458.WNCRYT
Size 288.0KB
Type SQLite 3.x database, last written using SQLite version 3038003
MD5 39c107106df5aec4995782fd43af668c
SHA1 05e4d7c9e42bf61b0f0556ebc30789d92988e9ab
SHA256 61862c34d562b184326fa3e7e52ff323d8f260a856ef453b6a92ea0935eb9a6f
CRC32 E54AA09B
ssdeep 192:dva0zkVmvQhyn+Zoz679fqlQbGhMHPaVAL23vj:d1zkVmvQhyn+Zoz67i
Yara None matched
VirusTotal Search for analysis
Name c1c74ab4ad221e89_msg_18.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_18.txt.wncry
Size 520.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a2009e6023bc621e595b79de4081a52d
SHA1 e295bff22122a26ea2b5b12ed6eaca1a16313f91
SHA256 c1c74ab4ad221e89983b71683e8cd6aef8c11bbab1a3862e9fb4fc86c8c90809
CRC32 29E1B00B
ssdeep 12:bkEaTuLy6dWmL9pNuuwd9L/pXFvuDfwRqiKgMqgXQuxi8Kto9:bkhuL/WmL/N3Mh/vmDwq3gMhBQo9
Yara None matched
VirusTotal Search for analysis
Name decd001e84b93162_303.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\303.WNCRYT
Size 9.4KB
Type ASCII text, with CRLF line terminators
MD5 112e4e050c21a89c34b07deeca8028e8
SHA1 96a099194834410a80ec0084cb2ddae7dc14a1e2
SHA256 decd001e84b93162cfde052bcea5acfc49d525c980d157536b189a79d9fab43f
CRC32 F40A29C3
ssdeep 192:He6Y0kezFaNUEQr92ZUDOk3Nu5VnCgZvf/miKs4IqE2Ltp0vE:HvXkOUNUEQr9+Ej3NsVCqvfTKs5qxJp5
Yara None matched
VirusTotal Search for analysis
Name 0668843e7bbb539b_537.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\537.WNCRYT
Size 998.0B
Type news or mail, ASCII text, with CRLF line terminators
MD5 e443739d1be8dec602b74461ee9e4226
SHA1 3461e168bbcc33f134718399510f604161b446a5
SHA256 0668843e7bbb539bc7def1dfb0ebe4e581abd8e5eb21e9fefee7cf2b23b6f6c7
CRC32 D19822AD
ssdeep 24:7EkWqY2jS0Zj+Xm0xUWWHDjS0VClA38+m1F:/WqY2fhLYWjfglA38+m1F
Yara None matched
VirusTotal Search for analysis
Name a8cd3cabab9b5dae_empymllgiyrcx.rtf.wncry
Submit file
Filepath c:\users\test22\documents\empymllgiyrcx.rtf.wncry
Size 880.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3c9c1730180a484a2700f4063e2890f5
SHA1 76e17b7a1e803c00bd2e3a379eeac77ff88e8a40
SHA256 a8cd3cabab9b5dae7eb7f36dbd162d1c535e88919c791220f657f964df5bd9d2
CRC32 BAA9EECB
ssdeep 24576:DGZeVBav1VnuDIZKebhoj6olwVQOvOqaqJ9/P5KEcA26f0II:KQSTuDufhoj6olwx9pX2o0
Yara None matched
VirusTotal Search for analysis
Name 5afa4753afa048c6_m_czech.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_czech.wnry
Size 39.6KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 537efeecdfa94cc421e58fd82a58ba9e
SHA1 3609456e16bc16ba447979f3aa69221290ec17d0
SHA256 5afa4753afa048c6d6c39327ce674f27f5f6e5d3f2a060b7a8aed61725481150
CRC32 56FADFD9
ssdeep 384:SheftipUENLFsPzy3EFHjHdg2yG2gv8n8+8zfB8k8F8i8k1Z8M8I818E838C8A8s:Shef3jHd2G26nyMZrS14g
Yara None matched
VirusTotal Search for analysis
Name a1dad75ae966830f_758.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\758.WNCRYT
Size 309.0B
Type ASCII text
MD5 f804cf5bc46bdc9aa8023878219312b5
SHA1 433819a76e7cb5cef1e8fb34288750d1fdb4de1d
SHA256 a1dad75ae966830fcd31e694d476aa11e69cc2ea60aa7bb2cd838cf8545040c8
CRC32 037015B4
ssdeep 6:zCPrX7xBXiGFrLKH2lMHXIgUVRJw5CPrX+RfKh4QLKH2lMHXIgUVRJwt:zU9x/KRXIzJwU+khdKRXIzJQ
Yara
  • Suspicious_Obfuscation_Script_2 - Suspicious obfuscation script (e.g. executable files)
VirusTotal Search for analysis
Name d87517555c00e0f7_587.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\587.WNCRYT
Size 38.0B
Type ASCII text
MD5 c911255b0c11098c6ab7edf664fdc8b3
SHA1 c3d3c7436574c24ec30386b6da3807b01731b671
SHA256 d87517555c00e0f7dfd7181316bdc6b135d729a3da3babe51baa0d27fe2ee138
CRC32 91015C30
ssdeep 3:hW4LWghk5QfQYv:xWgPv
Yara None matched
VirusTotal Search for analysis
Name cd12a14b62869499_565.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\565.WNCRYT
Size 7.0B
Type ASCII text
MD5 f5e8bde65f7789f9d0cacb34ccf12dee
SHA1 bde99abe2e7f154825f84361e37bac56f5cb68f7
SHA256 cd12a14b62869499a8c3f3d8ba9276d52282980ca8aeb1687c00bb406b17b798
CRC32 33D4C757
ssdeep 3:6:6
Yara None matched
VirusTotal Search for analysis
Name 9bac1f5a4ef2dfe4_547.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\547.WNCRYT
Size 821.0B
Type ASCII text, with CRLF line terminators
MD5 979bf0985b9b796d53c07be40f02b132
SHA1 362d7cfdc35d3249d6dfc544503dd388879fb151
SHA256 9bac1f5a4ef2dfe428df9afbecd59d250efc5cbd42a93fcf9b4c6be9e08e7693
CRC32 A4D53B7C
ssdeep 24:QULHO2vm90vY6ExE2L1Z4NM36YSi7dJeGFr6cK:rDxvm90Ho9LCC6YSi72GfK
Yara None matched
VirusTotal Search for analysis
Name 2ca2d550e603d74d_taskse.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\taskse.exe
Size 20.0KB
Processes 2632 (WannaCry.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 8495400f199ac77853c53b5a3f278f3e
SHA1 be5d6279874da315e3080b06083757aad9b32c23
SHA256 2ca2d550e603d74dedda03156023135b38da3630cb014e3d00b1263358c5f00d
CRC32 BC193579
ssdeep 96:UjpvOHheaCDCNIOgTegoddPtboyX7cvp0EWy1HlWwr:UjVWEam7ofP1oyX7olWUHlW0
Yara
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 90be59a898bbbf2b_56.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\56.WNCRYT
Size 1.9KB
Type UTF-8 Unicode text, with CRLF line terminators
MD5 c213e2e8d30cd588d64d94d92b13396f
SHA1 e85dc689c62cd4ec29d542d8101fcaf805425d1c
SHA256 90be59a898bbbf2b18b8487ecb0cc1fff351f5141abd02455d34d853334b6121
CRC32 1726669F
ssdeep 48:XvFiKKqadiXS9d/h0GSZUUXjZQYyfqRtRNXQA0xc:XNpumSmGSZUUOQrNXD3
Yara None matched
VirusTotal Search for analysis
Name 2208b61e34d7341a_sr.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\sr.msg.wncry
Size 2.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b20d3885a6e0b60b6e22c241317c9159
SHA1 d0fa72760a0fe2971f9209a3a3451d6757482540
SHA256 2208b61e34d7341adec0691eff7eeaf6c53c9763c69b2e4254f884be85dc3e3c
CRC32 1F612E7F
ssdeep 48:bkdAhl6OikHF/OWp6eDlwz5CIFW6SWPKZkz8gxbEYe3vjDG3pscpPug:oE66F/Xdi3zvP/xbZMKHp7
Yara None matched
VirusTotal Search for analysis
Name 09cc4a9023249c4a_3r4gt47h.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\3r4gt47h.txt.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 646e1e75fa8c57d58af48877dc83fda3
SHA1 6d231a6196a90a0cae1986e7e19a5b6e465b34d9
SHA256 09cc4a9023249c4a734297fc5b34274ff168c34f2f53880411dcceaf8b8ccd99
CRC32 745986E3
ssdeep 6:bkE8ehiApms4Z5RKjmQ1qdsGdHS4LcgYHN9QyyOS4haOLfCTI+8rC3lJ:bkE8eoAsHYjmQ1uF2zNVU4ha+88Wr
Yara None matched
VirusTotal Search for analysis
Name 761c41c9889a9418_zen_coding_epp.js.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\editplus\zen_coding_epp.js.wncry
Size 216.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a05c9b554bd542b164e28d96e0a83427
SHA1 a744b3d84e9d13ad1b84edf72862d799e9e55907
SHA256 761c41c9889a9418272083c332290867410121b1c790b9f3b075eded8594c8dc
CRC32 D62CFA97
ssdeep 6144:GRobgcJVfaR433RwkuHN3Dn/tNnrpaov5TEGR:GaJVfhxsht+oFEGR
Yara None matched
VirusTotal Search for analysis
Name 7defc9af8087ee56_usertile20.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 9b700f9e1e8197252cb3705eb06e7c53
SHA1 3e79b386e3e2c1b24ed513112130ff1dc7e0e27c
SHA256 7defc9af8087ee56e36ca628f7a06929cd71667a65ad49aeabd5dd87bc2c74c1
CRC32 BBF8F35F
ssdeep 1536:mtqWuqKB2iffQTx2ClXInPpUSFFOTxelk:OqWlC1YTHluU1Tz
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 6120ae4676de7401_msg_11.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_11.txt.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 7a4c316044a0b3dfe56c05858df7e5d5
SHA1 fc0a4f9897dfcd47e0073b5745c7151788d2b490
SHA256 6120ae4676de7401eae622d78330de8cab1c0b3dfabc50d2568fc17f18d99262
CRC32 BE9B90B1
ssdeep 12:bkECWVSlFtlC0V3M45Ra1B4SfCDoud7kqL/9lb9U:bkBTjPV3M45Raj4SfCDoKI8U
Yara None matched
VirusTotal Search for analysis
Name ec0b25c734fdb71c_onyeiyahxng.docx.wncry
Submit file
Filepath c:\users\test22\documents\onyeiyahxng.docx.wncry
Size 899.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 9f741a49ae0003fb4916e9f6c65b4d7f
SHA1 0f2248432da38b4282e426b2de054e67d772b57a
SHA256 ec0b25c734fdb71cee4d5d2447d97eb1c092431a3ce68e0590a74311a70856c3
CRC32 9BC74FB0
ssdeep 24576:L/HDEy8gPp2Aueuw2PcKtzNxRzWax+vc6jBEz0vWtWQR:rjEyV0TerYtt3RzAvBjBEz0vkWQR
Yara None matched
VirusTotal Search for analysis
Name 42921cba7850b73e_kiprylexef.doc.wncry
Submit file
Filepath c:\users\test22\documents\kiprylexef.doc.wncry
Size 123.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4547d7a720aa4febd96cb641c407df47
SHA1 5e18703d396a1d3864ef45afbe221172ba69a991
SHA256 42921cba7850b73ea8f32f4f034f7f7522ddeef92aa7e5479e6a9c5d749defb6
CRC32 3772811A
ssdeep 3072:ScjdJfcEPluWlcvxqCk50OEM6qvtdFuxmMy2z3YWPFI+k:SedSEHlwYCi0cvN0xyZWPu3
Yara None matched
VirusTotal Search for analysis
Name c2b121f5c2353939_topbar_floating_button_hover.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\images\topbar_floating_button_hover.png.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 3c16a5354cda3f8c44b117edad655dc7
SHA1 dd6bb2e8363be979005d48543e4ec1be74aadca7
SHA256 c2b121f5c2353939fbd2d2a89a08d47154c1d60fe7b6b29d1fde21a5d3e267e0
CRC32 8B55DE1D
ssdeep 6:bkE+OPxy/rTfHWP8j3U73+kL5iuHcldJ9aEr/wvhebR4X0OhLaPtc5wHKT1Chobi:bkE/PqrTfH0sy3L5TkBw4q3hmvBkxan
Yara None matched
VirusTotal Search for analysis
Name 3ee947f897a3fb02_logolarge.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\images\logolarge.gif.wncry
Size 11.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 71d920f201512631891d43d661aafc33
SHA1 b4fa784255abb8fe269ab8d6855eb54d14e72033
SHA256 3ee947f897a3fb028f883f63928a5fafe339734dd9b84e98053e2b57d5558ced
CRC32 5C02FD5B
ssdeep 192:GRjCdW6s4VhfkZkGdpCvmXT8ziDZ9TiLTW31j7dzWPOcT9W7VQXe:9d6I1A6mDr19WvWJ7UPOfuXe
Yara None matched
VirusTotal Search for analysis
Name f49f4e1c7142bf7a_677.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\677.WNCRYT
Size 966.0B
Type ASCII text
MD5 413a264b40eebeb28605481a3405d27d
SHA1 9c2efa6326c62962dcd83ba8d16d89616d2c5b77
SHA256 f49f4e1c7142bf7a82fc2b9fc075171ae45903fe69131478c15219d72bbaad33
CRC32 1AA878DA
ssdeep 12:4EnLzu8z4md0eKwCW44mtls79cp32AqghoPx9ab43gWgw3SeWOdSyECYf5AQZ0eD:4azu806vCmgs7aB2seFkhq+9
Yara None matched
VirusTotal Search for analysis
Name 84b524eb26f6a1e3_msg_03.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_03.txt.wncry
Size 664.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 4c8a92cd1f13b64a7ca7679670eaca00
SHA1 5cc46827ac6dc9cfcd277832a148a90047a7b68c
SHA256 84b524eb26f6a1e37eb008b73a76351dd88c76033191ee9269d517f05c0ecf5c
CRC32 59866337
ssdeep 12:bkEBNErxOYWSJs0afC7vaRzwDRWdXiS+bFfb1Cb1XvwH7YaxRN3tJVW2J2fNSLoA:bk+AY2gC7CF9dsfb1W2BxRNHVLyNO7x
Yara None matched
VirusTotal Search for analysis
Name 244b7816b7293558_gv_gb.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\gv_gb.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 2f971d679d49d53eb4720234881400d0
SHA1 5cb89f264bf9ed2e91484cb02e46b955648156b1
SHA256 244b7816b72935589d34b939110b38f532e1a4bfa8272c7b3dcc313d04bc03ca
CRC32 1A219E48
ssdeep 12:bkES1ZfkHmytRcb9w1lKVRGJtnX6vnDzfOEMxwXP:bkP1ZfkHnYba10VRGDMDDOEwO
Yara None matched
VirusTotal Search for analysis
Name 931d7fbc6e7be1b6_stringobject.h.wncry
Submit file
Filepath c:\python27\include\stringobject.h.wncry
Size 8.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a4eb16c4b5722ba9c1ef04e38da96d03
SHA1 f356c60efdb0015ae584f6185cc2e7c91abcb320
SHA256 931d7fbc6e7be1b692d6cb10d4d716eab1e8c6c93a48f69772d3d18fd73e7800
CRC32 74C869BE
ssdeep 192:KlRH9uD2ux7BL3KYBey8zY7Qy7i7uME3y:KbH8xdKYkXSFyuMb
Yara None matched
VirusTotal Search for analysis
Name 486a8b71c0f9241a_693.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\693.WNCRYT
Size 90.0B
Type GIF image data, version 89a, 16 x 12
MD5 d43a31bbb551890c7b2c98423519bb1f
SHA1 38cf4225fdc5906ccfff655b26f48e4785115904
SHA256 486a8b71c0f9241a5bff2b275e8f011349076bf4fdd777ed1458eb050c0633bb
CRC32 5A68007C
ssdeep 3:Cw6/R/Myj1C/xlDnOhmiq+umZY9DM9/hE:R6/R/zRC2hmf+MD4y
Yara None matched
VirusTotal Search for analysis
Name 1c1fde08453c143a_nullbytecert.pem.wncry
Submit file
Filepath c:\python27\lib\test\nullbytecert.pem.wncry
Size 5.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d467613a1d0073422f1331932e319ce7
SHA1 4a3327efd22e5d67b1901569f15570b100c5539d
SHA256 1c1fde08453c143ad111691570abf544962bd6c0ba50dae137b61250fe002d41
CRC32 3A927E4C
ssdeep 96:oVUFznpVF8xb4U6b5i/4iWzdPaG63CaDT83zMy+cCQ2KGhboiRgIJtv0o5Gim:6UFzfFfb5qEdACaDI3zMBcCht7/tv0oM
Yara None matched
VirusTotal Search for analysis
Name dd4f5edfd1a6f0e9_testtar.tar.wncry
Submit file
Filepath c:\python27\lib\test\testtar.tar.wncry
Size 275.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7a5636a6d1c19732e922c1ee31442a69
SHA1 d4857b10e8c0b8c74c401efecf9c9470875ff8ce
SHA256 dd4f5edfd1a6f0e9adb7c4e1dfd31e0b6972d8a2c2ebabe7e4fc8362d9e45b41
CRC32 93C2BE17
ssdeep 6144:WpBcNJF0P5rkzt5BqeEelrF7pwvzFzWbBn8CtC0dW52PiLmoO:WYNJF0Bkz3BrEIwzJCn8CtFdW8PLoO
Yara None matched
VirusTotal Search for analysis
Name fafe65db09bdcb86_105.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\105.WNCRYT
Size 1.7KB
Type ASCII text
MD5 349823390798df68270e4db46c3ca863
SHA1 814f9506fcd8b592c22a47023e73457c469b2f53
SHA256 fafe65db09bdcb863742fda8705bcd1c31b59e0dd8a3b347ea6dec2596cee0e9
CRC32 C087866A
ssdeep 24:4azu8dVYe48VcOVcz1HtDVcqiVca4mGE18VcRBkEVcRfVcRMsVcqiVca4mGE18VI:465v4bNVO7GQbBkDuM4O7GQbBkDuh3x
Yara None matched
VirusTotal Search for analysis
Name 17db6113a08cc996_da.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\da.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 748da4dece7b6e80b0d001eb06edf83a
SHA1 8ef67a33ddf4b963f9773ef037e23543111ac8e6
SHA256 17db6113a08cc996c22634cf1d933c484a868757067b9bcdf18a9871537cc274
CRC32 D94FBC68
ssdeep 24:bkqn/BgGXzyeD+CdAUTZm/adS76tOfosKMMU8o1GAdl82mz+vEEtqXZMzvHrRUV:bkIXzf+eAUdm/svcfTLso1GA82mz+vvM
Yara None matched
VirusTotal Search for analysis
Name df989bbb7b1a4258_230.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\230.WNCRYT
Size 3.0KB
Type C source, ASCII text, with CRLF line terminators
MD5 9f318b9c5346a94372c3e37c0baf8421
SHA1 1a80ae8581abbd4e2b88b333b6bb39cd07dc151c
SHA256 df989bbb7b1a425821bc68e1eca9cd745c12932aa02efcc83d700b47f013d04e
CRC32 33C5E400
ssdeep 48:ZzeMCMnbOBlEEm5s12GTeZh78b/uEGv7N5+0NJxG1i/GnUbAXhIYDC32W39eCCBI:teFMnbOBlz27ScAeYOGmURE
Yara None matched
VirusTotal Search for analysis
Name 200d3ca5aaa8497a_lv.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\lv.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 801ebb4b5e10a2c3bd504410fb4a595c
SHA1 7edc293811d061709e3d2778bd39c6fcbb575650
SHA256 200d3ca5aaa8497ad4bf3e3bdbc9d7b28fa288088c48337d419487118cf99abb
CRC32 289E150B
ssdeep 24:bkUToFWdm6t6SkFqic8c015WZkEN2GMhHDC4fi8KowihfZ3gTH4d00:bkitkFqR8RaNmHG4tRF3uF0
Yara None matched
VirusTotal Search for analysis
Name 55985bbf9c4ee723_pyport.h.wncry
Submit file
Filepath c:\python27\include\pyport.h.wncry
Size 33.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fc747f630fe5b36bbed5e04ec9d2b578
SHA1 54ecf584b8b7a5a7c01bba50d8285b902f4ce6ed
SHA256 55985bbf9c4ee72365df1124500c25b6329c02a38ceab8ca675024d39525fd4a
CRC32 F34B726D
ssdeep 768:eF954GBxtss3Do2KsO5vvBbZhC422Yv7JmI7AHs5KLPV4:i9Hsszo2G5vF3C4qDJ5sHs54u
Yara None matched
VirusTotal Search for analysis
Name 8380644ba27707bf_hr.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\hr.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 9a23951b502eb3053d7579cda37c0f7d
SHA1 a5c8dbd56bb41a525ac56fa340aa8e19cdfb72b7
SHA256 8380644ba27707bfdffbe1bdd0c154e3139d327937844b25192d04270a1e2c2c
CRC32 90634DA3
ssdeep 24:bkIBiPXDznjOHl0R8gMQkiXDWg9wGxE3OEEqyxay59eWLCFIi4llB5TRrKXS39RZ:bkISXD/OHlJQ3zD9wGm3nEvxN8iCFxOD
Yara None matched
VirusTotal Search for analysis
Name 1f30e009d66dbead_act_fold.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\act_fold.gif.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b68a6dd9570bab6d597baef60e42734f
SHA1 a8c1689b978763cbd18b101d36d6c76a5b5f36d7
SHA256 1f30e009d66dbeadeeb10f0f328219cce9a526a01a49b2d47ab79ba31343f7fa
CRC32 F2E9973C
ssdeep 6:bkEuZ6V/zRZQXasgW2FQ7NREq/K/cZDsAmKocYWTk2zjUos6gsekSOZLUwDxrUc:bkEuZ6V/1uXNgWN7NREqi/KJk8UosEpp
Yara None matched
VirusTotal Search for analysis
Name 035ab91712944509_contentscript_bin_prod.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\contentscript_bin_prod.js.wncry
Size 4.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 61d60e63437d4702038c1e03f1a850a6
SHA1 550d6315c1e5aa6504e946cd64781f9871550175
SHA256 035ab917129445090286460e0c65b7c18a0b5e422623dcc6a4e6c8f3c8f6f098
CRC32 53581BB2
ssdeep 96:o2td4tddZCnQBUy0bJdKE0tYvZUo/CRMjh82FdaxugAihOz:MNCnk0bJdK1tY2oKMV8nugAiEz
Yara None matched
VirusTotal Search for analysis
Name 60d7c1ac404d1834_craw_window.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\craw_window.js.wncry
Size 255.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b8b59128da145af2e37b56f0f2d9d2ac
SHA1 3165b99d8e78db89c1e254177b8a9611c34e3816
SHA256 60d7c1ac404d183493a02d6148477a2c08bcd858423e0e025cb0b242b928d4bd
CRC32 6EA823B1
ssdeep 6144:zc2BQAuwWfgx+cXF/grImoSL+OrX6cwceNe/CdqYI2zrah:zc68xgxTXbmoSXb6FcgDqv2zO
Yara None matched
VirusTotal Search for analysis
Name 7694587b6473cb6c_46.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\46.WNCRYT
Size 5.2KB
Type MIME entity, ASCII text, with CRLF line terminators
MD5 534a696c77551afd0fcd49247e77175f
SHA1 7854fdb096bc8a1f72e218bc24b240f856784f0f
SHA256 7694587b6473cb6c60b3833b8251d2fe0c27dc47da751c45a194daa9a05af4d5
CRC32 52ABAE39
ssdeep 96:mFv/qR3WZ1OBQmC2LsdbdWqRdMGCa3UYSDytFKZ0Ru:EeygSmRLs/8zaxqytFS0Ru
Yara None matched
VirusTotal Search for analysis
Name 090ba1f78fcb3e4b_key4.db.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\profiles\qxo5wa6x.default-release\key4.db.wncry
Size 288.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e6a36efe67c5bef42744c499fcf93695
SHA1 7541ec853fe98314584a7b03c60bb18d2de15fd9
SHA256 090ba1f78fcb3e4b4d79636e1fa12b880be17b7a4d78dffe1c3738c177003206
CRC32 6D67C8BD
ssdeep 6144:R/Som7BsPKvZ04fsDWeySez8PLmUYXHC5zSlxF96ncEhO8L7Il/qo0:R/SoyBsPKvm3DpvOw6UYXHC5zHcE8g7t
Yara None matched
VirusTotal Search for analysis
Name fa2f707cc0315c5f_286.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\286.WNCRYT
Size 3.7KB
Type C source, ASCII text, with CRLF line terminators
MD5 b175dce211005930324afb03b5ee76af
SHA1 d1b53c462e42d2df7064757f1a0f7d01d5882dad
SHA256 fa2f707cc0315c5fd8b6a989991b6c0709d2ad8e960a31cd4f34cfe2132b2c9c
CRC32 B316B73D
ssdeep 96:QAJiCpweFkUr4UxFW/vY8Yy/vB9wWOKxZsrGO6SlLyPK:dJdpweGUr4UxM3Y5EbwwsrWI
Yara None matched
VirusTotal Search for analysis
Name 7b34ff6cc5433bc8_162.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\162.WNCRYT
Size 2.1KB
Type ASCII text, with CRLF line terminators
MD5 80ca7677e58a4997fd22f095d325afb0
SHA1 0b53bd1d1dc417e9b5b449d50999833581a54e93
SHA256 7b34ff6cc5433bc886652172ae2eac24e2bc1c3ca5e23f1a495095fe6727ae0f
CRC32 641AB674
ssdeep 48:BbFmV5uMrGj7d3j9J3GnrK1Yk08i5jD9j7PyIIgDUD:BZWcUuNjT3mK1YUItTyII3
Yara None matched
VirusTotal Search for analysis
Name cf492cbd73a6c230_659.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\659.WNCRYT
Size 417.0B
Type ASCII text
MD5 044baaa627ad3c3585d229865a678357
SHA1 9d64038c00253a7eeda4921b9c5e34690e185061
SHA256 cf492cbd73a6c230725225d70566b6e46d5730bd3f63879781de4433965620be
CRC32 692C785D
ssdeep 12:4EnLzu82vGz7AhF/Q3vf3v6TANv+K3vz7AA7:4azu8vPm/ivfvF9xvP9
Yara None matched
VirusTotal Search for analysis
Name d58462b629fdad04_fa_in.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\fa_in.msg.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6a3fc19e70a74ff56e1521189fa2d0ab
SHA1 99add7732378d429ad35cb22745a5ea423e546a4
SHA256 d58462b629fdad04bdb306e3df3d040964f0189ac9d3c0b81cb553f479039af4
CRC32 00FB3982
ssdeep 48:bkyNGBc+hIq8OOKgvnqyT0SA9pi3rLgXMUfXL1uLGQAfJbky4yL+x:oyNGBlIxObaLAbi3rLuMUPB4CBApx
Yara None matched
VirusTotal Search for analysis
Name a1d71dc0d202ab3f_thumbcache_sr.db.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\current\appdata\local\microsoft\windows\explorer\thumbcache_sr.db.wncry
Size 312.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 704bb4b9b78f1a2387cb3101033cd0f9
SHA1 e98ec15e7b96cd97df121ccd1d9164aecb69d79c
SHA256 a1d71dc0d202ab3f7d2e43658e19885ac5e77a9b704e0ad244bbb9606742e6ce
CRC32 BE850F95
ssdeep 6:bkE3p19knEjzOEmZ5/8r35BUrJCqnX7yaEFJ9iDjArrwh/nEIl3H:bkE3p1jjZmZ5UBUrJCqnLyv/iDgrwh/9
Yara None matched
VirusTotal Search for analysis
Name 365b156e4f174f01_stars.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\stars.jpg.wncry
Size 7.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e13786ba8080acaa9170c9f3cdd864c0
SHA1 e7919cc3a63f6147769d590abe48618dedb87af1
SHA256 365b156e4f174f01decba53a520c4defe2f2276d2fb51b36a5387183796f0463
CRC32 965DD01A
ssdeep 192:NzchWz+uTMc6X9jroadxemQai8g6tS7JCiQ:NzcMCuTL6X93Xo3a3g6taQ
Yara None matched
VirusTotal Search for analysis
Name 8f61db8f7235309e_math_testcases.txt.wncry
Submit file
Filepath c:\python27\lib\test\math_testcases.txt.wncry
Size 16.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6088d3b761cc7296961a6ac210b92da6
SHA1 05b80db7d02a228eb6792f3e8ab409fb57e7308f
SHA256 8f61db8f7235309e52cd931788cefb670f44d19f5892d98849f9756044403353
CRC32 949F4C7F
ssdeep 192:GbNNfHpwFIWvfJOKjr64BV5HCXozB9uskH8RFNwenkiC87DU8mvZDWDMwqR5SzPp:McBOorxRB9AIeUyMRgczPe3gLzkgx7
Yara None matched
VirusTotal Search for analysis
Name da25e3e5e5b8d7b3_lighthouse.jpg.wncry
Submit file
Filepath c:\users\public\pictures\sample pictures\lighthouse.jpg.wncry
Size 548.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 89ddbfb1350c3be84070a647a345c9b0
SHA1 45807b8359277bc6574fd6f23eb681d715550d4a
SHA256 da25e3e5e5b8d7b39ba30d1af9866d337d2dedec20ef69eef47d0dd3d3237ae3
CRC32 DCCFB290
ssdeep 12288:Ot772ABeW91xjTFaHvTl0gOAR3ppYyof/nEemZMlD9lHJN3ljRS:caIfjaR0mLof/nE4L5jI
Yara None matched
VirusTotal Search for analysis
Name 0dd74ebfba50c8c0_294.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\294.WNCRYT
Size 275.5KB
Type ASCII text
MD5 d79543631317645443cd8652746857e6
SHA1 f50feb701f2e461d998dc857ac542fe8ada2830e
SHA256 0dd74ebfba50c8c07cccd36089749216b3d59fb10df2a6deecfea1fc8632b9e9
CRC32 85B54F7D
ssdeep 6144:GriCfLXd1YU58fVuKlnm5plZ0PXCRrcMBHADwYC+MslE:GrdT3YZuz5LwCRrcMOje
Yara None matched
VirusTotal Search for analysis
Name 753c002de0970d07_741.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\741.WNCRYT
Size 242.0B
Type ASCII text
MD5 a2a7a6c00091ead24b4476bc6131c8f9
SHA1 15db0dcf727237b47007b90bbb539bccb28f715f
SHA256 753c002de0970d0732be1cacba9ac3e38e75b28d2e8221f9fa7fbb477011b71a
CRC32 04848E58
ssdeep 6:jjBb2yEeUgNjS+IW2iRon1aRJ12iRga80DJAiHZ:jv/TNjrIW2i6n8RJ12iyabJnZ
Yara None matched
VirusTotal Search for analysis
Name 7d3a956663c529d0_624.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\624.WNCRYT
Size 259.0B
Type ASCII text
MD5 764e70363a437eca938dec17e615608b
SHA1 2296073ae8cc421780e8a3bcd58312d6fb2f5bfc
SHA256 7d3a956663c529d07c8a9610414356de717f3a2a2ce9b331b052367270acea94
CRC32 20162427
ssdeep 6:SlSyEtJLlpuoo6dmovtvflD/Lo/E3v6xH5ovto+3vflm6PYv:4EnLzu81tvflD/SE3v6etF3vflm6q
Yara None matched
VirusTotal Search for analysis
Name 9cd54ec24cbdbec5_683.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\683.WNCRYT
Size 279.0B
Type ASCII text
MD5 b08e30850ca849068d06a99b4e216892
SHA1 11b5e95ff4d822e76a1b9c28eec2bc5e95e5e362
SHA256 9cd54ec24cbdbec5e4fe543dda8ca95390678d432d33201fa1c32b61f8fe225a
CRC32 28A46A35
ssdeep 6:SlSyEtJLlpuoo6dmo4gPI5og9X3vG5og9X3v6X5o49+3vnFDoAov:4EnLzu8WgAhF3v8F3v6JI3v9dy
Yara None matched
VirusTotal Search for analysis
Name 12b3e6af37d2c123_528.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\528.WNCRYT
Size 779.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 93a55370834e521fa145f7f4516e57a8
SHA1 1bdd69ef24df26cd18f1e54daf7610f6491f4ab0
SHA256 12b3e6af37d2c123f3771bd97bc4de3fb9dce3eb01bb0ea2b24a2af7d6059d59
CRC32 A1DC5D29
ssdeep 24:jhrpoBG1v+PMLRq2m0/QCcg8wcs73bO1F1PR6cmiEIF:Bpow1vLwtxbg8VsrbOP1PR6cmiEM
Yara None matched
VirusTotal Search for analysis
Name 9fda5a41e5f1095d_icon_16.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\icon_16.png.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 15ef24eaaea6212424bf4abc96afac09
SHA1 b6e4149730119ce168862b3d0644b4f4d77264d3
SHA256 9fda5a41e5f1095d759299a9536e0a016bf978c9603d4669b3308fd22d30a7fe
CRC32 CCCED596
ssdeep 12:bkEWwbISezjiECWGDTGfCIQ4nJBhINQ+xJAi6q+:bkubLeshofQURmfxJaq+
Yara None matched
VirusTotal Search for analysis
Name b5fb07530290cdd4_729.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\729.WNCRYT
Size 556.0B
Type PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
MD5 06eb6c8c7c17e3dec6171898cfd96f8f
SHA1 403cf0dd5baf9c9d8bb05491a57d1dfe3b9cb21c
SHA256 b5fb07530290cdd4c7d952aca289ef2bdfa947aeb6af89716783a9618889c15d
CRC32 F30C5520
ssdeep 12:6v/7QVgSK8L10JNoSybmYo5BHkPRaian/VsTYxD:xVnK8L1uopbmn6KsYxD
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name ed651a2c8eea8b37_145.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\145.WNCRYT
Size 3.8KB
Type ASCII text
MD5 ad6c8299d63c606f46b91e55e923020a
SHA1 4e5eef89c33b152661c7d5d74bbe54ae3c215cc8
SHA256 ed651a2c8eea8b373af753c35ec7dfd91a284f2cafca8697985c83676d382e8b
CRC32 7840A579
ssdeep 48:9714EhrzeUv0xrFf+/eR0Mqp+cIFIXd/JcrtCcuUc6Sq4Pe:97148efrF2GSMqgcIFIXdhAene
Yara None matched
VirusTotal Search for analysis
Name a225dc2e17999fc5_mirroring_cast_streaming.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\mirroring_cast_streaming.js.wncry
Size 36.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6302e6db1ed5a1c88220de1637b188eb
SHA1 855813b5dbce9c0d77b009a3e40de2ce5619dea8
SHA256 a225dc2e17999fc5b6a8a879b6c75012e3bb8882992efa7d3f0622b9515c3dcc
CRC32 F4FC1532
ssdeep 768:i55eM0jyEeTIRxOPcGBoebSV7qJfo8bgrMSwTzdSCfe8doaz:XM0uEeTGOPcQ7I7qh6rMxSWTz
Yara None matched
VirusTotal Search for analysis
Name 0e0ab935cee99d8d_building blocks.dotx.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\document building blocks\1042\building blocks.dotx.wncry
Size 374.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 66c65e050184e82a3cb67487edadfce4
SHA1 e68621df38fb29050e79a693187b78e58fed9f14
SHA256 0e0ab935cee99d8dc241152e35c9f57edce08989d2882688278e8a4696a690a2
CRC32 6D811CCE
ssdeep 6144:25SdyjdVjjxdcd2sj/T4No2BSe0sT01fN6apnbdN5ezNii0OlaXjlzbyMQZHZjcB:qSdmjji2kCqRbgb084BzgH1alzTUzs
Yara None matched
VirusTotal Search for analysis
Name 322489459f3b208f_cs.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\cs.msg.wncry
Size 1.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d82b0ff80472f6d20e41c7c3f95a6258
SHA1 ca959bff6d824a5d0a2de4da4c27284eb2055786
SHA256 322489459f3b208f6107ef60f65ff2cb54cb9375cf54898f389a4c16c6f6bc75
CRC32 87F760FF
ssdeep 48:bkNO6j+A853MadZPRCW3gDzqOMSzXp0eakCCGQQ:op7E8afsW3O2S+kCCNQ
Yara None matched
VirusTotal Search for analysis
Name 5a3c0a2ab821c55b_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyperclip-1.8.0-py2.7.egg-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 8e97810e2fca3aa13e3ab5722c4c4243
SHA1 cde795b37275d4c2248fbe7a90b04134279a7c41
SHA256 5a3c0a2ab821c55b7ce3e41bed54795c89c970d0f211edd1db96501db4eb3ef9
CRC32 209DE30E
ssdeep 3:bkElL3Q11bFpYb6dTYh1BtZcz3CiL5bJU1IWN4upQqe6oeIeMODp7PCODDd4REvt:bkE9+LYbBjXZoFJsjpoeITUVPcGvtN9n
Yara None matched
VirusTotal Search for analysis
Name 5d8980686fd6f3d4_487.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\487.WNCRYT
Size 931.0B
Type C source, ASCII text, with CRLF line terminators
MD5 36fc7c208a69ada005878009069a6f68
SHA1 2bb51ee41a2bc0034882267e5daeb5365b88b4a8
SHA256 5d8980686fd6f3d4e715360feecb52d1be97a71c8475fb7e40764cd2e8934c13
CRC32 155393FB
ssdeep 24:EkHPYxutxVOO/hFafJUyKAdQMsU9FILl0innO9:EgPSurj0x74n4
Yara None matched
VirusTotal Search for analysis
Name cb806443c899d437_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pytweening-1.0.3-py2.7.egg-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 067179881b0cf4dc1acf47c39c3f91c4
SHA1 5b3bea3455a49a5b21b8dcf23f4a3afe8ba6c78d
SHA256 cb806443c899d43735fdfdadba52628afe5db95a64304df59b87a9b08f4b1319
CRC32 7BCACD3A
ssdeep 6:bkEg//0pODll1aILwsJQUnDIqfu5wgwOmyRSG0JIEV:bkEg//0pU1vLwd2IqKwKmpJB
Yara None matched
VirusTotal Search for analysis
Name bbcdb12efa0aee3d_nl.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\nl.msg.wncry
Size 7.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 42f64b056c40be406261afa1f2f7955f
SHA1 50088943966e42027b517f76ad6e51c3c678fd3a
SHA256 bbcdb12efa0aee3d1af0c09f41da17d3ba4b0ebae22b2f517c3cd8248b542076
CRC32 B487183F
ssdeep 192:OG2wL+d+w/cP99V2HCHHsCRgwm5oV8KoN1dzW:fL+wpJ2HCn7zVlq1dzW
Yara None matched
VirusTotal Search for analysis
Name 611a85cff2192625_feedback_script.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\feedback_script.js.wncry
Size 23.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 93a06e04e148e95c4812c35f0854db58
SHA1 27c66e05531f79619c47a08fc11f5305e8c18d4d
SHA256 611a85cff219262548068fc6b84439b8d3ad1d601f8c4da6653615372c3b3e44
CRC32 E93D2280
ssdeep 384:6xyD/PqJ6YssCKKGWnXheFQxXOxr/MyMw8k6m/hH1I1ks32ZVmpvNasOj7aJp63p:lDnq+rGi0uxarmzbmpO72ZVmpv4seV3p
Yara None matched
VirusTotal Search for analysis
Name c6208beb489f38b8_428.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\428.WNCRYT
Size 36.3KB
Type ASCII text, with very long lines
MD5 9fba2e5f4eb5ac1622c5ad7cb75693f7
SHA1 f9c3b904bc579280790a46466d126b1b40738727
SHA256 c6208beb489f38b87388cd2bd0bacf43c5374a77065d31cd7ae0a119ece77f50
CRC32 838B2265
ssdeep 384:peZHtoRLs2c2M5rP8grU/38oBrfrg2JvdSaaFmYgrK625N5WTUUeJt7LRfse4DlR:mE2s/gJamGirHRmZmKbNs4Mu
Yara None matched
VirusTotal Search for analysis
Name 6f2208217a6d2f65_425.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\425.WNCRYT
Size 48.2KB
Type ASCII text, with very long lines
MD5 397295edd14a7e5f61f0cb2ef7d8ba2d
SHA1 7e5a440bdb410a8cd3f37e3f2e563197f17104b5
SHA256 6f2208217a6d2f656e623dfd9e0809bc04f7da45e2e92bd43f0cdd8f1e320393
CRC32 1D1C025B
ssdeep 1536:TYrsCcbxfRLD2j3yUtzipU2o0IrJw3vBEsXHldjevPzjoDvxLk2XbsQoE2wZqPQE:TYrsCcbdRLD2j3yUtziK2o0IrJw3vBEN
Yara None matched
VirusTotal Search for analysis
Name 9527316cc182304f_ixm980fm.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\ixm980fm.txt.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 4218fa463975aa5804b1c4ab0ab8df09
SHA1 3d90e8840166880195498fdc62e0934affa2508f
SHA256 9527316cc182304f0a905250889550dfdcb8983fa2529b44035c46ded9ac7a3f
CRC32 1728BC6F
ssdeep 6:bkEJw7p6HDM67BZ5hv98n8OGK3j2pjQ/tuZ0qcmpYSGXGtKu991xvEmS5wVC6d:bkECp6Q8h9+lGK3jELdpYSqCvX1ptSyl
Yara None matched
VirusTotal Search for analysis
Name 3287fcaca23ec0d2_750.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\750.WNCRYT
Size 186.0B
Type ASCII text
MD5 688e7836d0a7a0bb540019e7b5c6bef6
SHA1 c102436c58eac4cc910392d67e8d67be0fe42d10
SHA256 3287fcaca23ec0d2dbe66125dd3c2e2a3ce84851e0aeb5504df99134d25b28b1
CRC32 B3BC2DE5
ssdeep 3:qPCIvQT2vxnLGK8TVtQ/Tk/PSTS+VvxejPiCMZ0jLRdLQ3QS2vxnLGK8TVs5cSzv:yB8TVtQ/BTJpeo0j1dLQ3W8TVCcSizST
Yara None matched
VirusTotal Search for analysis
Name 416c3eebc4dacf45_classobject.h.wncry
Submit file
Filepath c:\python27\include\classobject.h.wncry
Size 3.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ac87386f5cfba341b6054dceb340d378
SHA1 3a402fbb4cfad13945a8834bd69846d96929ddc2
SHA256 416c3eebc4dacf45160519dfa3108efd1597702d56fc10758d36ef04c7884a14
CRC32 84D4C0A5
ssdeep 96:oogwrbj0r6H/6m43ij1Pj8GIQjgfIRAkumE:Ljp1yiCtJ
Yara None matched
VirusTotal Search for analysis
Name 6ef2b7fae1f2b19e_main.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\main.js.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e3a27fc91445ed953833e6206019908e
SHA1 e41e7b048da1e1c6e6d8b160b669713574ce7b13
SHA256 6ef2b7fae1f2b19ecafc1986099df759d3e27956a6cb5bb8d15d5e04c3198965
CRC32 E6B32DBB
ssdeep 6:bkEN4ss9L5sN0yE6zqKNw8sAOQqGvk9Xdt5Vs3Hvt7cnwERQfSLIa0gd:bkEqss+0P6+KXOQ1UXdtcXF7cnXQOIjC
Yara None matched
VirusTotal Search for analysis
Name 956f24b56b088d39_iso2022_kr-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\iso2022_kr-utf8.txt.wncry
Size 856.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 fc610a1a0d86f144f4437ecef088e2cb
SHA1 659972fd49b6684054d1ec5092cee5c367e4bd09
SHA256 956f24b56b088d3960b054e33185e872861b0a2cb4bb401861069be531c27ee3
CRC32 9CACBCCE
ssdeep 24:bkRnwk3ni2iG7nJBdYrU1KQSpcscudbtBI53en5N:bkRAG7nJvVwpAlen5N
Yara None matched
VirusTotal Search for analysis
Name e5093ad0ac6a5db6_pwrdlogo200.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\images\pwrdlogo200.gif.wncry
Size 3.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7a53133344d5e7afa9aa5ece3113d492
SHA1 16b40d25ef9dc7650fdd3e907a9284c82f7b7af2
SHA256 e5093ad0ac6a5db6a78aaecda3141e50b88a8b78d5985feb21a9ff40cf5946d1
CRC32 C8B38F94
ssdeep 96:oWBWnsApwhcA2tP28C/ujTyjRx8WGD1XRr5gJzxAAsK:X0nfwhcA+/C/uj4/6Xg7
Yara None matched
VirusTotal Search for analysis
Name 809599cb0b86c74f_en_gb.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\en_gb.msg.wncry
Size 344.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 5995363c3148563e2348443ea858e931
SHA1 360165a2effb37edd25af33df29e635621a8bc74
SHA256 809599cb0b86c74f303d672e30ee0eed0c08508aeb826aa4c029f450cfe7063a
CRC32 5F03681B
ssdeep 6:bkETVtCbBU3ZfJTPBB21P8dawydX8WrN1PNRJB1mIA5E/tKCMp+7v3wJKssaMDU4:bkETLCbshT56MawQX8Wp1Plj/cItKCMw
Yara None matched
VirusTotal Search for analysis
Name c379694ecf060219_601.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\601.WNCRYT
Size 801.0B
Type Non-ISO extended-ASCII text, with CRLF line terminators
MD5 442ba3da2a95df4041c6e8e1e8289c10
SHA1 ff6e71897a78e7a88ca27630a9fabd57386c374d
SHA256 c379694ecf06021978748a2ddfdd23d3be8ef23a365b1673432e9c507c2159dc
CRC32 DFDCBE2F
ssdeep 24:tFVbagi38LyidBkmhGwBQ+tSHPBITXqgGGMXLchBf7RUcZ1ZG:tFVbliJidBkOBQ+WPBkGrXLchTUcpG
Yara None matched
VirusTotal Search for analysis
Name 9a7ce4b9b7467797_fi.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\fi.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4ad8599d5022de6d2b7c5cf4a0e2cabc
SHA1 5866794e4232ff8cea423bb2b953243fea46b147
SHA256 9a7ce4b9b74677978f9b4cad4f735ff29cd7abf0f566f90485a89af508082ffc
CRC32 2C976AD8
ssdeep 24:bkY2Z6yuyIM5mmks+aj1lZhtv2FHGCLABJ9WttvFLOnvrcRdxYvDto:bkY2ZaCbN+aZLjqHGsu9yLOvwRoy
Yara None matched
VirusTotal Search for analysis
Name 1f21838b244c80f8_m_vietnamese.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_vietnamese.wnry
Size 91.6KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 8419be28a0dcec3f55823620922b00fa
SHA1 2e4791f9cdfca8abf345d606f313d22b36c46b92
SHA256 1f21838b244c80f8bed6f6977aa8a557b419cf22ba35b1fd4bf0f98989c5bdf8
CRC32 C7ED65F7
ssdeep 384:SheftipUENLFsPzy3EFHjHdW2YG22cViQj3KiG8dpcH8iEriG8E8O83Jz52sxG8h:Shef3jHdWG2+oPZrS14i
Yara None matched
VirusTotal Search for analysis
Name d29e4fc08f16dae8_tix.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\demos\bitmaps\tix.gif.wncry
Size 11.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c1b6340d22f03b439374788152870a69
SHA1 e2d7240c1534e298f383f83c05420f45cd3691c6
SHA256 d29e4fc08f16dae8b75e48b40e005f2886f86c05ebc94006e99fe808fd2a175d
CRC32 20E21FB4
ssdeep 192:yGhp4lBILSa1gAmWNxTOpX5ktMJnhqPy0R+wCl0gFqsqvt54AqRzln+HI6sH9sFt:hp8yL/y6IXyMJn0KM+Z0oA4JRzl+H9sW
Yara None matched
VirusTotal Search for analysis
Name 7856a43341329f4f_icon_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\icon_128.png.wncry
Size 3.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 bf1f5b63c275c2a178314517e2c53459
SHA1 59935c15b9b01b8271c1b91b5aab29d4e548afc0
SHA256 7856a43341329f4fcae9a2dbcb4e6b9f9303db7505ecf0c48f573f39c75d3eb0
CRC32 E8B64552
ssdeep 48:bkOzqBaAxCbg/yTYsP/JHSnQh5f5IdyMYysE+izuBXwjAHW3wC/WF6VZbwijJ7UD:otjCjyaJMp/zmUA23wC/WeJFUCCbeY
Yara None matched
VirusTotal Search for analysis
Name 9bf538fc4b96fbd1_fo.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\fo.msg.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 36b7b0730334b4114fee1d2d7fff3b8d
SHA1 fe476ab81b6ec52b2bfe22bd6af7dfb106f1148a
SHA256 9bf538fc4b96fbd140d8c620b3da6a0673f779ed47a5696181622cfe6b008e12
CRC32 2918F49E
ssdeep 24:bkKN+igvuqKF1snGSg9qilKgMOKBV8Tbe1iCLijDnzhPx5UncG2s7a6:bkKig16GIu7M3BVrJ2DBxincG2t6
Yara None matched
VirusTotal Search for analysis
Name 3262c4bd1cd058cd_156.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\156.WNCRYT
Size 15.8KB
Type ASCII text, with CRLF line terminators
MD5 70e121a4ed2172ad8b17fddd913ba5d1
SHA1 8b9c243989215b5962c0e2552b0c8264e786c95e
SHA256 3262c4bd1cd058cde40631e8042da52bb4816b20cb5478a90b84ec09cb6f3d27
CRC32 9815A612
ssdeep 384:BEVBm0B4/Yr1zHupKECx3sl/iyfDgvAwTEy:BESF+HupKECx8JiCaqy
Yara None matched
VirusTotal Search for analysis
Name 6ce9601fd9987e75_23.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\23.WNCRYT
Size 542.0KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 6a2df771261a3dc10304cf34362a53f9
SHA1 3247ad9178cd058466362b78aac846d76fa47959
SHA256 6ce9601fd9987e75d049b2e09e387bf86a3c3bc2ce12ea7c7d6de4c0aedd4d4f
CRC32 E6604121
ssdeep 12288:3aGCbfGf8dvaIEGCXN9mvIaGCbfGf8dvaIEGCXN9mvIaQ:3a7L8PXNYwa7L8PXNYwaQ
Yara None matched
VirusTotal Search for analysis
Name b6589b1546ba0266_287.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\287.WNCRYT
Size 1.8KB
Type C source, ASCII text, with CRLF line terminators
MD5 08b37d4cea0df4667775a6c79cda3daf
SHA1 82d0e654e0e1959051f821f426031a8ccfc4177f
SHA256 b6589b1546ba02662f612ccb38c6d985872998eaf0b3115dfba07f4e0ddf9cad
CRC32 CF86C008
ssdeep 48:tVrSpEKcCDZnwfP/sy3en4VcNHgBB5rx2WouYHPz+9:cVD5wMOenztgDSL7W
Yara None matched
VirusTotal Search for analysis
Name ac87068283e5d1d9_316.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\316.WNCRYT
Size 26.0KB
Type RIFF (little-endian) data, WAVE audio, Microsoft PCM, 32 bit, stereo 11025 Hz
MD5 865bb0bdb9f34c5e6795ff34b20f3533
SHA1 35c7219a416b2a2d5e7876f6f9973e2cf4460b28
SHA256 ac87068283e5d1d92cfe4dfb2cc50d5ea5341d5ac0efadfa47db48595daafcfc
CRC32 BC9E3C0D
ssdeep 768:EOcraxb7tfS5gbRsRDPRIeQ7ENMoxFAj:pcrQhfS5gbYRI5kMoxK
Yara None matched
VirusTotal Search for analysis
Name 0eba5399fee276a0_297.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\297.WNCRYT
Size 1.9KB
Type PEM RSA private key
MD5 170555a84120985bef1afa430a90c465
SHA1 aa3652093aafc935d3d65b65954d59c9ba198b16
SHA256 0eba5399fee276a0834e1488637ed1bf611ca1e28da39f2abc6edb2c59d6c4c4
CRC32 7B96A84B
ssdeep 48:LrkOS/xYGIevZFbaLkCucMSkOS/xYGIevZFbaLkCucM0:LrE6yDbaLktcNE6yDbaLktc9
Yara None matched
VirusTotal Search for analysis
Name fc9b6c07facc7649_16.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\16.WNCRYT
Size 678.2KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 afc1d668daf43bbae2bc10702bcca78a
SHA1 2d2497bb8230286b666efeeb8bfe4986e731147d
SHA256 fc9b6c07facc7649f51e0ef18dadd9f3ca3447f80a6e37b549eee5b8bdf85abf
CRC32 A19A084B
ssdeep 12288:GtYcQVLgdeDmFPkn1GKvnxitYcQVLgdeDmFPkn1GKvnxitYcQVLgdeDmFPkN:GqPVLgd8mF8n1pvn0qPVLgd8mF8n1pvP
Yara None matched
VirusTotal Search for analysis
Name c049960cdfca6c60_pt.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\pt.msg.wncry
Size 4.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 54059f5a691ec2ec5d66ed2bd6114586
SHA1 d02e600ccd001a39433e652f75271c1e57e858d1
SHA256 c049960cdfca6c60407143cfa45267cc5e3564e09898229abee9a31bcf59a42c
CRC32 36D81656
ssdeep 96:oqVxu/kvh3C2qQl8o82MzkRdkE0eeoIr3oNhxaqF78Swug6n0:Y/kvhSl1h0t0eLI5qF7fs60
Yara None matched
VirusTotal Search for analysis
Name 83a6b672a799e419_513.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\513.WNCRYT
Size 682.0B
Type MIME entity, ASCII text, with CRLF line terminators
MD5 85a1599d38f88cd49974fec44458ef0c
SHA1 ef5cdc684180ca007753f437a8672f07a638365a
SHA256 83a6b672a799e41993f0cc60ebb936881d957765e7c618a6a17538f041e8db32
CRC32 4798036C
ssdeep 12:3XmyFxxGEYUp8MG886AQcVgQearowgQYf1IcgQFSCgAQrIUAQrIWJgQearowgQrj:3XmWxoErbGiuVtrowiacrSCgSUSWJtrf
Yara None matched
VirusTotal Search for analysis
Name 639bd1803f57a4a1_270.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\270.WNCRYT
Size 3.0KB
Type C source, ASCII text, with CRLF line terminators
MD5 87b0ae703be59e794ac4370a2be4c188
SHA1 79db18a44b9e65b2fd41d27668802e9332f0683c
SHA256 639bd1803f57a4a1293b72905a904be08553ff9cd040ee7b23be41d90e4cbdcf
CRC32 145912A7
ssdeep 96:qkIe4oF8a8a+dxBn9S3jGJcLRD4vn3bknA:qbe4oF55yxBn6QPAnA
Yara None matched
VirusTotal Search for analysis
Name 29c7ca358fffcaf9_669.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\669.WNCRYT
Size 251.0B
Type ASCII text
MD5 bc86c58492bcb8828489b871d2a727f0
SHA1 22eec74fc011063071a40c3860ae8ef38d898582
SHA256 29c7ca358fffcaf94753c7cc2f63b58386234b75552fa3272c2e36f253770c3f
CRC32 3320FD7B
ssdeep 6:SlSyEtJLlpuoo6dmocv+9/Loz3v6rZoco+3v+6f6HK:4EnLzu8+vWq3v6rpF3vmq
Yara None matched
VirusTotal Search for analysis
Name 0c1d97b042864513_756.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\756.WNCRYT
Size 132.0B
Type ASCII text
MD5 a16670dc183c0f2168aca34cf262dcb2
SHA1 f3e2e4f9bbbbfd2147cd0c23d84575e9033923c9
SHA256 0c1d97b0428645138fa9eec9716070bd11bb5278b352d2fdbd5f66f69e3466fa
CRC32 911584FA
ssdeep 3:ptz5XHHys1szVEo4DrwS3vJ+gKI89kXVEgc9ch/ctVVxjPv:Ys1szVEo4Drn3vIgw9kXVHCchyVVxD
Yara None matched
VirusTotal Search for analysis
Name 96aa86cf3a8aadf7_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\mouseinfo-0.1.3-py2.7.egg-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 fba742fd92b407e541eebc278c5f242f
SHA1 c00d4aaed66ddb8a1c438b6ffa316a87f3b8a0a7
SHA256 96aa86cf3a8aadf74bab41bf653bd3113272087b8f3236d6a789fce0af036ec1
CRC32 296AB18D
ssdeep 6:bkEwkZT++YWo2Mu2LaV/bssVfso0+qV8a2ftRKZkys:bkE3Z1FAu2Labmo0+qVJ4tRcs
Yara None matched
VirusTotal Search for analysis
Name d2e14be188350d34_122.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\122.WNCRYT
Size 1.1KB
Type ASCII text
MD5 0f5c8a7022db1203442241abeb5901ff
SHA1 c54c8bf05e8e6c2c0901d3c88c89ddcf35a26924
SHA256 d2e14be188350d343927d5380eb5672039fe9a37e9a9957921b40e4619b36027
CRC32 E51978F9
ssdeep 24:4azu8/0oFUBZNk1Mkp3pFukZEoVYfPcF+T1vWFMvUvWI3:46kNkKkpLEoSfPcFgvWFqSWI3
Yara None matched
VirusTotal Search for analysis
Name 1a2302d24e8a5bf6_pyconfig.h.wncry
Submit file
Filepath c:\python27\include\pyconfig.h.wncry
Size 21.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 330d05e8fd2d947db499bdfdbea372a6
SHA1 24102b7d26d9997f1eb49675efb6e1f1c4cf3bd7
SHA256 1a2302d24e8a5bf68dc6d6fdf0e22360afdad9878bf9edd4e40550c06e7d5ade
CRC32 215DE875
ssdeep 384:rgaZKx3DeleXrEvHW4M3XBRmZ/02ZaxJSXcUouMPrzlxexMZHXyNIkbmwxawy/Vr:rs3SlkEfW4M3XBRKBGzPlxexeHXoz5Tu
Yara None matched
VirusTotal Search for analysis
Name 01ba4719c80b6fe9_549.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\549.WNCRYT
Size 1.0B
Type very short file (no magic)
MD5 68b329da9893e34099c7d8ad5cb9c940
SHA1 adc83b19e793491b1c6ea0fd8b46cd9f32e592fc
SHA256 01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b
CRC32 32D70693
ssdeep 3:v:v
Yara None matched
VirusTotal Search for analysis
Name 5f7e71782581f0bd_486.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\486.WNCRYT
Size 582.0B
Type C source, ASCII text, with CRLF line terminators
MD5 83afdcdb78cb16fa02d3e953bfaaca38
SHA1 c2c49db8fb36a76fe21c6186237b8c37087715be
SHA256 5f7e71782581f0bdb4e8438d29fe715786aa91d3d49a2c36ad1d4fd29559f19d
CRC32 7DB3ED86
ssdeep 12:wLHKndrcHBRhnaNnaAmJLskygfLqGFEHlbgAggBniqHI:w+yHBqoAYs2fL7SlbgAV4uI
Yara None matched
VirusTotal Search for analysis
Name 7298d6566d25ec0f_faawoqrzpleqfsgvv.docm.wncry
Submit file
Filepath c:\users\test22\documents\faawoqrzpleqfsgvv.docm.wncry
Size 273.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a548ae740c0ec673e1cb50b0f51488e5
SHA1 5279f4ca22e2f5a9123f233821ac96c078b25c60
SHA256 7298d6566d25ec0f35abb7b685c1925164b0da2b9c9aeb6af9ac447285d611c2
CRC32 01263862
ssdeep 6144:gyT4h2CTXRnFFgGG2ZyqJhkTXkTf9h3z3XfXG975T:VO2cxgGG0J2TXkb37e5T
Yara None matched
VirusTotal Search for analysis
Name 867956c2f4144b92_atwjkhhgpixqpqbcw.doc.wncry
Submit file
Filepath c:\users\test22\documents\atwjkhhgpixqpqbcw.doc.wncry
Size 885.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d2a7e4df7338caed355a00f42782ebe2
SHA1 b2ace78704bffea24123e0db06103fae2ce3c640
SHA256 867956c2f4144b923c19f2399036ffb8ffeec7e262b9c72ae16ae2af32f05107
CRC32 F6E571C2
ssdeep 24576:jjevdTP8Z0gv6JT1D7C0DBRuO0ZEfKltqv:IZUCeYdmQ8Oq6v
Yara None matched
VirusTotal Search for analysis
Name e6842ea936c4ed4e_mr_in.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\mr_in.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 4b82be981d4bee0e255bf57a4dcdc344
SHA1 4cc0f1281aab927b776c232282f6c315147b22e2
SHA256 e6842ea936c4ed4e2d26dcffa26957287dbfeeb5123f09d96c8cf435f865fe09
CRC32 D96CC735
ssdeep 12:bkEivCi0Lvs6N5+lnLvl+4AYSefYfQ110fS1YVMFWXS6jwK:bkFvtW5YLc4UfkXYOFWXsK
Yara None matched
VirusTotal Search for analysis
Name 391eb793ef792eaa_kw.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\kw.msg.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8c762531ffab4f07ada500ddaccb72dc
SHA1 bf1114b8da874f850b5afea23bb08cc6c22f0c92
SHA256 391eb793ef792eaa667cd163c32634681f223f2c41121c592cb5ace8e226e62d
CRC32 5B42D617
ssdeep 24:bkS85cdNzJFybLiHoXrce5DMXb1bQ6NoGIPZoZu63sadQrJF7X0PlruH:bkfh+sXMXbfMPZ7cduJd0Jo
Yara None matched
VirusTotal Search for analysis
Name cccedec0f25c174d_pyerrors.h.wncry
Submit file
Filepath c:\python27\include\pyerrors.h.wncry
Size 12.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e75685f000aab42082a6cffe8acd954a
SHA1 1aef5d033deb5790d85171c5ddf49c980eaf9d01
SHA256 cccedec0f25c174d8a338b7833830e107977240dd11ec0ea508e57f3f0e64783
CRC32 CF7D287B
ssdeep 192:/QR6tdTGtDRDORcmz+i4kZI3EBR77kj6S66erszJ7f/BWWO5MkNNO1YnC:A63GRRCRCiV63EBh7kOeepbOMNO1kC
Yara None matched
VirusTotal Search for analysis
Name 6ed95025fba2aef0_468.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\468.WNCRYT
Size 217.3KB
Type UTF-8 Unicode text
MD5 cba7b319792b372675225b57279be08e
SHA1 3f306ecc86cae3c20b569d2d4c86d692fea3433f
SHA256 6ed95025fba2aef0ce7b647607225745624497f876d74ef6ec22b26e73e9de77
CRC32 D67BBF42
ssdeep 6144:BcRqZx9cSaNI6Fd4tL02dTCTgSQh1hV1A6:Bc8+HW6f4tL0mk41hXA6
Yara None matched
VirusTotal Search for analysis
Name 8381742f186c2acf_404.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\404.WNCRYT
Size 6.5KB
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 a897d7087fc077ba6029aef413f33946
SHA1 92f07bb0c871d4d9f4789433f4e6c1c72b3945cf
SHA256 8381742f186c2acfdc3fd512c33a8e61b4efcf7eff5161788b8628f6c095835e
CRC32 C307D1F8
ssdeep 192:3t70vLOxjehL4zaZlRxraCghGlKZ4Wruwy7Ro+:3tki9eez+7aVhGA4ot+
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name e611ce582a7fa645_499.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\499.WNCRYT
Size 896.0B
Type C source, ASCII text, with CRLF line terminators
MD5 9cabff0dca4d3dab04af09837c029b41
SHA1 42a2fb3b6205eeea934242ba806e45bdc59f1636
SHA256 e611ce582a7fa645676fe623803c4d186a50b079f2a2840f5679df5c9897e03f
CRC32 37DE0AC2
ssdeep 24:QfNkHG3PTkPYGWUIqHCvWtVCv5VOPkFtD:JHWh9IHC2C2cf
Yara None matched
VirusTotal Search for analysis
Name 3ea4d4154d724d23_53.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\53.WNCRYT
Size 2.6KB
Type MIME entity, ASCII text, with CRLF line terminators
MD5 f55bcbec3b20b0eeb5284ae93d2570bd
SHA1 f5ca2513d5a2ff8818537ba35f288056dba8d70e
SHA256 3ea4d4154d724d236eb1a68fdc10de21091781c594902618c17edc3dd8380823
CRC32 9470B562
ssdeep 48:mTohFNd+nbAs9qWJQQFG7p2d+K6sTRd+UD9dEk1EJh32F:mTohFN8nbAs9vOQFyp28K6sTR8UxdEIZ
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name b0fd86d0936bbe26_bears.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\bears.jpg.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 0412166898242866f22529551a0b8e43
SHA1 3c7a2a38180a69a4886f84b1ca704d47891e74f5
SHA256 b0fd86d0936bbe26be11820bdc92e96abb04edd906c7a976ceda723e0e6c43a6
CRC32 DCEEC023
ssdeep 24:bk4SWAxogx85bD8n5o5KUMtnGGcWlq5xLrsLNEmrErCxpJW6MfgkeP:bk8ULq5cny5KPtn7FIuxHegkU
Yara None matched
VirusTotal Search for analysis
Name 5cd94e84f5dc304d_715.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\715.WNCRYT
Size 115.0B
Type data
MD5 7adb32fb6b065c0b21dd14909d6a913c
SHA1 cc756175c9a66c03f3805ae05a87638920146532
SHA256 5cd94e84f5dc304d53c75395fa668297dd4f26b75c88f7459e5a2704064f7e2c
CRC32 88D89293
ssdeep 3:2SiHF4MfTSX7BMSetRjIs1IGQRXTQnGJnUNvfrSLIJ4Kn:2lxSXFMRjL1IHRX8GJaGLIJH
Yara None matched
VirusTotal Search for analysis
Name 9240e117a06c8868_structseq.h.wncry
Submit file
Filepath c:\python27\include\structseq.h.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b42fc6293f1be667904c0f2c6ef6cbf7
SHA1 a936df9eeda3d0bf304f0994e9a655b5227ddb68
SHA256 9240e117a06c886875f9ec635483c062cb37b719763d957524517f361700d584
CRC32 60E34C89
ssdeep 24:bk/kU3qP1urW26dAswA+ZlSZG6nH2PG+OuXTro2:bkXqArW2qAsiTuG6H/+TTro2
Yara None matched
VirusTotal Search for analysis
Name 7251116df0cc4211_mr.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\mr.msg.wncry
Size 2.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d5814f4b4b383ccaa946070142ed17f6
SHA1 69debc6c0f53dbd8f3b80e29fc9a05b814501ac1
SHA256 7251116df0cc421100ecd481333e85d10c2fac904f93caf554ad538fdc90b9fd
CRC32 3E160A03
ssdeep 48:bk/vz7NtN/Egd1BuswuJn/ba7f1iWXkuePfHA6TpxHu22fsubfQrVv6vHzM:oXvNtGg8HuJn/u7fFXCP/dJuXl0Cvw
Yara None matched
VirusTotal Search for analysis
Name d115718818e3e336_682.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\682.WNCRYT
Size 690.0B
Type ASCII text
MD5 ce7e67a03ed8c3297c6a5b634b55d144
SHA1 3da5acc0f52518541810e7f2fe57751955e12bda
SHA256 d115718818e3e3367847ce35bb5ff0361d08993d9749d438c918f8eb87ad8814
CRC32 D01E52A1
ssdeep 12:4EnLzu8+YmWjjRgWfjxBTo4erxy1IGZzNN+3v6amK3vZsq:4azu8+YZjjRXbfNedy1IG5N6vjmsvGq
Yara None matched
VirusTotal Search for analysis
Name 4bfcdfc58db942d4_555.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\555.WNCRYT
Size 98.0B
Type ASCII text
MD5 6dba4c7083503ef8999e15b84a59f857
SHA1 943b82b14ef85715ec21366c16d15f76c7b45ddc
SHA256 4bfcdfc58db942d403558d4188b02638a4a4908e6597308a3cb89839212ea6c6
CRC32 BCCFE9F2
ssdeep 3:1VriL6M5IEtBK6M5IEtZFYUh6M5IEWn:1VriL59K59FYUh5M
Yara None matched
VirusTotal Search for analysis
Name a7e7513ae4a6bb6a_formatfloat_testcases.txt.wncry
Submit file
Filepath c:\python27\lib\test\formatfloat_testcases.txt.wncry
Size 8.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8dd79ad2e49692aed497cef712ee6809
SHA1 0c31ea5772bce4922a0539efe3044e8392f0b423
SHA256 a7e7513ae4a6bb6af7f5599b560f08b927dbe8fb0d977322da22f36c18e0efbb
CRC32 A82E3B1F
ssdeep 192:OooUk+T9Smnb5mDzJ9XJDite+cm+3UJnKkrE1:vo9Gx1m/h8e+chk2
Yara None matched
VirusTotal Search for analysis
Name 77b6e486e19a7ce2_msg_19.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_19.txt.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4ad27c6ecbc49ce0f01efafb92146aa8
SHA1 168ba83107564aa82c3a876df816e04338543b00
SHA256 77b6e486e19a7ce2b9ff72c2ed0578a3ed5be376de953b3642c0c7d5f39f38ab
CRC32 60915761
ssdeep 24:bk0l+s4mtYU6IaEE8a0AV1hrCDdUI5d1VZGDs5fFnv3T1rN4JcC+:bk4+s4mGIrEuYrCDdrjz4DaN4S9
Yara None matched
VirusTotal Search for analysis
Name 057781446fb2ae26_transcodedwallpaper.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\themes\transcodedwallpaper.jpg.wncry
Size 628.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 bcf9235e4834b0f87deae67d50786042
SHA1 667f8c38c019f36228e513cf200d51ee5e3c0f53
SHA256 057781446fb2ae260d8d34a2a58ff28d9feeb42082d7645210bacc2541231483
CRC32 A2EAE5A4
ssdeep 12288:qcMRC1B8U+S2aCDVqFATSx+0+5H0rzmsAO6pDogeQuRvtbS20/3fx:qchlvCDVqqOxGuvCRAfRvtu28vx
Yara None matched
VirusTotal Search for analysis
Name e9a0d777e6aacfe4_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pip-19.2.3.dist-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0d3f9d178e161db97f159c47332f787e
SHA1 876d157a29b4ef4a37e9c48c3c19f9d6674c2787
SHA256 e9a0d777e6aacfe4f7d3595a228d125a65036c7c5d9e10b95fc8de03391039ef
CRC32 B1D4B711
ssdeep 6:bkEMlkEZKYVRHLhi/JNtUoFsHufpcMCo+2/ry15h6zPtZz2caL:bkEokwZmtzSiQEy15h6zt1w
Yara None matched
VirusTotal Search for analysis
Name a952ba1ddb789bdc_261.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\261.WNCRYT
Size 1.2KB
Type C source, ASCII text, with CRLF line terminators
MD5 e4e4f6e32088ba62018a3728b0e99c4b
SHA1 1777b8903a21e359644856944f6e369c5201d292
SHA256 a952ba1ddb789bdc12b0d3ac47b5319956b2c24037c3d6eed34e907ec48ddbd3
CRC32 B1112348
ssdeep 24:C0r7LqHCvWtVCvW569A4mMbgy+m9xljq0b8:bWHC2CO56mjMbgy+m93jq04
Yara None matched
VirusTotal Search for analysis
Name 242756fc4a38b793_objimpl.h.wncry
Submit file
Filepath c:\python27\include\objimpl.h.wncry
Size 14.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8de0c16c398acfac91c8a9383807b972
SHA1 8d7a7149834f86ebe3c08138ce7f88fc2ebf0776
SHA256 242756fc4a38b793317bba59bcfd9415800736b230223d3544611ffe99ee2b09
CRC32 DD984FE0
ssdeep 384:n/F+R+Nbvo/1NHmr7C3HGpUCvprEWmH5IA7yJrqxbQVg:8EZo/1Ni7C3Ha7vprEt5TOJmxbn
Yara None matched
VirusTotal Search for analysis
Name b0121b5b5ec91f4b_en_za.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_za.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 68cea6dc0393208999c4560e480554e2
SHA1 1d1d8cabf03ce12cfa926dd5b0583a92912ef02a
SHA256 b0121b5b5ec91f4bf20a3b9ccc2d90274d450177354ed3056afd382bff1e02e1
CRC32 0CABBA6A
ssdeep 12:bkEmPkco6CPichom0Y1tiXUHYxBRkaHrpn2E97qbhM:bk8UCPx0D62BFt97qdM
Yara None matched
VirusTotal Search for analysis
Name 5b8015a027750553_pt.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\pt.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8aff7133e1f1f50c359c0d42d6c05fcd
SHA1 cc1cff531cbb04bc60c832ed6e44d0788427300e
SHA256 5b8015a02775055399542ecfeb5306a77bd1d3971bd0f74e19df21491b2379d0
CRC32 3524E88C
ssdeep 24:bkcuMTSYQNrjakFPuXzh4+t2gH+rg0o1M/WE1HfP+2EiOhfN6nObotGR:bkcuSSdrjavuxo+rgd1+DP+lj5l8tGR
Yara None matched
VirusTotal Search for analysis
Name ecc44eac6baab5cd_267.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\267.WNCRYT
Size 11.8KB
Type C source, ASCII text, with CRLF line terminators
MD5 cebed602cd07bb6fc4f7b95b46e4cb58
SHA1 3879607f2900a984c83ad73688e811e6428c9065
SHA256 ecc44eac6baab5cd83b7eb18b2c3f8f9d3e1ae1df432f0d8f8df860d05a0ffcb
CRC32 99EC1C1E
ssdeep 192:cRFZG+KpPFkw17jkOZDiuEh+ZoP9fZv3AmVi:cRFZG+QPFpZgmDzEh+ZoP9fZv3Ams
Yara None matched
VirusTotal Search for analysis
Name 410c26b109ce9d32_318.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\318.WNCRYT
Size 1.1KB
Type PC bitmap, Windows 98/2000 and newer format, 16 x 16 x 32
MD5 e3a1f317b1a275e5d5f1b4b0ff04ee01
SHA1 8f37f2c3b3c5b5fd2da41ddcc59ad1b6c29b9bf0
SHA256 410c26b109ce9d32d35c0e4bc6dc92a7579910ce706939a056323de5801a7a87
CRC32 48FBE47E
ssdeep 24:mg4qEp6Ajg0B81C+AeflhfhFB/ZwpSo4AD1p1Hp8mP52lp8:Qxjg02w5ADJFBQD1HNU
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 11e3cb23ac9a1b09_421.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\421.WNCRYT
Size 6.0KB
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 3876966fc0c50aa81047de2d87159352
SHA1 37c7cda2a60b4bd04e7c37c0e1a282546d13df07
SHA256 11e3cb23ac9a1b0910a122c77132fe634076a5ac37d4eb768276903990dd0d5c
CRC32 DA772610
ssdeep 96:htkTFz3JA9gn7GsBteFi6CERbTriasH2oMVyyR4XKef3YL6SFJA9CXuh2fm:Gn7GsBsFijERb3rzoMVyycj3iF29Wfm
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name e3c3ec9d7a8b007d_qibmgzongfji.rtf.wncry
Submit file
Filepath c:\users\test22\documents\qibmgzongfji.rtf.wncry
Size 340.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7257aa0e235ed175d0fe45302501d135
SHA1 9d3985eb6db691cd01a8391782a9c8729e4a5ef7
SHA256 e3c3ec9d7a8b007d37b5d57858728ed5cc49fab9fea2a06b88eb267a48df9c89
CRC32 AB9D7427
ssdeep 6144:5q39UV7JfmEJ2QAWKEkYLfLpsKRkdnBl8nvrAoLyz/WGzLttxiAiBX:5q3o7Fm9WKEV+VdnBlgvFLqRzZtxiVV
Yara None matched
VirusTotal Search for analysis
Name aee148bebbc70841_pygetopt.h.wncry
Submit file
Filepath c:\python27\include\pygetopt.h.wncry
Size 648.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 62289984d9b27d5f0b1d549791798f0e
SHA1 1f61e382e4eb79f4e942f3dbac926c3b43fb81a0
SHA256 aee148bebbc70841c4c7e093eaeb029e8bb566e80f8140dcaf7a36a50c162219
CRC32 31855BA8
ssdeep 12:bkEdCirI1gYvLzGqicsqSAzfpoaL2RbtEj00egdQOxf2jYPSGcA18zC:bkp1GYszAztL2RpWLBZ2UK1Q8W
Yara None matched
VirusTotal Search for analysis
Name 8578e05ad5e5123f_755.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\755.WNCRYT
Size 287.0B
Type ASCII text
MD5 f57abfdc181cbfe20d3103f2a62c4bba
SHA1 cae5cc1cffb022d172c80806b9b52e272dc42b77
SHA256 8578e05ad5e5123f489f1e8c650174ae138058018b9b60f78194f99ada23ee72
CRC32 B496C894
ssdeep 6:KHj1tTV4cVGAeo0jR11tTVp10MQkT7AeIbWDoXtTVvLEqKxD:KHTTVPVG1TRTVpTX1IbWDodTVTEq+D
Yara None matched
VirusTotal Search for analysis
Name 581414618cd495c4_235.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\235.WNCRYT
Size 1.9KB
Type C source, ASCII text, with CRLF line terminators
MD5 fa93753fdbefd8869d0efe7ebc0e52a7
SHA1 f236dc7f993b2e6a65a1644bb7d4d047d92fe859
SHA256 581414618cd495c42a82c3f0ab1a4e3f10a294e2fb4bb1efcfeb44bcd0ec3a42
CRC32 968DDF1E
ssdeep 48:FAcYj7/g4/7n/7OGto+IrrYhQPWPzWt82BzL:FAd//g4/7/7D4Y+26DzL
Yara None matched
VirusTotal Search for analysis
Name c6e8f9d842c3656a_installed-files.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pygetwindow-0.0.8-py2.7.egg-info\installed-files.txt.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 40987634936381737bc7840b86f3c66d
SHA1 84c21fab38199d206f071e65ac67540d08b87273
SHA256 c6e8f9d842c3656ae33d4e7b3bef61a947aa6a3e734880b1220251cd97b3029c
CRC32 97555886
ssdeep 12:bkESFXogsf6gGrlHzEcSQFiLkKB7/9LKQvi4k6yDzKG4V1/VtuoCYn:bkzbsfBGxHP6kKR/dKT4kTcbtBCY
Yara None matched
VirusTotal Search for analysis
Name 5acb672d97f4adf4_699.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\699.WNCRYT
Size 176.0B
Type GIF image data, version 89a, 32 x 32
MD5 f3489c18d9a2de4a86bc2a10c70572c5
SHA1 52a2330cc05ca0fecb31ddda3db2748eb680b124
SHA256 5acb672d97f4adf4ae8d31b3968a1a17dfa66c35d74a1da262f14c12615d3f56
CRC32 621297E5
ssdeep 3:CsligtxlXlG8dEU7KC7hTHyknXwwxagHMULTEV8q0Rp7mWRS3GtxFAmhsJloW:Nlw8dt7hTHyWgmHrM6+3GDt6roW
Yara None matched
VirusTotal Search for analysis
Name b36bea754347f0af_plusarm.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\plusarm.gif.wncry
Size 344.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 acdb506865abe534525b6f7b29cea2ce
SHA1 e7c3a813f4b2510ec648bfd218cc196d293730e6
SHA256 b36bea754347f0af42d0fada68b9ed20fab9fea43d710212d8a182ae02bc8ca3
CRC32 1429D408
ssdeep 6:bkEt5SzDBGQG9LAtv8mqt9kg5GZj8QQjhs1eBIbHWl1xoRIXqPh5sw9Ja5Lu:bkEt5SzDBGQqLq8cCGN92KU+b0xoRIXa
Yara None matched
VirusTotal Search for analysis
Name eac2ab504ded78d7_cversions.1.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows\caches\cversions.1.db.wncry
Size 16.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c955d2a2e4cfffcc831666b8d9e62b3c
SHA1 a2a9f1f7ec7d69d9b0afaa45130827a9fd0e0b76
SHA256 eac2ab504ded78d7903e9cd36f55046307f108a2701d42e905dd9968f3955d68
CRC32 7684CC7E
ssdeep 384:KK24QXeOtWVfDCvauYfDxgAgDldj0iYsGqHlm9J:KK0eOtofDCCuYbxgN70iYsZHyJ
Yara None matched
VirusTotal Search for analysis
Name 56107e97d8bc4bd4_msg_14.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_14.txt.wncry
Size 952.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 6928d6296953be9f0e9ae4096549a178
SHA1 56ccc24a6109dd4b68b39beb379f5bc42853ca99
SHA256 56107e97d8bc4bd4a45cf30a19737f3ffe0e5c40598e38c5f4815aa9649b515f
CRC32 114B0E47
ssdeep 24:bkEgPaR8mlbM2HyQlYJUA0EEAHyvAsY8s2eFa:bkEkaLO0yQlYJUALEAHyvAsNDl
Yara None matched
VirusTotal Search for analysis
Name d43fe0b2e61ee2bd_state
Submit file
Filepath C:\Users\test22\AppData\Roaming\tor\state
Size 381.0B
Type ASCII text, with CRLF line terminators
MD5 56411f9a1fc3ff1ed8d6c65d7d254706
SHA1 c4904f77f4fc980ae73262212a9e1cc070a834a7
SHA256 d43fe0b2e61ee2bd9dbd18b62edb99ef6ff7a77ecde6207cf343af8ecf70fda4
CRC32 EB1164AC
ssdeep 6:SbdWwxXRuPUvznXr87+QVe2vwR/EnvU/UiWnFczasT0JAUiWnF0UZffoe3WWURbE:bwxXYsvzXr87HVBvwN6F1nFczN0JX1np
Yara None matched
VirusTotal Search for analysis
Name d668407ebcca65e8_msg_38.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_38.txt.wncry
Size 2.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6c174dca4546f4d92d080f21f58f197c
SHA1 2563c9ab6c90cfcd9bca14ac80ec1053bb41eb72
SHA256 d668407ebcca65e8b428fabf39507bfad5880429aa142550c65bfd45b0c4f734
CRC32 41674202
ssdeep 48:bkm6zBpbl1RQ+9eI0OTqRMI7/JYBHaCFuO4ujW9pIJjXq39NqPZcexnsJb/sSB:omYBb9erOTqRMIIgujg13+PZdWsw
Yara None matched
VirusTotal Search for analysis
Name 09878665b07bcb76_545.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\545.WNCRYT
Size 585.0B
Type GIF image data, version 89a, 16 x 16
MD5 3589fe3c728610ee9dc8ac288063b086
SHA1 ba08415e43a061a1d26854b39e4cdd3b3d61a37a
SHA256 09878665b07bcb76fb3222ea1b4947a553ad0af76fc12b31651d1707980791dc
CRC32 1AF5FBCF
ssdeep 12:dzDB+3fcNKXO5cCZDKFuBgzgs6RvbhUU8JtlTq:dcUNKXO1KF/gsUaJt5q
Yara None matched
VirusTotal Search for analysis
Name 057c75c1ad706537_102.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\102.WNCRYT
Size 1.1KB
Type ASCII text
MD5 88d5cb026ebc3605e8693d9a82c2d050
SHA1 c2a613dc7c367a841d99de15876f5e7a8027bbf8
SHA256 057c75c1ad70653733dce43ea5bf151500f39314e8b0236ee80f8d5db623627f
CRC32 C39536BF
ssdeep 24:4azu8qppr5xqPs5Jpwe3zESbs5JpbxK+dfJ:46ct5XGe3zwXu4fJ
Yara None matched
VirusTotal Search for analysis
Name b75caf05ce8917e3_small_news.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\small_news.jpg.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 02f8e036abd6642461e62cdf019dd61f
SHA1 92dc108696fe920e49671b7880c0a21fe83ed8f7
SHA256 b75caf05ce8917e315068fb7bea0dcb38980ce0407467a3889d1bc0828340073
CRC32 A97C454C
ssdeep 48:bkRD58Rm9Ck/YQs7qvMtDaLqJOX3ImDgSO6krC0G+9s5tQbzpOj27:oRDiR6/YQs7qXLqa31gS1krC0GCkt4pF
Yara None matched
VirusTotal Search for analysis
Name f3517d74c0bff110_ja.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ja.msg.wncry
Size 1.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 631eba3339a2ea6116ef64acf5377995
SHA1 443064b5350d0b936bda9a4cd004e2706467a469
SHA256 f3517d74c0bff110b096283eaefc014dabb7122547f5a3c83765ac49c7ea3c29
CRC32 D2E8C751
ssdeep 48:bknLbI0GOkQ7qeYDnHycdqwKNh17DUzYKEWG6a2bxX6acLZZ:onLb4OOTDp+9DfK5Ta2bxqa4Z
Yara None matched
VirusTotal Search for analysis
Name f9ca4819e8c8b044_98.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\98.WNCRYT
Size 1.6KB
Type ASCII text
MD5 7e74de42fbda63663b58b2e58cf30549
SHA1 cb210740f56208e8e621a45d545d7defcae8bcaf
SHA256 f9ca4819e8c8b044d7d68c97fc67e0f4ccd6245e30024161dab24d0f7c3a9683
CRC32 47ECF54A
ssdeep 24:4azu8BMnqZEjgYDT0/y3xg2LSREyqyxDfsycNp/Tpn29Ey5ykDDzi:46cGTYDT0/ya4KIySNnCz2
Yara None matched
VirusTotal Search for analysis
Name 8256bef25c13a362_idle_16.gif.wncry
Submit file
Filepath c:\python27\lib\idlelib\icons\idle_16.gif.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6b058910bd61944ac931255a0184c22d
SHA1 5e9c8f74b983c2457e807a5ab400da02ee685004
SHA256 8256bef25c13a362a649ab447889fad6b6818024da5c27a0c01b4db1aeb63954
CRC32 52AC4230
ssdeep 24:bkMKdneKTJDQRFsq/9NGMfGjbcvJCN2jB6zgSrQnWY:bkJeKTYF//9L8TN2jBtnWY
Yara None matched
VirusTotal Search for analysis
Name 86253ae71fa84f29_38.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\38.WNCRYT
Size 10.0B
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type Non-ISO extended-ASCII text, with no line terminators
MD5 f657bd35ac609010ac6a2a1f4c2c929a
SHA1 2fa4130f9606b38e0717b1167b7dd71e840a20c6
SHA256 86253ae71fa84f293b8dcb351a2354531eade7315909c6e112bd3e65ce5acdc4
CRC32 8B7C3DCE
ssdeep 3:BMVq/4x5n:d4x5n
Yara None matched
VirusTotal Search for analysis
Name 6427ffc1137817e5_70.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\70.WNCRYT
Size 8.2KB
Type ASCII text, with CRLF line terminators
MD5 6101cc4c9aa2b54a2c6b738173850a70
SHA1 a6f56261cb3470e0d06e74365126b04c562730ad
SHA256 6427ffc1137817e5d40b85429af904ef0ed1b516951637e6b9bb45590efa351f
CRC32 CC81DF98
ssdeep 192:M3ID8ux+SQFaxWjEJEhfGzJ4Uu/muwFGwkss2Xj9:MY4axWvvzbg9
Yara None matched
VirusTotal Search for analysis
Name 84753c80d9e200d1_logo100.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\images\logo100.gif.wncry
Size 2.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 508fe50846efd8fc6e9939c7e39e2131
SHA1 9c9bb05e8033abd1b22fc2a24771af9d220d5c68
SHA256 84753c80d9e200d1c41f700a54e3c2b01285346ee2fc5b7a554e74b51fbd4d53
CRC32 DA0E394C
ssdeep 48:bkw1IHbwM9RGAeighnOdYket6RHaitdwZ4JmLE8tsPeUIMVQhPgvC:ow1AV6ig1tvitAY8tsPvBQhMC
Yara None matched
VirusTotal Search for analysis
Name a4318d89fa4632a1_182.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\182.WNCRYT
Size 2.9KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, comment: "File written by Adobe Photoshop\250 4.0", baseline, precision 8, 1440x24, frames 3
MD5 f05db36ea7f31d5801df60cfd75f8ef9
SHA1 14e41e9d08e11de9358a66b37951be7e3652bebd
SHA256 a4318d89fa4632a1901e80d4c421c5fb75cd9eb063257d3bf76865ee898aeaef
CRC32 629991E1
ssdeep 48:/H32lria4bkjogvjEYDDDDDaD21ItgvjE9zzzzzzzzzzzzzzzzzzzzzsyodXV:/H3CG3mD7/7ModF
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 7ac5fc35bc422a54_643.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\643.WNCRYT
Size 251.0B
Type ASCII text
MD5 f08ef3582af2f88b71c599fbea38bfd9
SHA1 456c90c09c2a8919dc948e86170f523062f135db
SHA256 7ac5fc35bc422a5445603e0430236e62cca3558787811de22305f72d439eb4bb
CRC32 219123C6
ssdeep 6:SlSyEtJLlpuoo6dmo76GUFLoTW3v6rZo76T+3v9f6HK:4EnLzu8d6GUF73v6rq6K3vMq
Yara None matched
VirusTotal Search for analysis
Name 05c495334a5a606d_tanspecks.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\tanspecks.jpg.wncry
Size 3.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ddb7df4e2f6b9b32692592547111279b
SHA1 47977f3e131822fd4b048a8063385b941686eb0e
SHA256 05c495334a5a606ddafc6784974df27fc0ad650e1bb86d4b4d2fd02bcebbdc66
CRC32 19738C48
ssdeep 96:oU4p9F/DyJaH/RBCBBoaDGUy8zjHBFtVVqfvXUqmn4/hED1+:Xg95yQH/qBONUy8DUXDmn4/s1+
Yara None matched
VirusTotal Search for analysis
Name 7cae42d5a53237f4_msg_22.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_22.txt.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b369ed812f532ace914faee294f0cff3
SHA1 52f79b6f11d1ed780dda1ccd3440d9c92301d6fb
SHA256 7cae42d5a53237f428f385a016b2e4564bc19b14988c6b3b68e157208d7343ae
CRC32 B8413582
ssdeep 48:bk3u0FWUzUdLsYMCXALL3j7O4kMdlZLZHfbMy6Xce7y9kEOXbzXnIO:otzUdx1XEbj7O0nZLZjMy6Xccye
Yara None matched
VirusTotal Search for analysis
Name dcf04d1ed617fc70_745.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\745.WNCRYT
Size 106.0B
Type C source, ASCII text, with CRLF line terminators
MD5 c46f1b7e6541f924e7b57fc2c7f07914
SHA1 8296faa914cfa68a29600732a9d74f3b82948da3
SHA256 dcf04d1ed617fc7060d53b2fef3c668b6f7a5c9312e6362ff2dd695e6f728213
CRC32 7217BC9E
ssdeep 3:yWyFNo0RFGFGx5oeoV2R5KQRSGHf9Nv:yJv/RFSahRUQQg99
Yara None matched
VirusTotal Search for analysis
Name 6942be96114fccbf_en_in.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_in.msg.wncry
Size 600.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 8434bf5277cb1ee50b1f864031484634
SHA1 bd0d3392fbec3b312663f0e4d18c71438b074a21
SHA256 6942be96114fccbfdc062eb2e464e86f6b48119973d7fadc8a9e9d5ca2f2b7ed
CRC32 3CF495D9
ssdeep 12:bkE45rMqu2ZSJ7J7G6sUvLmOfSqgrC4uniW2zkb8u7ZPRUleprNpRjS:bkx5zul1FG6sUzPBKTuniW2z48ud6Svo
Yara None matched
VirusTotal Search for analysis
Name add47338e64fd4b8_euc_jp.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\euc_jp.txt.wncry
Size 1.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 057c02bb040ca887b5df49f58957f0a2
SHA1 89639f0a02fdfff1be7f8fc93b42527f98ec6c29
SHA256 add47338e64fd4b820971df407519cc732c226c32fb41da0ccadbc9d1982ebac
CRC32 D072844B
ssdeep 24:bkt0MTk0V0FmkZlNE6qGwS3yfxk/u5mTCM0L:bktq0RkHGve/gmTho
Yara None matched
VirusTotal Search for analysis
Name 5c10ce0589eb1156_734.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\734.WNCRYT
Size 160.0B
Type PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
MD5 e0862317407f2d54c85e12945799413b
SHA1 fa557f8f761a04c41c9a4ba81994e43c6c275dbb
SHA256 5c10ce0589eb115600f77381130b70ae0b7b3752614d86d4c89e857658aa222b
CRC32 2B4201C4
ssdeep 3:yionv//thPl3xWrA4RthwkBDsTBZtnAkx/9lVtEXIyN+ltN1/lsg1p:6v/lhPKM4nDspnAkZHVtEZgltN1eup
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 37ae53c074c1a699_python.png.wncry
Submit file
Filepath c:\python27\lib\test\imghdrdata\python.png.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 362b5c3237dd063276f52b496b96d091
SHA1 e49471065a8740ca3dc08857c9cf09f8af81744f
SHA256 37ae53c074c1a699cbc038bb07561ab8bd7281250c4d124dfe289c7b43b61d9c
CRC32 C106E70A
ssdeep 24:bkglXhqHl80RYB8dsFsszS69TVcwZ7tfDzShrHKm:bkGXh8lvq80s6DdVCb
Yara None matched
VirusTotal Search for analysis
Name 0d4171aac746daaf_en_au.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_au.msg.wncry
Size 584.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e0a4a9fbdf7df2c3cc08402a830f93b1
SHA1 9296a25822f93c1ecdf6a38e98a4cd8270ebbdde
SHA256 0d4171aac746daaf94cd2271f190dc5c68b7dcf3b02006dbafa2f7e529926a39
CRC32 DE29A69F
ssdeep 12:bkE7kxwniUAf3/hzdFC+BuesHoaCmr667Kt/G5GsRxVQt5Cp5l3y4VQ0R8In:bkskmiU0a+TaCmr6rp9tkZee
Yara None matched
VirusTotal Search for analysis
Name 561ba6c476d10e8f_568.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\568.WNCRYT
Size 9.0B
Type ASCII text
MD5 11636b39fc872526a5c1385992b1d084
SHA1 b3d414a0c9a410cf3ae777b7b1a6e01e8b15a114
SHA256 561ba6c476d10e8fab6521ffb712f8d4340ee0309a483234973d80221c141db9
CRC32 3CE70DA2
ssdeep 3:O5n:in
Yara None matched
VirusTotal Search for analysis
Name fbc16790b6a446cb_9.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\9.WNCRYT
Size 230.1KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 20477fc535f1c4d1e6f94d4c86243ada
SHA1 3434560ebc3e82054f52d69ace8ec46d9c40c0da
SHA256 fbc16790b6a446cbf87b8919ae8d2b1a1c16a3ee8ea740553b65ea6bc19831a1
CRC32 E25AB288
ssdeep 6144:afE/nEoNhcuKP4S1nIHFTzVHouvopjJ3QYq:p7/OgS1czltop+z
Yara None matched
VirusTotal Search for analysis
Name 1887d7df719819d8_62.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\62.WNCRYT
Size 8.5KB
Type ASCII text, with CRLF line terminators
MD5 06b386cbb4614358099b3741402557cb
SHA1 3e5423a8006fe9b80f934cba3448d42d0573398b
SHA256 1887d7df719819d8fe151b28b4b0555ea6e512f7a22db5a113e633386c1538cb
CRC32 E1AFC6B9
ssdeep 96:NexsLifxJrg/vPnX6QddAWX9hghNAmgKu3czK3r69+n926zJakV+QQDoYkE7DgXM:NSy0D236+YGKEr69O9rai+IEGtVLhC
Yara None matched
VirusTotal Search for analysis
Name 6360ce0f31ee593e_99.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\99.WNCRYT
Size 1.9KB
Type ASCII text
MD5 e6dbd1544a69bfc653865b723395e79c
SHA1 5e4178e7282807476bd0d6e1f2e320e42fa0de77
SHA256 6360ce0f31ee593e311b275f3c1f1ed427e237f31010a4280ef2c58aa6f2633a
CRC32 E4541A1C
ssdeep 24:4azu8XMnSZEjgYDT0g3xg2LSREyqyxDf5cNp/Tpn29Ey5ykDDzJ6v3Nev0Nv0f:46OeTYDT0ga4K9SNnCz0v9o0JI
Yara None matched
VirusTotal Search for analysis
Name 39527473bb838d98_10.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\10.WNCRYT
Size 147.5KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 2eb6ea782a14e0a3d065d8648f5cd22c
SHA1 6ebafc1149b4acaf5f62e585a68880f789fe6265
SHA256 39527473bb838d98a9bd7aaf40e4d4d780bb5d30b3aa38f376b7e9667b25c170
CRC32 E9AAF3CA
ssdeep 3072:pmlHI12yXdTj4NqaaWFgLlizJ7PKhHI7Y9r8wPsnU:pm5I12aT0Nqaaegi7yhKYd8wknU
Yara None matched
VirusTotal Search for analysis
Name d4bf9de657583b56_msg_31.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_31.txt.wncry
Size 504.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 55c6465064a979e7299c39d4e7c4c4e1
SHA1 8c6db66787f3ae0a050f06b10183ef6246d41fea
SHA256 d4bf9de657583b5672289a73b6d6de5181dcb854692b0f1516b50f916ff97595
CRC32 977C05F7
ssdeep 12:bkE5NUQjULF9UzVfcviqMtmI/PofgAd0WpJyx1Pc6oevEs:bkOCLQVGi9tp/Px20AyTcYvEs
Yara None matched
VirusTotal Search for analysis
Name 37484901eb40eefa_293.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\293.WNCRYT
Size 1.4KB
Type GIF image data, version 89a, 48 x 48
MD5 29c399d2467ae9540e459d333227a38d
SHA1 a8e2103ce9487dcaacda72dff2625d77181d82c0
SHA256 37484901eb40eefa846308e1da3ff6f240ea98f769a2afc3cf4fdba00327ecbe
CRC32 E8AE1E26
ssdeep 24:o+ATB/3ZACAP2UNR9KrXcP2ZLhzZGEWowggZx733HKNYMMzMHSUulec0:ohthA9eUN+rXAOZAoTgD2uQJulev
Yara None matched
VirusTotal Search for analysis
Name 5606a5f0d5dadbcc_state
Submit file
Filepath C:\Users\test22\AppData\Roaming\tor\state
Size 222.0B
Type ASCII text, with CRLF line terminators
MD5 9e620db1360c271273da7e897c994408
SHA1 27c10d2b59cba71684e4d4301b0bd2ec8898ac45
SHA256 5606a5f0d5dadbcc266cb362d38b2472ccf9856ec09e3bfe7aeb9a9e0bb4fedc
CRC32 F9EC3AA4
ssdeep 6:SbdWwxXRuPfFJtnXr87+QVe2vwR/EtbWWURbibfl87XSq:bwxXYDtXr87HVBvwN2PeSq
Yara None matched
VirusTotal Search for analysis
Name 85df965326111365_en_bw.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_bw.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 9b01ac071bd4b592aca192f65c933683
SHA1 917796405d237460ce2c7cd343e8ce54d29b8ea1
SHA256 85df965326111365b7379684f7508fd912eba2f0a1591625d9e9b1e6a6d8b4e7
CRC32 43F5D9CF
ssdeep 12:bkEK6HcFcMjc2aNt+ineX37Ctc6tqWbrpHnhgRdkX:bkx6HcFc65aNtLneX37Ctc8xH2RE
Yara None matched
VirusTotal Search for analysis
Name 926c8149c0163afe_readme.txt.wncry
Submit file
Filepath c:\python27\tools\pynche\readme.txt.wncry
Size 16.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 64dc834b60c37289b71de0f584c65fc8
SHA1 5d85e587d202ce6ae661d5de7ff720c392b43f63
SHA256 926c8149c0163afe17ab1a9907e69250c81e3c2d84d3a24f8e90fbc7aa896dc4
CRC32 F651D9DE
ssdeep 384:YR4OtkQ7YGsetWIPF7YAWQ9QunGe7p0sJShhs00zonj:YR99ftLpYAe2ftb0coj
Yara None matched
VirusTotal Search for analysis
Name f06cdaf343ba32c6_tk.gif.wncry
Submit file
Filepath c:\python27\lib\idlelib\icons\tk.gif.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 aee4b15c7bae7cbd9a9238b1733babb2
SHA1 8160d33f71a10880c6a102935ef185adb6c64ec1
SHA256 f06cdaf343ba32c6677da36d9591362b13b64a6cd47dd846a6d68a8bb3dc3dc8
CRC32 CED25CAF
ssdeep 6:bkEGTzgZPxwGw+S6nyBcoxhIE/LgmQpav2+6lGw2GIoXjlTZsTJ/ACGRn:bkEEkkqnS7xhNLzovUwHnjlTZslI1n
Yara None matched
VirusTotal Search for analysis
Name 9e3114d945cfa1e3_176.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\176.WNCRYT
Size 1.0KB
Type JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=2], baseline, precision 8, 51x58, frames 3
MD5 40074a933b364db54e3bc0a7a76d0d9b
SHA1 9c1c08f0f38aba2bae08bfab4493947c097aaea4
SHA256 9e3114d945cfa1e3d0a36541fbc11fe0134a140e853cde76a393e4d5de4b736a
CRC32 9A5B6854
ssdeep 24:P+I9YMWyo0XxDuLHeOWXG4OZ7DAJuLHenX37ckZpvgZ3XP1WyONhxZ:p9YM0uERA9cWKXP1K/Z
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name e24790f3f1f6a6c1_299.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\299.WNCRYT
Size 2.2KB
Type ASCII text, with CRLF line terminators
MD5 2e25ca733a0c4d643b98945a3d5a83a3
SHA1 24c179496d124efdb39e7638efcf5ed2560ea5ca
SHA256 e24790f3f1f6a6c1463865c87eea78ae5ff38da1e2feb17a61b831eba14f8e74
CRC32 0423E511
ssdeep 24:Z9F/JYQDK35XVw21dwX4TG/k0GZl/zwIGPryoLeAMcFQnsThcvw4IzzhQBShtjxu:Zv5+3fldwoWYlTgyoLei6rdPo1miSHGw
Yara None matched
VirusTotal Search for analysis
Name 5a2fb627f58ff0af_brndlog.bak.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\internet explorer\brndlog.bak.wncry
Size 6.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 bcc051e1a568af194ed68fb88d37d1f8
SHA1 9c41f314a95d1498f8bb40e9924728bca891d11e
SHA256 5a2fb627f58ff0af881ede6cd130f80f506e97abb713f28c8119edb525eb70ba
CRC32 AA6BCC48
ssdeep 96:offGczwrGP0Nje2ZWsuD/7TIL/9JcdEaSPkV4isSxFlRcyV6xUCmCiXqairGWlHe:GfGCAGP0Ni2WD/7EL7kIkSjS3lRck3C2
Yara None matched
VirusTotal Search for analysis
Name 68a10d55cf863d72_jellyfish.jpg.wncry
Submit file
Filepath c:\users\public\pictures\sample pictures\jellyfish.jpg.wncry
Size 757.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 58f11bbbb02e177de375a73ca3e4e1f5
SHA1 ed30685a0994a254bd4a78b52bcec73d2c62b49f
SHA256 68a10d55cf863d722b0ca5a8d67d6a9109c8733eadb83abf01c84421a1375633
CRC32 35C8DF34
ssdeep 12288:4+R7gUXHz6GLZre/EOC+c8f935Mw4a2CPyljzDMhIIFepNBil:TR7lF0Bln6JXeIIF0vy
Yara None matched
VirusTotal Search for analysis
Name 45035faa302ab6a4_usertile34.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 eaf6a6895a0e770389a94bec82fb2a29
SHA1 159fa46649b251792d3d01ee0a7a952ed21f94f6
SHA256 45035faa302ab6a495872bafd1283da0b97e5ebb71450128d29e6336243709be
CRC32 7F3F6B9A
ssdeep 768:zpueNhR01PqvX6JndLM60ABQGz2DcBnx7hJvKwu9w3nh3h+fh+dE92eUt/a5bNga:tB01CPAdo60ABg8nx9PXh3wy/qb7
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name ddb764baae4dadb0_warnings.h.wncry
Submit file
Filepath c:\python27\include\warnings.h.wncry
Size 952.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 7d7f0fed06925ff3b54d348ec759c3f4
SHA1 c22fce407a78f42da93655cf2ebb5cd0fc6d465e
SHA256 ddb764baae4dadb07a05020427669b5fbe5e5debb2708ef2a38115da62ff96c5
CRC32 E6B4C2EB
ssdeep 24:bk4bLksFhkiC7MMSfRZL7UDnLuq7w5ECHmttwQik:bk4JkiWENmns5s3wQik
Yara None matched
VirusTotal Search for analysis
Name db1fe30f75f8cecd_255.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\255.WNCRYT
Size 40.0KB
Type C source, ASCII text, with CRLF line terminators
MD5 bfc99bffb8cbe62f3a28339b07e7c896
SHA1 41082ddc25970a0e5a8e8ddec32b3e075b3be828
SHA256 db1fe30f75f8cecdb756f384706aa8e45a803142a6228e6e34ebe2b3b7226d39
CRC32 37FF50D5
ssdeep 768:BADcaJsui+wrCgWD1VFTK+IgrHec1uI4Z/prqaWTF14:BAouym3FMgrHec1uVWTFC
Yara None matched
VirusTotal Search for analysis
Name 70c0f32ed379ae89_m_romanian.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_romanian.wnry
Size 50.9KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 313e0ececd24f4fa1504118a11bc7986
SHA1 e1b9ae804c7fb1d27f39db18dc0647bb04e75e9d
SHA256 70c0f32ed379ae899e5ac975e20bbbacd295cf7cd50c36174d2602420c770ac1
CRC32 481B5740
ssdeep 768:Shef3jHdXG2Cz2/vBAOZsQO0cLfnF/Zhcz7sDsYZBB/0gBjL+IU/hbhMVDtsR49P:ShehlrGR1m4dx9mjVyAvg7ouDT
Yara None matched
VirusTotal Search for analysis
Name 1b4979874c3f0253_642.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\642.WNCRYT
Size 251.0B
Type ASCII text
MD5 fd946be4d44995911e79135e5b7bd3bb
SHA1 3ba38cb03258ca834e37dbb4e3149d4cda9b353b
SHA256 1b4979874c3f025317dfcf0b06fc8cee080a28ff3e8efe1de9e899f6d4f4d21e
CRC32 570A7900
ssdeep 6:SlSyEtJLlpuoo6dmo4FjbJFLo4F+3v6rZo4++3vjb0f6HK:4EnLzu8QJFL+3v6rv3vbq
Yara None matched
VirusTotal Search for analysis
Name 3a114ef4a757107d_entry_points.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\setuptools-41.2.0.dist-info\entry_points.txt.wncry
Size 3.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d41dddf1c5870432b0d01f8bf86492c0
SHA1 8fca34154ef8b68fa658ea81e41c4284e212561c
SHA256 3a114ef4a757107d01f6e0755be782c70e6df34a777939acd421b4462296ee1a
CRC32 C9099DB5
ssdeep 96:o1cuGfvYUsZFreHUp6nOP9fO8ESnPGq7P1vCe1DD5uQFw:ovGfvQZMQl9MSnemIe13wQFw
Yara None matched
VirusTotal Search for analysis
Name 18722f081b971abb_mk.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\mk.msg.wncry
Size 2.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fd2c5b2c85548f43a39c0bfa4094aa48
SHA1 3b5761cd2cd2375733a920285926f34cea555408
SHA256 18722f081b971abb8ace4f9badb8f5ddad13c9343938e1b9d1c3bb89f33bcaeb
CRC32 F8196FC9
ssdeep 48:bk2YNZQKQa2ACoPGVfs8PqE1Vql4bV4XWj5mXK3zPvIv14dFDUdAwHlz7Z:o2YNXB1TPGVfsOp1VC4u2QK3zdTUdNRZ
Yara None matched
VirusTotal Search for analysis
Name 6ab315e02afef819_msg_09.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_09.txt.wncry
Size 744.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 91d0045848a56436958e9d881cf49aaf
SHA1 2f7358224e5db93fe0556c7a2d478e6b45c11f3f
SHA256 6ab315e02afef819891428d700bf619f09d06d30e3476d7aab60002f3559a307
CRC32 A1B7BE11
ssdeep 12:bkENr7eLktEduOr97GCdEbMr8AO6RYlZKm2AbHUnPS6MuP6PzE6IpPUHzF3iJ+B/:bko6ktyPFsTAhRYK/AyE06XTF30WIpk
Yara None matched
VirusTotal Search for analysis
Name a1e85ae3b333d58a_symtable.h.wncry
Submit file
Filepath c:\python27\include\symtable.h.wncry
Size 4.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 98a2d4058e9179b0b84084aade4a8825
SHA1 6ba4fcc2567f1371d5607aacbbc28d165fe328c4
SHA256 a1e85ae3b333d58aad0a2af5c5f91c45e9b98ed544762547757a51f286d9067e
CRC32 009C0E12
ssdeep 48:bkS0/waasv86BCeWIGtHuOjRLMtoO7afiarvEUbdGWM0VSF7QwDZciN4NhLKqLYJ:oSEaL6FWIGtH+toXNGGwydh1Yrekf3V
Yara None matched
VirusTotal Search for analysis
Name d2679ae95ba1b57f_426.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\426.WNCRYT
Size 36.5KB
Type ASCII text, with very long lines
MD5 8d60de6df728358dfaef101b50dd9ca3
SHA1 a654ef083ef82f7b28e3451d58312771310ad3fb
SHA256 d2679ae95ba1b57fb4ff188f9f4d13778d5c29f38f6554ea9a4764073436bdc5
CRC32 9E5D937C
ssdeep 768:mlEL7gYrJvTjzDmwQE1R0xhBQmtYpB/fZRg3mOf6BzO7FeN:mlEL7gYrJbyPE1u7BBtK/fZG3mUP7Y
Yara None matched
VirusTotal Search for analysis
Name 3bed45bbff732870_pyexpat.h.wncry
Submit file
Filepath c:\python27\include\pyexpat.h.wncry
Size 2.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 bf3697618ee64a601c15e52f439920a0
SHA1 c53e2d57a813cec00c77bab64441ff05aa50ff62
SHA256 3bed45bbff732870a916d300179ebc3564072234e77d1c968fe07a8d87442cf5
CRC32 D9F9299A
ssdeep 48:bk47KTQwWTVyqNvnwMWv1ieHrsUm6/OGWI9fcCoMN7vN/yzu8s:o4GTQwojNfwMWv1ieoW9Wo0MvNyzXs
Yara None matched
VirusTotal Search for analysis
Name cc5a4ae09efad7e2_324.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\324.WNCRYT
Size 1.0KB
Type ASCII text
MD5 7c9632c4cd36285608db17df97f3a6a8
SHA1 578f9132fc994bd29caab35b20f137166bd5e6e6
SHA256 cc5a4ae09efad7e20c269a46e31abf9fb85eaab2a1e1b573e3717f971f4b3325
CRC32 5B33A4A9
ssdeep 24:e92cN47i2RlGn0WGJAXagXspXFjXFdgdsH7kberMyGn7:mN47iilG0WGJAP8pB1+mH76e4yGn7
Yara None matched
VirusTotal Search for analysis
Name ccc2b4738db16faf_97.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\97.WNCRYT
Size 1.2KB
Type ASCII text
MD5 3b4bee5dd7441a63a31f89d6dfa059ba
SHA1 bee39e45fa3a76b631b4c2d0f937ff6041e09332
SHA256 ccc2b4738db16fafb48bfc77c9e2f8be17bc19e4140e48b61f3ef1ce7c9f3a8c
CRC32 993CCEB8
ssdeep 24:4azu8W1Yn1YZ1waUuvVTGiMiLpBgoVTJ01iLTh/w2SJmG5F1svtFmsv5d:46K1y1Mv9GrM9oc/FSJmG5F1KtFmK5d
Yara None matched
VirusTotal Search for analysis
Name e30e93d691d3dc9b_es_mx.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_mx.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 8fe6bd57561b32cce83fe602448920c1
SHA1 8fc70b14897af0d8f418ea1e308ef0212c8f45cb
SHA256 e30e93d691d3dc9b951a7c6ec5e9eaa2c2c253678fe988c3fb3a27f03efaf764
CRC32 5B0A1497
ssdeep 12:bkEros8k7lATOlU9fvarS4jl8JZznDre2cL45o4kYGfuGmIygBC17d:bksos8khATOkKrLjeJpnfBcs5o4HGfu1
Yara None matched
VirusTotal Search for analysis
Name 1b8e5281fc4792f0_728.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\728.WNCRYT
Size 224.0B
Type ASCII text
MD5 223da3f7c647bb53a937fe92ce5e1639
SHA1 a5190f975f481aaeb69d10c0fff0ec3624146c4f
SHA256 1b8e5281fc4792f09d848bf0720401a68eb700207e7e8c8c00ee1614ef6a3093
CRC32 AEFF84AF
ssdeep 3:2LGfEaDBkKC6W+xKC672XAW6KUNfKC6DGH4JpzVHeopHZHbRAcj+42tbA2Mu:2LGFY6tj66I6DTTfpHoi92tj9
Yara None matched
VirusTotal Search for analysis
Name b5f9b106011e1d84_184.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\184.WNCRYT
Size 5.0KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 196x196, frames 3
MD5 2c8e4b5c21697cc270c2024064c4eb93
SHA1 3a9b25c868cf0b2ce9503c802da78f22f689fc6b
SHA256 b5f9b106011e1d84aa5349ce86b76b46da8bf7c6b5c580b7da27fb97dd1688e8
CRC32 39759AB7
ssdeep 96:av31MHt9VX+2IdgjjfepsI29pu19p6oxMEnkvdBu/OYu:ht3U+fepsppo9koGEngBu/a
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 6152e728596b5483_476.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\476.WNCRYT
Size 494.0B
Type PNG image data, 31 x 18, 8-bit/color RGBA, non-interlaced
MD5 f8b8ecbb5aa27ebb79be363cc85f0580
SHA1 2358a430811447e9bc423674d79ad704aa8c2a56
SHA256 6152e728596b5483d0040b1f2ae262804871e47019d5df1a91477fa536b6ce30
CRC32 D866CC56
ssdeep 12:6v/7WV/Pln+5Q6oexSHOsdNnGpEGrwmrhbJF8eQLakH/3Mx:BR+poexSHlNn4p7hMerx
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name d582406c51a3db1e_692.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\692.WNCRYT
Size 346.0B
Type ASCII text
MD5 9cd17e7f28186e0e71932cc241d1cbb1
SHA1 af1ee536aabb8198ba88d3474ed49f76a37e89ff
SHA256 d582406c51a3db1eadf6507c50a1f85740fda7da8e27fc1438feb6242900cb12
CRC32 3A6DE8B2
ssdeep 6:SlSyEtJLlpuoo6dmoAykaRULH/XRxvBoAyjZRULH5oAyU/G0OZoAyxW3v6ZhLoAR:4EnLzu8I5xEOKRWW3v6w3v8AC
Yara None matched
VirusTotal Search for analysis
Name d27adaf74ebb18d6_104.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\104.WNCRYT
Size 1.9KB
Type ASCII text
MD5 ffd5d8007d78770ea0e7e5643f1bd20a
SHA1 40854eb81ee670086d0d0c0c2f0f9d8406df6b47
SHA256 d27adaf74ebb18d6964882cf931260331b93ae4b283427f9a0db147a83de1d55
CRC32 42C6FE3B
ssdeep 24:4azu8Hdd4CLxLtmCLoCLHCL3CLXLICLP1ptzLzCJCLt5LL53h5Lq+p5LcL3pLzCt:4655ftB9hMcGlhO8/n/0ecOfC3
Yara None matched
VirusTotal Search for analysis
Name 15cf5d1380c28855_open.png.wncry
Submit file
Filepath c:\python27\click\click_image\open.png.wncry
Size 760.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 fb6ad503b4cc354f513ba1af5e42d97e
SHA1 e0dc9ceef098ace2f4553c5d33d2e713b4d681d9
SHA256 15cf5d1380c288551824fded50b3cf63e936c5ea44aed7accf7cdeeb115f9b5b
CRC32 C492153B
ssdeep 12:bkE5jKirMAQo4UteH3bSis8EwFtDGKpaLqxRvMYGWN0U32N9ydtMNmTV9xZTsiAe:bkSjKirpQo4seH3TXFtakBxGlWND2NUL
Yara None matched
VirusTotal Search for analysis
Name eeb1753e4f02d2e7_keycert3.pem.wncry
Submit file
Filepath c:\python27\lib\test\keycert3.pem.wncry
Size 9.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f802a3ba127ce37412635672c911cead
SHA1 d73363518a77df14d00534b11eac4789982980ce
SHA256 eeb1753e4f02d2e788ac86a63832a259e1c80bfd4357cbe92a63f9c1b07ab98c
CRC32 628A9C0E
ssdeep 192:K1yNMcH1GmdkzlQpSpQbDQBC4SfL52ObvgIZtrISHgJjk3:1l7dk5Q8YkB7Sz5VPsSHiq
Yara None matched
VirusTotal Search for analysis
Name a110589734098137_softblue.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\softblue.jpg.wncry
Size 10.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e838950642ff980bcc3239325c36e379
SHA1 548941f55939bb1c397040995c781d5bf07a1741
SHA256 a11058973409813706e558ad382d3f3d3cbd7eee72b82079e90dacea1653cd77
CRC32 8E1E020D
ssdeep 192:YUXZSIDBcg0FcYQZp1XgzsbiVWUoxIyro1TRaAtrA9lMNpcqegIphVJyxOZNmVOn:YwZSaBicfwzsuVoxIycP1AXMHcqfS/Nl
Yara None matched
VirusTotal Search for analysis
Name 77dfd661a7e24809_thumbcache_96.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows\explorer\thumbcache_96.db.wncry
Size 3.0MB
Processes 2632 (WannaCry.exe)
Type data
MD5 dfb5aae6663fff329e01266bd28587e7
SHA1 06c3aad40bbf2cedf367e6fcb6451b1da71c821b
SHA256 77dfd661a7e24809a1a2fc96c6db37202cfa6eb0296a9e0274a12e0e65dfa9e1
CRC32 E3BC29E8
ssdeep 98304:rMh6rBijKRvwX4PvKL3oYIRBIKfJ6TqvD5U37Z:rMhusjK6X4Pvi3oYCI7m637Z
Yara None matched
VirusTotal Search for analysis
Name 984bd1f272d6e5b7_readme.txt.wncry
Submit file
Filepath c:\python27\tools\versioncheck\readme.txt.wncry
Size 2.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 69d89f6a7900eeacc2c12827d4a1e7bc
SHA1 ae5d02382cdf09d6326460e350603eebec716115
SHA256 984bd1f272d6e5b71658123d9422fee22cc11f1d088a16e14d64d072d7e90741
CRC32 D27A19E5
ssdeep 48:bk/hCpeEnI16zDO/fFgkEfUTB311kGO7cnFDdXB4QlbTb6ePqm1BBWBF:o/I3nI1/faolF1bCcFDz4QlrDqmLkBF
Yara None matched
VirusTotal Search for analysis
Name ee98df7691fdab03_313.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\313.WNCRYT
Size 275.0KB
Type POSIX tar archive
MD5 d15b8c2965f39e2f48d397b5450ed4d3
SHA1 bcb68be3bc38cbc281ca9bd5482b96479e7a20e1
SHA256 ee98df7691fdab030d39a237f6c6131341459b8de8605782f3730811b8239fc9
CRC32 1241DAD3
ssdeep 3072:/ZjQn1gcZjQn1gjZjQn1glZjQn1gYZjQn1grZjQn1gqZjQn1gXZjQn1g2ZjQn1gM:
Yara None matched
VirusTotal Search for analysis
Name a842aa7db2f2f34f_244.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\244.WNCRYT
Size 3.0KB
Type C source, ASCII text, with CRLF line terminators
MD5 f3f01bbb9f3e04dacde8e4e366a6150e
SHA1 dfcb7a83e8156b12d6bb327fb86a3e0a18c0950e
SHA256 a842aa7db2f2f34fcb0c629001e782d0890ad406354664b9631dbe8b4ed4021a
CRC32 A0176859
ssdeep 48:37IUXkYPTvrLEivEOXGEBvlEqkEB9pE1VmvEB8E9CEW6Y+y2g8tHtF4CIx7tk:LW68dkJEOq1VZpbj9LpIx7tk
Yara None matched
VirusTotal Search for analysis
Name ddc78a4a0ff0b3dc_zh_hk.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\zh_hk.msg.wncry
Size 1.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d6a78406b41f92cb76c9866423b2c5b9
SHA1 68225b137fb348e028a9fb5950ff90746ceeccbb
SHA256 ddc78a4a0ff0b3dc4c551ad0f227c531ff48b755a7eeb75d8f679de50ea27bab
CRC32 37282B65
ssdeep 24:bkM/FUkZcbjUTm5aN1OcGH/ylAr2yES700Nt:bkXkZjyi0ylK2yH70e
Yara None matched
VirusTotal Search for analysis
Name 78707b6417040ae0_jrjo1d57.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\jrjo1d57.txt.wncry
Size 520.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 9964fb1a7aa14a544c9e41016653fa80
SHA1 b559d85edd7b4c767f274966b37ee28a5ef02397
SHA256 78707b6417040ae0f7e5fce15601e4098d9f5c021719b2712707fed3c9a73f17
CRC32 0141E5EA
ssdeep 12:bkEsdPuRsfTIExLw9UgJCdDBATbsiaRuGnQvajreNA3L88:bkFPuRsLbhw+gJO8hLy2ip
Yara None matched
VirusTotal Search for analysis
Name b07f53fc2f0f0dba_feqkx2f6.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\feqkx2f6.txt.wncry
Size 600.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 9acec59c58525e86816eba00467bd636
SHA1 2ade8a935c7a77c6419f695bb76fdb81c4c588df
SHA256 b07f53fc2f0f0dbaf149e2a3a45fc0f96dc058d197e29a4a6722222d22095873
CRC32 CEDBC687
ssdeep 12:bkEQiirJMgBXZfx8u7ZhE0k5bqHl8e1xGgABElZMy+Owyv:bkCirJMgBJ37ZhE0Gm8PgAylWPOHv
Yara None matched
VirusTotal Search for analysis
Name e1aefbb53f56a80d_54.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\54.WNCRYT
Size 2.0KB
Type MIME entity, ASCII text, with CRLF line terminators
MD5 4c9fa2c0603df5d73918f23164b667d8
SHA1 20bc5467ed0cb8940651ebdefd32a94c029d532d
SHA256 e1aefbb53f56a80dcecbd05029d39fe7f44ba8b34559f6289a9464336821ffcf
CRC32 20D76CF9
ssdeep 48:mTohFNd+sS6Jhd+YkuTJhd+TO9dEp1JhJh32F:mTohFN8sS6T8YkuTT8T4dEPTT32F
Yara None matched
VirusTotal Search for analysis
Name 6168d264468f1ee8_177.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\177.WNCRYT
Size 2.5KB
Type JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 900x86, frames 3
MD5 2955f78cd81d76daa54efa893b75fd6e
SHA1 b0977f82fac3392ea2de5159a9a99c0bf47775b3
SHA256 6168d264468f1ee8afd2a0f424ce911c81f915a2f0497a859270bbedaedf802e
CRC32 4DCEA4F0
ssdeep 48:14/zxuERAHklAG4J2NvyihOKQoN1oy47Db1ShXGxSjnW6wgG:qbYEqkqzQKOQfyWDbAccjnW6wz
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 73a6ff559cde06c4_opcode.h.wncry
Submit file
Filepath c:\python27\include\opcode.h.wncry
Size 5.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b731bab82066ce9e34e6328e61454005
SHA1 8957a6596aaced15540fa29aeb0077378504c8ea
SHA256 73a6ff559cde06c433e4bba130567ea57774e48cd0696821d85595791e3b49bd
CRC32 DB719E8B
ssdeep 96:obUL7A1ear3LzCtou7OX18o/yr2M/QUq0cJal/Q+fX+qqX2LECthq:YUg1eaTLzCx7CH/sZ/QL0sa9uc8
Yara None matched
VirusTotal Search for analysis
Name f9641a6ebe3845ce_132.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\132.WNCRYT
Size 2.3KB
Type ASCII text
MD5 d145f9df0e339a2538662bd752f02e16
SHA1 afd97f8e8cc14d306dedd78f8f395738e38a8569
SHA256 f9641a6ebe3845ce5d36ced473749f5909c90c52e405f074a6da817ef6f39867
CRC32 B2F27863
ssdeep 48:46P4QX/wQT0H/u3rPc8JD57XWWND8QM70xJi53Ljtef:hQ556rVDWZcLOO
Yara None matched
VirusTotal Search for analysis
Name 81aae206aa89c03f_hi_in.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\hi_in.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 55750e2a0cfc9cc28723ba8759a4c596
SHA1 260ff326cfb4635006c4bf35165c8d029cecdfad
SHA256 81aae206aa89c03ff04cdd36970336a67ef3a0e8f3e5a40952be8ae087437f74
CRC32 9C8969DD
ssdeep 12:bkEwdoEHYO/p583obXXdyhT0fVxc/cjYbo47mqpDNe:bkjDbcF09xm847nDNe
Yara None matched
VirusTotal Search for analysis
Name ba557a3c656275a0_655.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\655.WNCRYT
Size 251.0B
Type ASCII text
MD5 40250432ad0dc4ff168619719f91dbca
SHA1 d38532ca84e80fe70c69108711e3f9a7dfd5230f
SHA256 ba557a3c656275a0c870fb8466f2237850f5a7cf2d001919896725bb3d3eaa4b
CRC32 890E9DEC
ssdeep 6:SlSyEtJLlpuoo6dmooygUFLooq9X3v6rZooy9+3v9f6HK:4EnLzu8SrUFzsX3v6rZJ3vMq
Yara None matched
VirusTotal Search for analysis
Name 2a8efd6fa666f454_nullcert.pem.wncry
Submit file
Filepath c:\python27\lib\test\nullcert.pem.wncry
Size 280.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 96d2986f38c980e29400647f3c8efd55
SHA1 708be461ce12d86ce914e444773bf62115895f87
SHA256 2a8efd6fa666f45424070f68de9155c26be7aeedbce4354fda3b4058164e1367
CRC32 1EFDE9AE
ssdeep 6:bkEFiWloa587m86WcAaI4IulVY3LB2nTZw7unrE+ZigYoaeDIf/rj59bAw/:bkE0Wlx5r868GIulVGYnTZw7udZVYyEx
Yara None matched
VirusTotal Search for analysis
Name 1628ee07dbf686bd_readme.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\readme.txt.wncry
Size 408.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 03d69fbf4a5952acba0e16ae9bb80c73
SHA1 45b7f106881dc27e48b22e02e8e3e41370c457b6
SHA256 1628ee07dbf686bd4fe41bafb72878884182a46ef12a059d105899cb5c7c6678
CRC32 E2E3E64B
ssdeep 6:bkE8c/tYXH44HYtVaFcKTE0C62hNpmvEK82rWEucrkMqXunDWYJxlxxfOZg:bkEJ/tefWEehLZ/2X7wvXunD5J3xQZg
Yara None matched
VirusTotal Search for analysis
Name a054aec259b85ece_monet.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\monet.jpg.wncry
Size 2.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 427df8866d3fbd01d8fdec8d563f2bdb
SHA1 4ce052d62fc77a191b90d82be17bff658e524766
SHA256 a054aec259b85ecef49d6454b3222acc72b5deb99b0d2571b1efd085c9fbd7a0
CRC32 3EA498FD
ssdeep 48:bksduv1/u9Dba1qx3GmTwocoWJr29712MaQKlWCL9CAxgmmYN:odQAmTwiWli2MaQKlWC/gZYN
Yara None matched
VirusTotal Search for analysis
Name d9d41f8c06b21e97_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\128.png.wncry
Size 4.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 912e9cb7ee0e70d2539cffb036904444
SHA1 805fcf20a11cd97a8f7a4bb12958036b3eaa9205
SHA256 d9d41f8c06b21e978439fc2447d5f5ff7370098b3a89ffdc787051cf1e7c7a56
CRC32 0C0D15CB
ssdeep 96:oxsEpG7EHwmTn2GniQ0bJcWp59L4dTFERtClyuNUuLM+DM0+4wVJ51CZtpX:qsEpGIHwmL2Gi3cIL4dm30UuLVDn+4wW
Yara None matched
VirusTotal Search for analysis
Name a0356696877f2d94_m_latvian.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_latvian.wnry
Size 40.2KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 c33afb4ecc04ee1bcc6975bea49abe40
SHA1 fbea4f170507cde02b839527ef50b7ec74b4821f
SHA256 a0356696877f2d94d645ae2df6ce6b370bd5c0d6db3d36def44e714525de0536
CRC32 7EFF84CE
ssdeep 384:SheftipUENLFsPzy3EFHjHdcqH24G2ZN1EDCv3Apb0WD5gYV/S4L3rnzdeo75Y3f:Shef3jHdcMG2NpZrS14F
Yara None matched
VirusTotal Search for analysis
Name 54dbeed654366dc7_344.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\344.WNCRYT
Size 1.0MB
Type data
MD5 c4a4666125a66d535cff3959a75a0d7d
SHA1 631e1f53a5f11fdf8c75bfac73d5bc009e77d398
SHA256 54dbeed654366dc7e66a4b8ad20f05f005af4da6caa285168a50e48a8c27ae5c
CRC32 5995BF76
ssdeep 6144:g4tgOy4tgOUArphYbCMPugCqvArphYbCMPjgCqBgCq0IMeUgAXV6xqBe:g7FIphYbCMP2kIphYbCMPvuBeUNcx0
Yara None matched
VirusTotal Search for analysis
Name 3cddeddc6bee5fa6_frameobject.h.wncry
Submit file
Filepath c:\python27\include\frameobject.h.wncry
Size 3.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 31290aec15a3b77809ad9d647018e4fc
SHA1 c04e56c9ef3fd48217458a3cf0cad7acc4b3c544
SHA256 3cddeddc6bee5fa66e4f7c06e3c4b4a3ee4eea78c9f6df88d64039c6b63b904d
CRC32 8A34D823
ssdeep 96:ou/ej3bo9BbIE5FnAQgZux1aeAdA9Z01GZlCTxbT2t:A38BBknkaeAK8GZUbT2t
Yara None matched
VirusTotal Search for analysis
Name cc57fe0ef19948d2_22.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\22.WNCRYT
Size 571.7KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 106331c1dbe2505743f7d4a00a1b0768
SHA1 25356d72b21031180efbc62ddf84c76c3b858e39
SHA256 cc57fe0ef19948d2262ae062a1a78657c3899bbd8f172439a53b53ed6720fa24
CRC32 1FA9496F
ssdeep 12288:tDA/G5WibwsyhYrUWOmClnzk6TLDA/G5WibwsyhYrUWOmClnzk6TLDA/G5Wiy:tU+5WisjY7OfhTLU+5WisjY7OfhTLU+m
Yara None matched
VirusTotal Search for analysis
Name a765ba81bfb7add4_prefs.js.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\profiles\qxo5wa6x.default-release\prefs.js.wncry
Size 12.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b50fb248343cb7240461c7461508fde5
SHA1 da1d7c180f9f8b5e3822d8b3caaf91b32a2f876f
SHA256 a765ba81bfb7add4a22033907f56f770496123adcf6274ce24d9109be53affe6
CRC32 5C05EC0A
ssdeep 384:/2EiIHVL7xeA5SUUnwg97jvC0/9T1PaxcMHDnrqAW:+WHV5eWtUwk7jvC0Fla/DOp
Yara None matched
VirusTotal Search for analysis
Name 620028ee8cdaa589_installed-files.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\mouseinfo-0.1.3-py2.7.egg-info\installed-files.txt.wncry
Size 472.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a00022615160e99bdb8127e5ccd2d18e
SHA1 278e662cca671e13056acbf3f30f64b32f1d7462
SHA256 620028ee8cdaa5896b9d13eb0fbde394b74240d516bae18068aa7ae75c4203c6
CRC32 796F54E3
ssdeep 12:bkEh1C+ra2n9F7JHiPpLND6P9577lAfMAthDZ:bkqCaaE4vSn1O
Yara None matched
VirusTotal Search for analysis
Name 115c582fad82b32e_68.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\68.WNCRYT
Size 1.5KB
Type ASCII text, with CRLF line terminators
MD5 7d72a7ac2731b2731c93f1cf1a5c95c9
SHA1 c1f18959a692fb8d5b09ff85283489c67af69f37
SHA256 115c582fad82b32e5cba76937fffb5be9e8d117e4b5a7c0dd4ac9778f6a20622
CRC32 56EB51EA
ssdeep 24:N6n8HQz7wW8Uew1cCkNhlKNZ+RrdrYiutdOrG9P0d22xuJv2SeYbvCUv+vPvLCvx:Wk14+g3uSiq
Yara None matched
VirusTotal Search for analysis
Name 0a1bb67a8b436690_727.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\727.WNCRYT
Size 231.0B
Type ASCII text
MD5 bf11c210c8eadaf03be26feef526c68d
SHA1 f504d7cee74103d1fb6468daa2809222aa023758
SHA256 0a1bb67a8b4366906832d10298c42d1d574e1823653c01e63836d486a3529e09
CRC32 CA085138
ssdeep 3:2LGffD6KC6W+xKC672XAW6KUNfKC6DGH4JpzVHeopHZHbRAcj+42tbA0KGYXMw:2LGX86tj66I6DTTfpHoi92t3dY3
Yara None matched
VirusTotal Search for analysis
Name 1adfee058b98206c_m_finnish.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_finnish.wnry
Size 37.5KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 35c2f97eea8819b1caebd23fee732d8f
SHA1 e354d1cc43d6a39d9732adea5d3b0f57284255d2
SHA256 1adfee058b98206cb4fbe1a46d3ed62a11e1dee2c7ff521c1eef7c706e6a700e
CRC32 D41DAC3F
ssdeep 384:SheftipUENLFsPzy3EFHjHdg2oG2l1glOmeo75Y3kmA31dv61QyB:Shef3jHdMG2l1AO3ZrS14l
Yara None matched
VirusTotal Search for analysis
Name 4d0bd3228ab4cc3e_335.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\335.WNCRYT
Size 3.8KB
Type GIF image data, version 87a, 120 x 181
MD5 bd12b645a9b0036a9c24298cd7a81e5a
SHA1 13488e4f28676f1e0ce383f80d13510f07198b99
SHA256 4d0bd3228ab4cc3e5159f4337be969ec7b7334e265c99b7633e3daf3c3fcfb62
CRC32 FD4A25CB
ssdeep 48:9qqbIh+cE4C8ric/jxK5mxsFBu3/0GIJ6Qap1Y5uMiR8pw5rB/SgijDb+TOh:hy+mnZ7xK5IsTwDQmkdiiG5rB/BE+6h
Yara None matched
VirusTotal Search for analysis
Name 9343a01cadbf5623_300.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\300.WNCRYT
Size 4.1KB
Type PEM RSA private key
MD5 6078173d1ca2be54dc629aa66d1973f4
SHA1 e5d9a79426b55b8f4e68f264ae286b68d1e44ad4
SHA256 9343a01cadbf5623ff0c0025d984864bf9fa78ed8425cbda5412127f0fa8f89c
CRC32 DDDFC127
ssdeep 96:LrQmhB6luuEnqUxAOD8xBjHncLHteQMhILymfLU94NVq:HQm4uuuqvO6LcqeLymfE4NVq
Yara None matched
VirusTotal Search for analysis
Name ddf9242072e64fca_pythonrun.h.wncry
Submit file
Filepath c:\python27\include\pythonrun.h.wncry
Size 7.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 46e3cd0e4bec4c3407290fee45e6b142
SHA1 68750c764e59ea71b16447293ec704d5a7c755d4
SHA256 ddf9242072e64fca82998e1471c49369e2953e9b2d9a68bd4baa25ff7efab7bb
CRC32 2DEE5BC1
ssdeep 96:ozE2pNmCy7bzArJBjO+WoadL62yv1F9Iwj/j811j1IBPSlgIBA6AmfiyQREY0itl:uqCyLqjhyyvX7C1j6xSlgImrmfJQeSnl
Yara None matched
VirusTotal Search for analysis
Name 61f63580e416eb8a_343.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\343.WNCRYT
Size 28.0KB
Type SQLite 3.x database, last written using SQLite version 3021000
MD5 6789f45721e36b5d9a809917fe2a52fe
SHA1 a53a8189104c0d9da71c39fe2e6a392876984298
SHA256 61f63580e416eb8a2c3c0b43ce1f8921d88852fa32c114261dc328e0714a6878
CRC32 06DC704E
ssdeep 12:TLiqidnGb0EiDFIlTSFbyrKZb9YwFOqAyl+FxOUwa5qgufTJpbZ75fOSG:TLi+NiD+lZk/Fj+6UwccNp15fBG
Yara None matched
VirusTotal Search for analysis
Name 2398763c5b727a91_tm01793064[[fn=균형]].dotx.wncry
Submit file
Size 69.6KB
Type data
MD5 39fe277997dab13a5ed4cf93120b4e11
SHA1 d87a6f8d5475fee2e6108377af85da56ce31de5a
SHA256 2398763c5b727a91cadddb24ff8d6114d7d1f5da49379e7e418398432ca3fa1d
CRC32 ABFC3BC5
ssdeep 1536:ODn/olFtocjeKd4RD31fnK7LTKqjsUyBtPvdw2Cvk1kHtSzFgE0GRx1wM:O/aFZjI1PKz6PVzCvk+Huvz1wM
Yara None matched
VirusTotal Search for analysis
Name 826e301281720b4f_icon_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\images\icon_128.png.wncry
Size 4.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6852446a3ba576655c9613b14ad753fb
SHA1 f3a9db44af3ac3f53ccd8af3a0d9cba67051b22b
SHA256 826e301281720b4f3fd9f5d03fe9fc85efb98fd0fc2c1ce596cde95188a2e692
CRC32 E2792A52
ssdeep 96:oNr5S847qO5gEQZmNDLG98rHKmlph7M9uiIg3qurCrKsot:y9S/5kINDLGsKEr7Ekg31lt
Yara None matched
VirusTotal Search for analysis
Name 8d73c1adf3319af4_472.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\472.WNCRYT
Size 639.0B
Type PNG image data, 51 x 18, 8-bit/color RGBA, non-interlaced
MD5 688cd0a58a13046c896a9b8a054917a5
SHA1 c378c97f05114395e551d17ceab5768c03aef7b8
SHA256 8d73c1adf3319af48299046c229541a38546f3b5fd4e99808e5fa734e4f68735
CRC32 BAC34FD6
ssdeep 12:6v/7+M/sb+nKHIlSyD7F6TrYlGkbg8VAgaoXjBhrzzRy5feOB/ApPrukbmS:7FM+yD7F6olG0VcSD8fVApPruM
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 80f7da46e7843368_tai-ku.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\images\tai-ku.gif.wncry
Size 5.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 9701a8e9b0be8ebe190d90fad543e000
SHA1 36fb626f44b16c4a89770897200035310896b900
SHA256 80f7da46e784336804b7440dbb4d1bdd9e1a1cc3204da52337188db4a3151614
CRC32 BC2EBD97
ssdeep 96:otSqadTsSEFhnaTLxh8mxKlgEF1cWZxKjDL5af8xZt8F1sldX4eZ8uweFz/zJcTH:YSqBFhIUlgEF1cWiXL5afy7oiDX4e+SA
Yara None matched
VirusTotal Search for analysis
Name 71e5367fe839afc4_633.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\633.WNCRYT
Size 310.0B
Type ASCII text
MD5 1423a9cf5507a198580d84660d829133
SHA1 70362593a2b04cf965213f318b10e92e280f338d
SHA256 71e5367fe839afc4338c50d450f111728e097538ecaccc1b17b10238001b0bb1
CRC32 CA14152F
ssdeep 6:SlSyEtJLlpuoo6dmoKr3v5oKrGaoKr5vvNLoKrw3vULoKr5o+3voA6:4EnLzu8si2vvNa3vuF3vo3
Yara None matched
VirusTotal Search for analysis
Name cd840e5daaa9a6a1_dont-use.txt.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\dont-use.txt.wncry
Size 344.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0c21dabac44cf38ed1750ba4c4b48a77
SHA1 1d986b6758bd8ce360a34d0be0474b478d395009
SHA256 cd840e5daaa9a6a124277aa5c481704bcae7e9530ea56e6a2aaf2e6f24647ac0
CRC32 3D035795
ssdeep 6:bkEvtkphEGbuVnR8veeAt58WURGc04haVedMz2+zsOT6OvDDF3hcz+UzD7rkmCur:bkEvWPEGqtR8WIRGCQVek2+PT6QDFxcn
Yara None matched
VirusTotal Search for analysis
Name 622d8defdd6b6abd_usertile31.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 9be40486ad4e673aec97906a636ccb2b
SHA1 19130bbaf3f33098a884ae68b3e5b0e8e2789c14
SHA256 622d8defdd6b6abd80a45ccec629363cf38a7d338945cf1af27bdfe7d0b777b6
CRC32 FE14EBFC
ssdeep 1536:A9Chrh8ImnBf6hHPbbnd3KO+nAUHtzRftvFS4WMCv:A9GqznR6xD53FsAUHrfBWMs
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 7508a28c7d6bb920_af_za.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\af_za.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 225117fc7c4507b8824bfde28b7762c3
SHA1 9f5b4ce621aa76535d751a5f29855ed1059b7762
SHA256 7508a28c7d6bb92006b2c6378c59afae50a0d8f3222d9f19e468b68e58b2617f
CRC32 A8F2D520
ssdeep 12:bkEXQW1C8zFlqooGYh3AFErsHHHaLNkSxqUA9g8Jd7sT5Ju3:bkIQUz2ooGYCFesHHHFLVQT56
Yara None matched
VirusTotal Search for analysis
Name 11f084a9a379a926_big5hkscs.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\big5hkscs.txt.wncry
Size 312.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 912f0734f23711a109cf0f7b2aedb2f5
SHA1 5fba17cff087e137bf8eea79c522197e6fa92ca1
SHA256 11f084a9a379a92671c2a96aae5d18f6c731eee3a96d83396abf0c225fa06a33
CRC32 7B7C517A
ssdeep 6:bkEOa32doC615pBEcyf45CRsWZFClj3TSoGbBF0O/Z/81F4G8:bkE9/C615o9Rs5GrbPpZ81mG8
Yara None matched
VirusTotal Search for analysis
Name a19bd35eba154030_241.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\241.WNCRYT
Size 3.7KB
Type C source, ASCII text, with CRLF line terminators
MD5 90d0111642e4d5ff9ec8fca6d4231cef
SHA1 eb9738ddb2fcbae1161fb61121cc864309d1c693
SHA256 a19bd35eba1540301bb9d5154404b411c760f09aec8333ece59a184e8572a1ec
CRC32 EA0C9707
ssdeep 96:R2yDLpgth6w4mijFg3jujm2aZsa1s15ss:R2LtIw4K7Zsaqks
Yara None matched
VirusTotal Search for analysis
Name 85e6406853b7553a_443.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\443.WNCRYT
Size 2.3KB
Type GIF image data, version 89a, 160 x 160
MD5 45027f5e38f6c72525027855ff121a2c
SHA1 d3b9889552421236b8e1d06b0c0a43c96c2ad156
SHA256 85e6406853b7553a281e5ac280897392f70b2405939b25075acad9fe33a4adba
CRC32 7D6B279E
ssdeep 48:3HE/iyT3M+dD60URXk+ARPn5D+yzfCro/Ay66QU4BEZG/:3QiyT3zD60uhQZgUp6U4ByG/
Yara None matched
VirusTotal Search for analysis
Name fc11c3d934f8de7d_542.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\542.WNCRYT
Size 96.0B
Type GIF image data, version 89a, 11 x 11
MD5 7154ea5eb2b1da2f3e306c6f843a5297
SHA1 3a2f873178cf50ca656b1089347c9ce2a492dcdb
SHA256 fc11c3d934f8de7d3285f616d0a9129f8113b158157501829c2e452101d067a4
CRC32 CF66E280
ssdeep 3:Coa5t1p/lfln4Z1Ot0plqBbF7Yht5z8ZA:bgtfSZkt0WtF6q+
Yara None matched
VirusTotal Search for analysis
Name 1b06651d92b113ac_59.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\59.WNCRYT
Size 10.4KB
Type ASCII text, with CRLF line terminators
MD5 2eec2fb4fa2e8cc29620e20e377d2496
SHA1 99cae680c8e2a59444d0cb940a126957cd60ef40
SHA256 1b06651d92b113ac0482f118e5dc6860e370cd2b2478141bc8a7d686930b7730
CRC32 A95DDFBE
ssdeep 192:4c/buKiDnJR0civDlNmSY0OUiVgs9ZWZy/nW:ryKibJuLvD3ZiVgsrax
Yara None matched
VirusTotal Search for analysis
Name 8aa19482c048d562_usertile32.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 98f0a86e707d7f9b73d472645866c670
SHA1 63012735ea0def7b482f35386fda42017c0e4353
SHA256 8aa19482c048d56203990b27665a2e9ae20021f0937b416496c294191c7109b7
CRC32 FC42AF24
ssdeep 1536:Z7k/TNVoPql9rROkK7QUszL5ZIdyttdt9Mn7:ZgNCPqvrB/t5ZKWft9Mn7
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name ed4908c098e8e17e_ar_lb.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ar_lb.msg.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8f2ff1d89b30e512d569bb45a7fb5906
SHA1 4866b41774de4212411203b47dc6813ca54c38a0
SHA256 ed4908c098e8e17e77013e599ae63c33e2be2dd7678c1bb2268413ad091a9598
CRC32 C8A810BF
ssdeep 48:bk9QMvn7K3otjgTpcHIgqR55UBxoMWCpI8cPMSVCZGzwg8oM:o9QMvn7FiFcHPq/5UBSMW6I5MSVCoMgG
Yara None matched
VirusTotal Search for analysis
Name 2dbcc70f2991ab9e_en.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\demos\en.msg.wncry
Size 4.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1ccfaeaf44d2f10dce4d5698b94ad320
SHA1 dbecb8f30022cc5da2eafeb3c83cfd5f46421378
SHA256 2dbcc70f2991ab9ef36bf643b31e1de32460806b42713b3316ad2790e26d281f
CRC32 98CB0013
ssdeep 96:okKZq5igq6xyNta14bQcJcqkktRi44BJYwZ9+gkH1Y4Q8AB4p8:dKkoa14bQUQktRi44Mw6gG1Yp7B4O
Yara None matched
VirusTotal Search for analysis
Name da3ac219a59a00aa_bytearrayobject.h.wncry
Submit file
Filepath c:\python27\include\bytearrayobject.h.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 648065bd18b44de4f6e8a9bb8961877c
SHA1 5a4a651390fbc86ad65b004b5bb960a430eb133a
SHA256 da3ac219a59a00aa97c44fae67a23d532e4000ac153919a4bc006e0a2b6f75fc
CRC32 619854F8
ssdeep 48:bkAIaiiUPqDsp61VMpH+Y4/APJRUCaqVZW9oOrE:oAIaiiUMi6DjDYb3lO4
Yara None matched
VirusTotal Search for analysis
Name 935164a2d2d14815_658.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\658.WNCRYT
Size 287.0B
Type ASCII text
MD5 d20788793e6cc1cd07b3afd2aa135cb6
SHA1 3503fcb9490261ba947e89d5494998cebb157223
SHA256 935164a2d2d14815906b438562889b31139519b3a8e8db3d2ac152a77ec591dc
CRC32 FFDB8D65
ssdeep 6:SlSyEtJLlpuoo6dmoszFnJF+l6VALoszw3vG5oszw3v6X5osz++3v/R3v:4EnLzu8gL+l6Vt3vf3v6P3vZf
Yara None matched
VirusTotal Search for analysis
Name 313e8cdbbc0288ae_128.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\128.WNCRYT
Size 2.0KB
Type ASCII text
MD5 5ca16d93718aaa813ade746440cf5ce6
SHA1 a142733052b87ca510b8945256399ce9f873794c
SHA256 313e8cdbbc0288aed922b9927a7331d0faa2e451d4174b1f5b76c5c9faec8f9b
CRC32 A5F4D486
ssdeep 48:46qoQCSdQqQP4QSsIVKP10NupiuQxQaQLlKnM28nGtfR:hjIX15VKP6NmBU3YKnFbp
Yara None matched
VirusTotal Search for analysis
Name b09bdd2aa68fa1c4_msg_12.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_12.txt.wncry
Size 968.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 302a339c0bd3f6cf1767327e1eb24963
SHA1 d8839c83336752e5eb6eb3552d6865f4bfcd78a3
SHA256 b09bdd2aa68fa1c487918ce5d9586e1d1366e33493506ade80c5d69297f5f9c1
CRC32 5FB53CF5
ssdeep 24:bkXrfjZ1qgPObKAfVAHoc9xZHt6fnU/dA40qvjQqogX:bk7fjqRKAf+xNtx2q7Xo4
Yara None matched
VirusTotal Search for analysis
Name d14279edd935ae8f_dependency_links.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pygetwindow-0.0.8-py2.7.egg-info\dependency_links.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 40f215d61ee4713b437521e05ea7a457
SHA1 e53a1f28966d69042323e885d63562fb8cd5c7e9
SHA256 d14279edd935ae8fc017c729c62bd5c5564c7d45ec6d2b95813c17314b8ea5f9
CRC32 A1983BED
ssdeep 6:bkEBC1RQlJbQ+v4z75NOU2FwH7gDfjGrCG74bByQEgmuh/+lXEU1XIV:bkEoDGJ3Y53HCfjG+G7qQgm8/+lXEU1u
Yara None matched
VirusTotal Search for analysis
Name 979e2ae3b4f4caad_608.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\608.WNCRYT
Size 769.0B
Type Non-ISO extended-ASCII text, with CRLF line terminators
MD5 233c704a7890fdf622e182d8671ae48b
SHA1 90cd8a00b607e5637c5cd09d48d8efaa0dda981b
SHA256 979e2ae3b4f4caade6aa430c449630f19dcb4ae413da6b85a83b504812b2f941
CRC32 ED672870
ssdeep 24:tY7R+nr78+DYKqhR2Nl7nMTjYN4vcDnuccPGwIbWpvy:t++r7qZ2Nl7nEkDnuBPGwIbCvy
Yara None matched
VirusTotal Search for analysis
Name 1906a1179872ef7b_258.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\258.WNCRYT
Size 1.1KB
Type C source, ASCII text, with CRLF line terminators
MD5 2ae2fd73e1967fa0cdc8c618aeb213a2
SHA1 9ed88f39f57eba7e1e05687cd08c54764124d9e7
SHA256 1906a1179872ef7bf1ef20ae689d5226bc160f0481c02dd2d152802583bdae51
CRC32 81218901
ssdeep 24:3UkAXrqhbpEBrpu4DRmO832GwvGBOpPOBIX0iQ9Gq49:cbq/Wrpu4DRm532FvZJX0+
Yara None matched
VirusTotal Search for analysis
Name 2ec77fcaf57682b2_52.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\52.WNCRYT
Size 2.0KB
Type RFC 822 mail, ASCII text, with CRLF line terminators
MD5 43d49fe7f454b9ffdc1470f2703e1c7c
SHA1 06c592765b62105ca0de42e4fc9dc891655fa14d
SHA256 2ec77fcaf57682b2b8aee8c678c999f197456534d0b1d1d886976dd6794fa6e3
CRC32 B04E58EB
ssdeep 48:4fPE4i5Cr1b04TQc0XkYOw0tzHaVLvUHnsO5Yn:4fPE4iKb0OBqDOdJHaVLvmnA
Yara None matched
VirusTotal Search for analysis
Name f3e6c3be7d6bb12a_431.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\431.WNCRYT
Size 2.2KB
Type ASCII text, with very long lines
MD5 07d9894330b66fcb01940b7a4053e3c9
SHA1 b263eb014ebc2ca7d244434f180ccd6bff4ce2fb
SHA256 f3e6c3be7d6bb12a5e35fcf13b9796e8490af075fedb0db989f9f2ef5eba9593
CRC32 0BD9B077
ssdeep 48:p3qZTRSt0RqyR98vZjrElD6Dq2HWho0LTAW8krxb:xCdSGqyRwPOdoqTooxb
Yara None matched
VirusTotal Search for analysis
Name 0c17decc481a39df_28.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\28.WNCRYT
Size 82.5KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 4771ffc935be7cd9ab6758fb71bde0c2
SHA1 f2cde24fb9ed0c20d409ad2c4e5abcf237a7ef35
SHA256 0c17decc481a39df66488ec3d734610f2074aec70157b4f6ef801f5d9e77490c
CRC32 19AD1E03
ssdeep 1536:mfj0TJYmyEGtFSl4uMYt5URZtdgcf2Ma9uCPU++bfIpyCXR81wwrXDxbOEsi:mQqmyPXXuMYt5U1dgcf2Ma9uIUEpyCiN
Yara None matched
VirusTotal Search for analysis
Name f276867ecc865d44_es_ni.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_ni.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 c628190c455cf76699bc2337150af436
SHA1 673c9e71a31eebde174b1b13668517f8188e2d86
SHA256 f276867ecc865d44b09ebbbdb349bb97a5d83cd957fac525aaa472ee7b7e620a
CRC32 92B648C9
ssdeep 12:bkErZvetSGtnHMRYSBI42mRmsxjUWgImnaIYiZIqrZ:bkAZvQSsG7BI4vxjUW8aIdV
Yara None matched
VirusTotal Search for analysis
Name a7cd959ba98df559_dependency_links.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyperclip-1.8.0-py2.7.egg-info\dependency_links.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 3d06ea15e9e51b4c50379f5578cf46d1
SHA1 9657f050e3dcbcf55ca8b7f9f043068a60ba548a
SHA256 a7cd959ba98df559d5bb94f2d90a4ede489bca4aac3579f5a835467812b20ba6
CRC32 5BCCB3FA
ssdeep 6:bkEw1cYkBHF2L9y5O1JaU7coFNmgCqsntw//8E15d:bkEwKYOMMWfg+NfCXwH8E17
Yara None matched
VirusTotal Search for analysis
Name 8fb74b81159b653d_ieee754.txt.wncry
Submit file
Filepath c:\python27\lib\test\ieee754.txt.wncry
Size 3.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2c5b7375008367b61c0ce95a243f746f
SHA1 8bf6e05d46aa20257d6cb19a7570d377f6c1f337
SHA256 8fb74b81159b653d3b28fcee086a5f5154fc3390f3bc65a062892b724654f65d
CRC32 56EFDB82
ssdeep 96:oqkimu8Xqp3TOfuOPs5os/Gvp53l+GlTrnSV0MIQb/:O5C3TPOPYHi9ns9IG/
Yara None matched
VirusTotal Search for analysis
Name 8edd4f8b6cd2ed28_sk.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\sk.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c0351610031dd82bf251f56be26d1e15
SHA1 29863a66affdba7de3a53bd22aa723b81d21a7b1
SHA256 8edd4f8b6cd2ed280490acd63e4716c67ca00d639acbc802e0c90d88b2154373
CRC32 F72F5DBB
ssdeep 24:bkC72MdYU3Lj3+rvYn8sXQpuMz7BHswyAJ6EURGDG9yH3XmL3XJSJUxPF4:bkrMdYMf++IIMtswyAgEiGDGIHHicCP+
Yara None matched
VirusTotal Search for analysis
Name 4b8050fd3af4661c_252.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\252.WNCRYT
Size 2.8KB
Type C source, ASCII text, with CRLF line terminators
MD5 9149b19534256e6dc2f186db5231fecf
SHA1 9664b36753ba2351b44682e3276b763282f49c51
SHA256 4b8050fd3af4661c1a0aa9923cdfe209f9c0b1872e3ee5f7a20aab35f70ad531
CRC32 952C7ACC
ssdeep 48:IfCZreIsoNJj6crjNGShev5JLE8BqUPG5esZ:IYrefVcrjNGS+fNG5
Yara None matched
VirusTotal Search for analysis
Name 96f96d7cefbb2923_thumbcache_1024.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows\explorer\thumbcache_1024.db.wncry
Size 312.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 d96adc173de4097596e8b381b549558f
SHA1 b47e4b955c48e461813681c93a35121debe59a58
SHA256 96f96d7cefbb292325ba9817f0d2ff287257a3c531f442d9b1dada13d2df24fa
CRC32 FC6875FA
ssdeep 6:bkE90OON43SGKyNLTeTYrY0+xCWi8QXOUcqAW6146Cl536ZSvR2:bkEONaKaLBnYCTeIAB1W3M
Yara None matched
VirusTotal Search for analysis
Name a044f48c4e71eb13_sources.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyrect-0.1.4-py2.7.egg-info\sources.txt.wncry
Size 584.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b6630bbd439a68814d2accb8e746ed4f
SHA1 447ebd6708ad4899549ab4b1e76ce8e58b45e1dd
SHA256 a044f48c4e71eb13bb3e992b0c5096cf34a98b03d9a566e85dff341a53fb1d3d
CRC32 8FF87A3A
ssdeep 12:bkEz3NH2UunXp/3i8hA49HesiygL78UTdPfTPk5NR0yuh5gl8uGYU:bkw3k1i8hAsidlPfo+ol8uNU
Yara None matched
VirusTotal Search for analysis
Name 5721a4b3f8e09c86_418.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\418.WNCRYT
Size 255.2KB
Type ASCII text, with very long lines
MD5 1709b6f00a136241185161aa3df46a06
SHA1 33da7d262ffed1a5c2d85b7390e9dbc830cbe494
SHA256 5721a4b3f8e09c869a629effd350b51c9d46f0ac136717d4db6265c0ee6f9ac8
CRC32 ED29153F
ssdeep 3072:I5vU7I6s2M9duIWFCbmYJ4tnFWdqpMad2vywhIp81QFv9F9nNsZgiDdOFlV/mZmc:I5vqFCb2p8Gx9FNNsZ9Dd/ceR
Yara
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis
Name 6db650836d64350b_m_turkish.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_turkish.wnry
Size 41.6KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 531ba6b1a5460fc9446946f91cc8c94b
SHA1 cc56978681bd546fd82d87926b5d9905c92a5803
SHA256 6db650836d64350bbde2ab324407b8e474fc041098c41ecac6fd77d632a36415
CRC32 DCB074FB
ssdeep 384:SheftipUENLFsPzy3EFHjHds42WG2mzGu/eo75Y3kmA31dv61QyZ:Shef3jHdsiG2moZrS149
Yara None matched
VirusTotal Search for analysis
Name f38fe31a3034abaf_msg_26.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_26.txt.wncry
Size 2.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5a9ddad869be08abfa8a962780f2ed6b
SHA1 541384e2f4b510114fa9c9e93a5a1c26cf4d66c9
SHA256 f38fe31a3034abaf06dc9cb7d265a70b01d78863983f0fc32739ac09ff5353a1
CRC32 A4C56CC3
ssdeep 48:bkZg3TYR0Nw6WjbodKgQa7B7Vp8hoN0bp/hsn+S8oyWCFXQ64WVG1yVbriLj:oZgDDw6UaKha7Bm7pY+vq1FWVLb2n
Yara None matched
VirusTotal Search for analysis
Name 8a58fadc6994875d_32.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\32.WNCRYT
Size 86.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 cee1da6296153fb1817e761e5067312a
SHA1 88acd542e9cc46ec4bd6b4cd125ea77a437da0ab
SHA256 8a58fadc6994875d4266c996f6572ea3dd014c4dc003929b1ab0dbbef85a92de
CRC32 2C86F64C
ssdeep 1536:jVOde9K5Z9/MyTHqzW6JkcOJwDwsf/qy0e+VfTqCIJ2F0W69+xafr7JMpwEKqnWf:jVse9K5Z9U2Ka6JkLJGVf/qIiTqHpHvx
Yara None matched
VirusTotal Search for analysis
Name 038e40bc55d8e881_532.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\532.WNCRYT
Size 231.0B
Type multipart/mixed; boundary=ABCDE, ASCII text, with CRLF line terminators
MD5 f8db6d0f5bdbf3bdeb8f6168fa178bda
SHA1 a7264a4ed2ec79289ab1db7ce10a8236bfaeab00
SHA256 038e40bc55d8e881776bc04d5e187d13c58535b80efd7a0dd6584013f90d8998
CRC32 C145281E
ssdeep 6:/eQ67JPwQ8G07/KXoWwQ8KxXoWoWoWwQ8KxXT:/eQfQJ0zKYtQfYFFtQfj
Yara None matched
VirusTotal Search for analysis
Name f120cb4f7f753941_usertile15.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 5bbeef2274e18d8837659aff869d8f05
SHA1 203f71f7353bca2b6f6802acfe7c7f39c1be4a48
SHA256 f120cb4f7f7539412edf4e4c4fca3b5666e2dfb3196e8460584fd6c9a073265b
CRC32 AC6B65F1
ssdeep 768:R3InSqCq+SC93WUuYcf7JJJJJJJ7B9JJGkJsmJLCvPTT5vGYYR5ifKZEW1fKZh:R3IxCPSC9FuLC3TTgLXMKmW9KT
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name bd7c645fe42ffbca_et.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\et.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 441d12f6d295e553d98c64cbc23b7a8b
SHA1 e81697a500e103d7fadd79ad27aa3cc9e4e5300c
SHA256 bd7c645fe42ffbca1cf0d9a51c205ea86e55e6405bddcf82e190906ab65cc498
CRC32 B5794BAC
ssdeep 24:bkF2kZ5Ic9JYyFBFORk5ogKz/DnAoviPKg9HI3Caku+p+6Lkl0sT57TLnQ:bkMkZ5IKW8OAoPMaZg9HZe+pXC7Q
Yara None matched
VirusTotal Search for analysis
Name 4ca238a51277a101_sources.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pygetwindow-0.0.8-py2.7.egg-info\sources.txt.wncry
Size 760.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 79f85d9f1d4b06cb46f8f0e9f6176ed8
SHA1 eaaecfb46c90ea323e45a716aca6d8283edaabcb
SHA256 4ca238a51277a101857c1595bc3c4ef01680e6bc3cee95a5b8a342d940411825
CRC32 8ED70326
ssdeep 12:bkEW+ZacT4j71D28Kmankb+OEsKeyXlTmWJ7DdMg0WKj++DCrhOqcj++R:bk274j88KmakgTXlTmsXKWrhwio
Yara None matched
VirusTotal Search for analysis
Name 9a4f25a107680d52_pycacert.pem.wncry
Submit file
Filepath c:\python27\lib\test\pycacert.pem.wncry
Size 5.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a4c5084f9caff6674c332b737740291b
SHA1 14a3eaa5cb8a55830e865ad16e6754994194cc68
SHA256 9a4f25a107680d5277836ecd283d104e7621b7eaa0df1d207ab729a21004ef4a
CRC32 5B2AE143
ssdeep 96:o31d01b3niFNRGknlcKpFOZOG7VUSRoVa+yIugzyBOYlZbOSUDavMBaJCDyhUqRk:y01LnCRGqW456V57JBH1v3xMOVpk9
Yara None matched
VirusTotal Search for analysis
Name 2687470b93947adb_databases.db.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\current\appdata\local\google\chrome\user data\default\databases\databases.db.wncry
Size 28.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 52513451a886322be7f174e5edeca23f
SHA1 6cc42eefbfda436e011198724d80fa3bd115e06e
SHA256 2687470b93947adb0fb9ba3daf7bbc276489c41270efa15759aa2bfab1016bfe
CRC32 DAC05452
ssdeep 768:povFOgQg+VGKBCKpC19IR2j8FaccTOi95Ywbzfa:py46UCwYGxo92wvy
Yara None matched
VirusTotal Search for analysis
Name 1ad2fbc604ec6011_694.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\694.WNCRYT
Size 76.0B
Type GIF image data, version 89a, 12 x 12
MD5 da15e983b22bf485bfc7249b1e94f0e3
SHA1 fc544e677a383869f742c15ed1b32bf6ff9f0502
SHA256 1ad2fbc604ec60116849574bc4dc371f8cb5796e14571ea2684c8bab99b4c467
CRC32 CD07AA46
ssdeep 3:CkklR/KwltxlkpWerkTND2YPi:HsR/q7kZi
Yara None matched
VirusTotal Search for analysis
Name 253c7a9d29681b94_import.h.wncry
Submit file
Filepath c:\python27\include\import.h.wncry
Size 2.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f23d17b33a409bf8f0446e8faae36c68
SHA1 2dd4caf98260c71832dc8e703832339c4930110a
SHA256 253c7a9d29681b94ea1d27e2a2962590ddd2d8dc86fb3653eaac5f8f9dd947fd
CRC32 7D6D3851
ssdeep 48:bkhj4qeR/a3pUKyLamlh4wB2AHbdTw15Hux13rAa1kckxTE05+B1fG4S4Kg8Y:ooR/yCPHfltrX/kaQ+PfGlCv
Yara None matched
VirusTotal Search for analysis
Name 0193e91725a57892_474.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\474.WNCRYT
Size 470.0B
Type PNG image data, 34 x 18, 8-bit/color RGBA, non-interlaced
MD5 6c80ad0b2563fb2997441241acea15c8
SHA1 b1cdfd646b339c53f6e0d672295bb6b93053dc09
SHA256 0193e91725a57892de14f62c75658193ec0950f3e2d2fcca33fce7bbf8bbe0e7
CRC32 D06B357E
ssdeep 12:6v/7N8/+LyExlXfN9Xe9bp6Dzn9F5GGkndxMYyEvw/xdO:WVXVFea1F57kjM3/jO
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name ae266aae4fa1c99a_554.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\554.WNCRYT
Size 4.0B
Type ASCII text
MD5 d851573b415fac5c5ec32f7150727932
SHA1 7874f2b6a9121fb487328754f5b4c521e2fb7e94
SHA256 ae266aae4fa1c99aa1e5fd59d19c228b774a7f112c07286ef5c53d20e0c5f8d6
CRC32 291B8FE6
ssdeep 3:ev:ev
Yara None matched
VirusTotal Search for analysis
Name 8231fa93f91798d7_gl_es.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\gl_es.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 40c4baa96e66a5828471367d9a5de392
SHA1 19506e5f5335d1aed282ce695079abab519d8f2a
SHA256 8231fa93f91798d7c24f614f7590addc3dd0f0a1635b306de99ea4efab196fe0
CRC32 92A066F1
ssdeep 12:bkEGk71qmKJ8kxMwoGYQn0tGtoiIBM53+/TlVxfSFQh6KE5/gOrObr70:bkcAlbnn0YaKc/Tl7fSFQh6TxgOrObrQ
Yara None matched
VirusTotal Search for analysis
Name 3729faf0fe6f9469_606.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\606.WNCRYT
Size 486.0B
Type UTF-8 Unicode text, with CRLF line terminators
MD5 cf84c3941ad53675f600cb5f82bc2f1c
SHA1 110e009764b04fdda1896bd4a7c1d55373276595
SHA256 3729faf0fe6f9469bca08973c847f669c603f7373ba580c92756bf86b9c8331a
CRC32 A21568D1
ssdeep 12:tOAvNBzSW/8BZWqy2jVEp7Qjj/LCeYGOiz/LQ73zPlp7/Jnocg3ff:tOAvNVSW/8PWqy2iQjDpJLQrzP7tnoc2
Yara None matched
VirusTotal Search for analysis
Name f6bc4dd6c3c096d2_447.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\447.WNCRYT
Size 377.0KB
Type UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5 30c42516fe0dcb032605727ee1cf6bbc
SHA1 bd3327dde7fd34b1484efd4a04dea386cd69895d
SHA256 f6bc4dd6c3c096d27e271a634f41e4bd7fd7f49032190d2ae2d745953ff79041
CRC32 BC98C72C
ssdeep 6144:x1Ke83zsm63zAc8tkbaGuKIbdixoTa3jaw8OENbm:Uom6DEkbNquaw8OWm
Yara None matched
VirusTotal Search for analysis
Name 4a9f8d8cb2a91e3e_white_chocolate.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\white_chocolate.jpg.wncry
Size 3.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d548189cbaa640c0a39b049d848184df
SHA1 d4c331f991f4b2dea3fd4922ed257942ab59eea8
SHA256 4a9f8d8cb2a91e3eac160365b545f4bd48f86b72a6fa55172d86aa73ac3438ae
CRC32 B96B1438
ssdeep 96:o57Fe9MTEx5xEBj7YN5Z6VryRSkVlqWCBo7q:u7Fe9MXPE5Zh/VlYBo7q
Yara None matched
VirusTotal Search for analysis
Name 4ad97f34e64abd93_291.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\291.WNCRYT
Size 1.0KB
Type GIF image data, version 89a, 16 x 16
MD5 79ff1b3fa6b72d81d75f123a650b2151
SHA1 729c99d5af327f1b17021f41b7157c696bf4b2f4
SHA256 4ad97f34e64abd93e1e32aff017ff8914e3204a76044f1486bc9fbefa07bfdbb
CRC32 0FE918FF
ssdeep 24:KCIw7LM4oN+RGrc96op/9kRs4c/fCEzUGfY:KCLHUCsKV9kRVAY/
Yara None matched
VirusTotal Search for analysis
Name 7acaa280ef725ae3_449.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\449.WNCRYT
Size 374.6KB
Type Microsoft Word 2007+
MD5 8b5aee7e0ce7c367e74240bceb5bcc83
SHA1 62af88e2adf8f26d58714fac04805655ae057157
SHA256 7acaa280ef725ae3de71d66d082bb3de372962f718b50a4fa28e190cd5930ed1
CRC32 0363C0BF
ssdeep 6144:pl82xfVaZUt2Km7Jh+u0O7Ss5SP5gqoRFkVupNU5HbhFLn+AYnJ:D8+VamMKicBO7SaSP51SG57LndYnJ
Yara
  • zip_file_format - ZIP file format
  • docx - Word 2007 file format detection
VirusTotal Search for analysis
Name fe43bca3ea915b41_funcobject.h.wncry
Submit file
Filepath c:\python27\include\funcobject.h.wncry
Size 3.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 666e45b5b6ce962569497b0665d7c348
SHA1 61fed179fc57ab58c5638100e8358073ef187901
SHA256 fe43bca3ea915b41c473b4b908ab8b2d9853c8db8eba0228eff95a2abbee7e34
CRC32 54245F6A
ssdeep 96:oJBdPGy7FTkcqoRiso0RO1Kk5k6sKcm6iQP7wnALS:RyFIcvRBo0RiKk5k6sKh6iSIb
Yara None matched
VirusTotal Search for analysis
Name a244ea283bf7dd0e_163.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\163.WNCRYT
Size 12.4KB
Type ISO-8859 text, with CRLF line terminators
MD5 132a18da8d03a8aebef3eb48a82b5f94
SHA1 cba819ebfaca3c7adf9c1b584cf16313360f129d
SHA256 a244ea283bf7dd0e95dc7735419864ef854891e6226ab2ed8bf6cca838c33cb5
CRC32 3A797A71
ssdeep 96:nShqJ65tqVE/YRixahG4Xx+WVMXKBw+CnqnhJKLEu9hGROB+WVrYFKpeZbW5CeFi:c9SotQKPq
Yara None matched
VirusTotal Search for analysis
Name ec354c46a32e6136_template.cpp.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\editplus\template.cpp.wncry
Size 392.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 d99609ca18264802b9b0b0cf611893ac
SHA1 f14b543932c6af6b5ab440a5d5f20da1d96a1655
SHA256 ec354c46a32e6136c390f20dd7387602b8ad0abe803a8702f5c33055b3b97387
CRC32 727AD523
ssdeep 6:bkEneLfBRcLCTxrWa2P8iRA2bAYc2BtMXQd/XhfaMllCVPFgx1CfxyBx:bkEifBRBTNb2JbBtMXQdJfaM/CPVc
Yara None matched
VirusTotal Search for analysis
Name 40a540044034b51a_open1.png.wncry
Submit file
Filepath c:\python27\click\click\click_image\open1.png.wncry
Size 664.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 d827ea22b2b1216442e55cde0f7165a1
SHA1 7b6f98abb33ab5a17543129fa7b1449a68dc75a7
SHA256 40a540044034b51a6130fa7a25b2d2556849e41603325e1b26213fde3783ab39
CRC32 86A66155
ssdeep 12:bkEpaEdZWVTyV+qRb/R9jGmB49sq/1cCH5ul/FwgGcOzKPlsIeLT6olXjh5clD2C:bkdEK+VpRjd49sg15H5ul/egGVKPlsIF
Yara None matched
VirusTotal Search for analysis
Name 89880582d0e56c67_websafe.txt.wncry
Submit file
Filepath c:\python27\tools\pynche\websafe.txt.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d2b51d44fc6dbf873339b3bd585959e3
SHA1 3e19586dac2f5b7ce3ff002d038a76d4f0ad8257
SHA256 89880582d0e56c67af48713c1d732560e958bc3f10ad67b7827f5f24fb2ad154
CRC32 181B49AD
ssdeep 48:bknp06lv4tJPvXm8IKXIIZRxrso3biS1hNzoTdT:oKQ43kYZRx4WoT
Yara None matched
VirusTotal Search for analysis
Name afe336300be33b19_480.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\480.WNCRYT
Size 824.0B
Type C source, ASCII text, with CRLF line terminators
MD5 16256f4e85c05eb15f23b315753bf9b2
SHA1 17ee527dced24948ee0adea6fea2ffe8c6a38be1
SHA256 afe336300be33b19834b6707cee64e236e6110ca1a99793fab736acfa9d1cc38
CRC32 D621A5CE
ssdeep 12:mRrlAB0YWy6FaDxE3e/LYrMTUM1wzMnNko4Hoeg75DEO+g3zggBYguNgY1oGAYMa:Khw1E3ezrQwwzkkvHC1nHBOVRj
Yara None matched
VirusTotal Search for analysis
Name 84f6d2498aa14387_151.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\151.WNCRYT
Size 3.9KB
Type ASCII text
MD5 e28545f6a7b22ec237ae53c8f12a83c8
SHA1 0bf3a4827b93d63934a099f935a484b9e101168e
SHA256 84f6d2498aa1438706bd9665918754275be7fa0099cfb8a8601ae1f79915c6f0
CRC32 56EC5325
ssdeep 48:mYkv1H+BBv5vVXnjB+y7oBUHHE3XQrDool2EQdWa0ybBhKG:zsH+3vLNnZHHE3XjoFYhL
Yara None matched
VirusTotal Search for analysis
Name 314f4180c05de4a4_107.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\107.WNCRYT
Size 1.3KB
Type ASCII text
MD5 0561e62941f6ed8965dfc4e2b424e028
SHA1 c622b21c0dba83f943fbd10c746e5fabe20235b2
SHA256 314f4180c05de4a4860f65af6460900fff77f12c08edd728f68ca0065126b9ae
CRC32 3C57CB41
ssdeep 24:4azu8Xjv5ZemNruwcVNtZHTE9wocxPvt9vq:46fBZemNqwIZHTEE3t5q
Yara None matched
VirusTotal Search for analysis
Name 67401dd26aee42ce_state
Submit file
Filepath C:\Users\test22\AppData\Roaming\tor\state
Size 742.0B
Type ASCII text, with CRLF line terminators
MD5 4e942147f1b01255b359465992f6811c
SHA1 3d9ce517881449275e1e65209496f74fcabdaf3f
SHA256 67401dd26aee42cec4f5ee5e2d210e2706747f734f712036e0365ef13bf99b16
CRC32 11B417C9
ssdeep 12:bwxXYrXr87HVBvwN6F1nFczN0JX1nF0YPvmHPe2y9EwEWEzEV9/R2Utv:bwRMQ7HVBfvcuJXvbuveX93VYu9/R3d
Yara None matched
VirusTotal Search for analysis
Name 802304af89c305a0_315.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\315.WNCRYT
Size 19.5KB
Type RIFF (little-endian) data, WAVE audio, Microsoft PCM, 24 bit, stereo 11025 Hz
MD5 95fa93fe473ea60cdde314dc9725730f
SHA1 74d45d5bae9cb915f853d2fd0fce956ed7cceb1a
SHA256 802304af89c305a0d5feb8bf6ba9c7b3abfb6d5e620ba6d4f4d69277ef315e22
CRC32 5E9D8AC0
ssdeep 384:sTGvh4oHhaK1M/n3fDrMksyE6MTRE5C5nS1USsZkdzAe:EeqoHwK2rrMf6F5undUEe
Yara None matched
VirusTotal Search for analysis
Name 77f0dafbb5f27578_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pymsgbox-1.0.8.dist-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 9eb4ba2b6a1fff0af436c04d659bb72c
SHA1 c0140e36c5c0cae67d5f2d5df90041988ece13c9
SHA256 77f0dafbb5f27578b3e08fffdbf5bd1895c8bb6bb40c035220f0a6596b2e3e44
CRC32 24FA03C2
ssdeep 6:bkEJCAsZyXvXjNwxjEmWDhgNXqHEEqE8m8y029+nLeWxUFPrshXja:bkEdsZITqxJ2hg8jqVvy0HUFPuXe
Yara None matched
VirusTotal Search for analysis
Name f5d2c183dfd2846f_es_pr.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_pr.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 438ac9effe99ce97561657fe29986af7
SHA1 458a41a92fdf4119bcbd9c48f82a4ed13dfbcbd0
SHA256 f5d2c183dfd2846f9f66fd8d6bfc1a45d07183ded3a4691a37cde33181273cdf
CRC32 8F60F375
ssdeep 12:bkEMm6jAWmSFhYa5NWltYxR65ixLX15H9C/1jJjmIEngcerLR2M3:bkLPmOmQR68FDdSvmIUBNM3
Yara None matched
VirusTotal Search for analysis
Name 8248a50f4629e8e6_parsetok.h.wncry
Submit file
Filepath c:\python27\include\parsetok.h.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 455a4bb68e96bffbca446009317063e5
SHA1 b5cc00c9ccf1b5a3480b6dcadac51c4538fbc34b
SHA256 8248a50f4629e8e6cbf460415088165e4b24e1861c81241ac845e66cf5339b04
CRC32 7997BCBA
ssdeep 48:bkt04uPjgh9JVE8dS6Roac7qgW/k96h8wZJpiU:otZu7MV+66nVWLPtT
Yara None matched
VirusTotal Search for analysis
Name 99ea9bdc0292fbac_tm02807606[[fn=팩스 표지(점 테마)]].dotx.wncry
Submit file
Size 19.2KB
Type data
MD5 54345bf818cfb7279fe24e8a864e33ea
SHA1 ca9065373aa40ebf45035348f080fba3efb7ff7c
SHA256 99ea9bdc0292fbac61a24520ddeb4841c7a4069f6aa8f3be46f0dbbe29dde253
CRC32 A7B77CB4
ssdeep 384:7o/6CmbsDjSreucN3FA9K2alXQmZGkHX44deVUa7KEhb3jbb:7oiCmsDGeucRFJZxckGVUal3
Yara None matched
VirusTotal Search for analysis
Name d430b10e6a19439c_te.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\te.msg.wncry
Size 2.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2b6ed405fa4a8ba595f6d38f48e0d352
SHA1 854b8808562894e9290e069a8e0c95d638b79bd0
SHA256 d430b10e6a19439ce100d8fe81ba71c4fb0d49f803a34850973a598a58e9d900
CRC32 92F76B1B
ssdeep 48:bkzRjflaiTHdVx7P+hXunmpyOrLupEluOCQAUWlETz555:oFjflfDdVx7P/nmpyELe+RCoWlEl
Yara None matched
VirusTotal Search for analysis
Name 7c970efeb55c5375_84.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\84.WNCRYT
Size 1.8KB
Type ASCII text
MD5 3789e03cf926d4f12afd30fc7229b78d
SHA1 aef38aab736e5434295c72c14f38033aafe6ef15
SHA256 7c970efeb55c53758143df42cc452a3632f805487ca69db57e37c1f478a7571b
CRC32 81345548
ssdeep 24:4azu865Fehk+wR+9Gb+Oa+UXP+wR+9Gb+Oa+UD:46nhCNbadNbQ
Yara None matched
VirusTotal Search for analysis
Name 77948952254c8a19_penguins.jpg.wncry
Submit file
Filepath c:\users\public\pictures\sample pictures\penguins.jpg.wncry
Size 759.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 552a33016cbf78cce41c1604d6c18fcf
SHA1 97eb92f8243ee0fe0aac7081ec00c61f12bf0f1e
SHA256 77948952254c8a19a19ff4017604919bdedd23a7c7f9da73c343fc28d9b4cc75
CRC32 7CC9B658
ssdeep 12288:BgY3sedeSoN5kZszP7mm39DbDGzTM+VLaotPpeckJu0YKlshnbfK3lcXWAz/YoBz:JoIWP7vBb6HMkaoBp/auWahnegWAz/DN
Yara None matched
VirusTotal Search for analysis
Name ada87d92704c73d1_python.gif.wncry
Submit file
Filepath c:\python27\lib\test\imghdrdata\python.gif.wncry
Size 904.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a6bb30f640192be3f9c7f151aaf7930c
SHA1 412f4e6617713aae6659ac8f3b55390418e13faa
SHA256 ada87d92704c73d152fcf06c55e0e36112c59f84ded1076a575195b2ce057dce
CRC32 3F75D018
ssdeep 24:bk5WxCfgffua3TEDDp0U6xlS/biGqey5baoVvm6z:bk5YCofmaoDt0U6x1Sy5baoVvm6z
Yara None matched
VirusTotal Search for analysis
Name 8a48175000db42b4_407.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\407.WNCRYT
Size 3.3KB
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 d18b2dca8042dc7e6d91ad7d356ed3e1
SHA1 5868635fb3ded80290c4a9f3c2b3640206405ade
SHA256 8a48175000db42b4926cf1ce26b8df981d55c6e889f91264b7f1b2ec544f0bd6
CRC32 F7B8BCEE
ssdeep 96:IlYa2KzpOd/zPjKUyZO/VBJiYtRMgoVI8CzGf5eib01:IiahMlydkVBJiYt7oOSf5et1
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name f4f52d61a6e91f09_283.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\283.WNCRYT
Size 1.7KB
Type C source, ASCII text, with CRLF line terminators
MD5 680164b0809b5831c753af4fdf754a8c
SHA1 66997b8550ca4b1615c000ab873407da72b0daa3
SHA256 f4f52d61a6e91f09ad3c4ee97a769bfb6b281e66593a99c0754ace382a76bcc8
CRC32 DBD24390
ssdeep 24:KknEi0pMRrSmDczMSkmEAwMUtxIL0NAw091faAphvDyQVqi0h/Y1X+LN:K2TTR2znlKMUr20NX09RDpdwWZAN
Yara None matched
VirusTotal Search for analysis
Name 5dd74532cbb73f8c_284.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\284.WNCRYT
Size 7.9KB
Type C source, ASCII text, with CRLF line terminators
MD5 05d5ad0952ba133d534e15f8bbf2ff2f
SHA1 7401a5190f49f5d3550f761503b9889aaf9410e9
SHA256 5dd74532cbb73f8ce6356cc496fa3d6d9e455df802e5cef0147e340659e15ba6
CRC32 6017E830
ssdeep 96:FQ2/My+KQ+dH0mV10P3+w2WchWNGpN7dNi9NDcXI/f/Y/L77L7NkH0:u2/fpWD2WEj+fcY/f/Y/rw0
Yara None matched
VirusTotal Search for analysis
Name 0bb574bb3b72a3fe_506.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\506.WNCRYT
Size 998.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 d10841e022ccc47ec8b5ba79e5f16418
SHA1 8a4868f7fbe63313328b580c0a31647aa02dc718
SHA256 0bb574bb3b72a3fed8c2331c49cc0ed847a3e394bf7fca3b6de09b4467751211
CRC32 38CA6753
ssdeep 24:SENirrL4J/+LbXmCjrOcUl8RgXbg4ANWGy+WGy+9:SqKrcJ/+LKC27ORScTNWGy+WGy+9
Yara None matched
VirusTotal Search for analysis
Name 9fb6891adc3ce647_597.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\597.WNCRYT
Size 34.0B
Type UTF-8 Unicode text, with CRLF line terminators
MD5 0b7ac83afb191bb5b287a26008baa1e9
SHA1 f0af160611048a05cd8a20daea49fab9b1715ce2
SHA256 9fb6891adc3ce647c7f7b3e187a56580b18224c18c233ec1e57d624ca2d02275
CRC32 A231AFD2
ssdeep 3:Ztvvphrln:Xvvjl
Yara None matched
VirusTotal Search for analysis
Name 428675f94ed7bf0d_308.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\308.WNCRYT
Size 2.1KB
Type PEM certificate
MD5 a07e22d97352195c0581e27b0ec8bc1a
SHA1 84ce8066256e0202281ee1f6822ec5d667c51f6b
SHA256 428675f94ed7bf0d6b726b12fd2f472fc6da6b17d8e1295f39b6cd13c1d31858
CRC32 3054A564
ssdeep 48:Lr+4hkTav3vHD0UmkwVfqWH7QQ4GVoOMIU:Lr+AkGoukiWH7QQ4GVoOU
Yara None matched
VirusTotal Search for analysis
Name d4cec51eea91c62d_560.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\560.WNCRYT
Size 267.0B
Type ASCII text
MD5 b0f61bb2703ae650d55fcf52daaa88c0
SHA1 5ad41d7ccacb8de0c46111f3f762256ab9f157ed
SHA256 d4cec51eea91c62db121de1ae0f8b77ba2a4e8ecc02470e9a0c76bf109c706fd
CRC32 C01845A3
ssdeep 6:iKoY8lRV9gni/tfUFdc3MX87H+Bk3MX8tiG:H8f6iZkdccIeBkcciG
Yara None matched
VirusTotal Search for analysis
Name 85f91cf6e316774a_689.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\689.WNCRYT
Size 312.0B
Type ASCII text
MD5 eb94b41551eaaffa5df4f406c7aca3a4
SHA1 b0553108bde43aa7ed362e2bffaf1abca1567491
SHA256 85f91cf6e316774aa5d0c1eca85c88e591fd537165bb79929c5e6a1ca99e56c8
CRC32 2EF369C6
ssdeep 6:SlSyEtJLlpuoo6dmoX5HoHJ+3vtfNrFLoHJ+3v6MY+oXa+3vYq9:4EnLzu8d5eJ+3vtNEJ+3v6L1L3vYq9
Yara None matched
VirusTotal Search for analysis
Name f8d4bbef63d6262f_ta_in.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ta_in.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 599532b10fd9e4a62501a080be3378df
SHA1 2116c8faba9064ef5b933883877a52657a2cd629
SHA256 f8d4bbef63d6262fe7ed4bca2c77d1209a6f3ea5a483de46c2fbb02884bf7d92
CRC32 C6A54BE2
ssdeep 12:bkEUsEipgZH3ZCsVM1T79/zlqB/i+ePsM/pvkV4AxP25mDBdzx:bkFsx7plqB/i+eZBkV4AxPFDBdd
Yara None matched
VirusTotal Search for analysis
Name 548dabd67ec6dab8_446.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\446.WNCRYT
Size 14.7KB
Type GIF image data, version 89a, 256 x 256
MD5 248a9c3eb8debb6838fc83c597c1b0ff
SHA1 ffd7b1bec0fab5948961185633ac176e66ef0886
SHA256 548dabd67ec6dab82f3cd4e825573d9301d3d1f35ae3045d15afcfa81bd60bc9
CRC32 3FF3001B
ssdeep 384:WMGMxSuIBIxDfif4fp1MaUhPoGcKtkOTzanaD/lEF+YW:W84VBIxDfiQoP9aK/KW
Yara None matched
VirusTotal Search for analysis
Name 6173455b352accdd_748.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\748.WNCRYT
Size 83.0B
Type ASCII text
MD5 a7aa8b00281d2312697012fd666a1a42
SHA1 357ba663237f3b83f9410a7934342211fa60e8ec
SHA256 6173455b352accdd04feb9a369ee44bd0905cd9050bb8b18de4ac27e6e7ffc24
CRC32 28CF35B8
ssdeep 3:WWoAKUu1yK6avQidrQpRoOQIGO3MecX:WUXuSkQ+rGa/tpecX
Yara None matched
VirusTotal Search for analysis
Name 3234b52f5d710532_metagrammar.h.wncry
Submit file
Filepath c:\python27\include\metagrammar.h.wncry
Size 552.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 670016f7031013f028b282342fdd2616
SHA1 6dec2a5bf7404755f730765c07e56d6a3e0a57ad
SHA256 3234b52f5d7105327ee5d90a77b468314fe980e394ef171a9eaeca0ec6e66ecb
CRC32 5556FEE6
ssdeep 12:bkEvxL5HMx9lMQGvY3tSkyGUp/Plk+O8j6+joqZJLjXLGCKr4UyAMkW0sjx:bkcvs/lOY3rVUZPu+O8j6+jV/LbLFKrC
Yara None matched
VirusTotal Search for analysis
Name 5cf44a57f50beb6e_749.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\749.WNCRYT
Size 123.0B
Type ASCII text
MD5 0e33b966501d43b6767e9a0b81549b4a
SHA1 97bee5073e740749edec4aaae4549c9fbb897532
SHA256 5cf44a57f50beb6e202044980feccd6a433a60fe4a025fe4b130dee155935de9
CRC32 4C2F25D4
ssdeep 3:ptz5XHHys1szVEo4DrwS3vJ+wAEXG+Egc9ch/ctVVxjPv:Ys1szVEo4Drn3vIwBG+HCchyVVxD
Yara None matched
VirusTotal Search for analysis
Name 1242e0bf3c88f563_455.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\455.WNCRYT
Size 69.4KB
Type Microsoft Word 2007+
MD5 25c31618e1528877ecdf5c1cf09b2cb5
SHA1 e7b47c81dc8535ab99eb066e53290273b93a891a
SHA256 1242e0bf3c88f56378dbb936b2a55eea986926811375ed5db687cde6fdecc642
CRC32 1A59FB70
ssdeep 1536:pu76/2N1pnLFMOAzhVFIMgUCVpJQnxP0tsSo:pu76/2NXLFMzdVaUQm0CF
Yara
  • zip_file_format - ZIP file format
  • docx - Word 2007 file format detection
VirusTotal Search for analysis
Name fcea17dee8413652_544.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\544.WNCRYT
Size 79.0B
Type GIF image data, version 89a, 11 x 11
MD5 e7e14ab461627886185554e766d31ab6
SHA1 a98a0bac6c8ca1ed5793c5eb540b4a1da2dcec67
SHA256 fcea17dee8413652327d3d1f7565ac6b32b392a5e424947ede2088e276003469
CRC32 1ABE4AE9
ssdeep 3:CABt1/xlfl+oE/NVJsRj89NgrxE:Jjf8VJsF8AlE
Yara None matched
VirusTotal Search for analysis
Name 381e1857f896224f_zymqviojrv.rtf.wncry
Submit file
Filepath c:\users\test22\documents\zymqviojrv.rtf.wncry
Size 257.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 baa0f54f2b8293e569b3fbe9389ed452
SHA1 76d13e58f70348fbab46e101c56f856ead4da9b7
SHA256 381e1857f896224f24e6b55dd62773aeb639f44c9480a616207b13f515b72b6d
CRC32 494F0D0F
ssdeep 6144:P1ODSFXMSdhsDWxTem7xEgG67hjtPptiJffqQ7IdC8vyg0B:tKSZMqhsDWc0xEFSBJLECBCHge
Yara None matched
VirusTotal Search for analysis
Name 2d8e35357600b8fa_de_at.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\de_at.msg.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c4480f4c22e0eb5e0ec5b3800514e59b
SHA1 d2d98dd39e12bf9248e7ee17dc677fb50c74103b
SHA256 2d8e35357600b8fad66c238dde2d69c4f5103ec0fb6c04586c072c6519617e9d
CRC32 ED2FDA08
ssdeep 24:bkJea/sn5TTZrXa2jkDPArloGNQCsql7O6a9MM3wgUre7xiSX6Mu:bk8xV3rloGNQChifOKb8S2Mu
Yara None matched
VirusTotal Search for analysis
Name f9d5d6c76d7af143_146.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\146.WNCRYT
Size 3.8KB
Type ASCII text
MD5 4c1b749ac7182f4f4ae0b1d17356bde0
SHA1 1843d238dec98dec543fe2af8c392cd461dd0a72
SHA256 f9d5d6c76d7af1431c332186cb9fabb2f47a98e8a970265df312222ba6f59c0a
CRC32 A9E24547
ssdeep 48:vTE1U2XR5GiWXirZe0uoH0KQyTaBi2DcDmQ/jY33lEzTCyfv:volXgFHyGB3ELxDH
Yara None matched
VirusTotal Search for analysis
Name 6a4fa892570b4f35_760.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\760.WNCRYT
Size 518.0B
Type ASCII text, with CRLF line terminators
MD5 60a35902480734f4bdbe53fb19b9313d
SHA1 94799bd1b0ebf3f4e1e96ef38c2b1806338b5945
SHA256 6a4fa892570b4f357c3226bdb7eb80590e84517715488c9c580038939cfe9ee5
CRC32 21EE051B
ssdeep 12:T4Lwvf1vVudhY82LDcGuyXkvsUvE+LK5H4ll:T4Lwvf1vWlzHVG2D
Yara None matched
VirusTotal Search for analysis
Name 2314f494863beafa_topbar_floating_button_maximize.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\topbar_floating_button_maximize.png.wncry
Size 456.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 26aaae38fff0f5006e3d428ca114d03d
SHA1 f806b0bdd3196ccc38d6b764bdec5e3c775dc451
SHA256 2314f494863beafadb714838c070fad6b5f3cadeb6864791720d8ad48c50f273
CRC32 00F80068
ssdeep 6:bkEPAes2K/4/L6w6GFJJSP3G5goFb8y3t1flS1yiPlP+MA/L/l0ffrwYTS//:bkEPAes9i16GFC2Hlq3iL/l0ffrpe/
Yara None matched
VirusTotal Search for analysis
Name 9ac0cf3c28e1b2e3_hi.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\hi.msg.wncry
Size 2.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 81423802bf12ca07026ea5f3e6b415de
SHA1 f2ce311b0698d0e7184c2232776f03df7ae4b814
SHA256 9ac0cf3c28e1b2e3b62b20d141063fee327fe01f8ce3cecba19127449a52f206
CRC32 332A1E81
ssdeep 48:bkhKVmtK51aJuZmw0LwM8PJxqUUh+GJr53YaMVkWk1CjL853Z7swwxbgGJ5:ohLK5IuZgLw1PbqUydR5qe0jLi3Vex7n
Yara None matched
VirusTotal Search for analysis
Name 9649b803acac93df_416.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\416.WNCRYT
Size 4.3KB
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 292f836a2638ad64f6f56097dc2ec431
SHA1 e3c39916f1c9f13e338730a80a46b50b1550a557
SHA256 9649b803acac93df7d35c7a8f89aed26739d3aefab2e1031cd6204fe2058be94
CRC32 2D6C0D63
ssdeep 96:p5rVnvl2FaVBec98P4Tq8GCYDo57Op7BTNI4ScA6iDuo:p5rVvgCR9Fq8GRo58lBI4loN
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name b04aca3810194e6c_cast_app_redirect.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\cast_setup\cast_app_redirect.js.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 f3ff320ee86f9103dbc2564fe0eb100e
SHA1 26e233b69018e316122ef5b65c36aa14add496d9
SHA256 b04aca3810194e6c1fa42ba4c9ceeb1bbe9aa1eaa4ebd16c6dff26c99800f724
CRC32 B7371C51
ssdeep 12:bkE9VHNPyhXeBTvRlNMs2sPuYRnY+kHSzx/vNJp:bks9TvRlNMLsWkY+kEJDp
Yara None matched
VirusTotal Search for analysis
Name 3371ae94d24814c5_dependency_links.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\setuptools-41.2.0.dist-info\dependency_links.txt.wncry
Size 520.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 4069bd765d4730b486ea4c44b27c52dc
SHA1 8975255473382289ed59f22f9da0c9b7de13a622
SHA256 3371ae94d24814c54033cbd4efadf2fd7bb9fed31a0006337bce042a47e47879
CRC32 22CDFF90
ssdeep 12:bkEuyxkRXHcpZ+jhj5VhSZkwJCfTBOKe3zctUC/hVzzCin:bk2UN9Kk1OfkR/h1
Yara None matched
VirusTotal Search for analysis
Name 94ffe1f99841fe23_434.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\434.WNCRYT
Size 5.7KB
Type ASCII text, with CRLF line terminators
MD5 89b54f47734d05954938cf069e429e79
SHA1 57b90f90e8cebf9615cf1dd861f437e19bc69388
SHA256 94ffe1f99841fe23f87cfb894a29c24e258ebec562d25f8468c809526ab2b8fc
CRC32 FDE3FDE0
ssdeep 96:aKElJQiL3wkQ+t526r5OfgIMcDOzUAAMcDOG4KCyF:aHlOiL3wkP/Pl4Ia
Yara None matched
VirusTotal Search for analysis
Name b44f711809149d78_61.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\61.WNCRYT
Size 7.9KB
Type ASCII text, with CRLF line terminators
MD5 4a42c32b28e89f8ea05af746ce3a7b2c
SHA1 758ec74f1c9c10a98ff8c7d76b35f2d8a7014a23
SHA256 b44f711809149d78954da0a8c01257554439958be728a2eb60ff51785b781073
CRC32 31C6539C
ssdeep 192:u6CwalsyMy90hmRKpQJgiTLpx6UwEj8rdUe0VMLRXXKLBwY9faB4W1g5/0X:u6CwwsyBmh+KpQJ7TLpxbe0VML8f7l0X
Yara None matched
VirusTotal Search for analysis
Name 1f683e1d3bafde75_sources.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\mouseinfo-0.1.3-py2.7.egg-info\sources.txt.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 d5aa1a0bec82c434ded158a305723b80
SHA1 8572c53be4788cdc6b37e3787a370bc64e551bc0
SHA256 1f683e1d3bafde751dc96c5da2fa52b412b18f30361bb70b3e303c0f256eba68
CRC32 FD54E490
ssdeep 12:bkES0IoMrCzAOyMjOz/hys044U7v2nXowupshBPcOnU3e4v:bkNFoOCzAOPjOlysh4UsgEnD2
Yara None matched
VirusTotal Search for analysis
Name df7c4ba67457cb47_133.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\133.WNCRYT
Size 1.1KB
Type ASCII text
MD5 3afad9ad82a9c8b754e2fe8fc0094bab
SHA1 4ee3e2df86612db314f8d3e7214d7be241aa1a32
SHA256 df7c4ba67457cb47eef0f5ca8e028ff466acdd877a487697dc48ecac7347ac47
CRC32 B240F169
ssdeep 24:4azu80VAFVsNTib5vk5CfYTnGk65GmogWFLNvoKvWI3:46j8NTgwVTnlSJWFLJvWI3
Yara None matched
VirusTotal Search for analysis
Name bb3aac44f643199c_rangeobject.h.wncry
Submit file
Filepath c:\python27\include\rangeobject.h.wncry
Size 968.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 aa5574d09558fdde5dd48fe4fa634ccc
SHA1 efe328c926aeb9df67d53bd108292f5eb80bbb70
SHA256 bb3aac44f643199c57c13863ba4d1be4b2db248f144453729fafbf58987600f3
CRC32 26B41267
ssdeep 24:bkpZLDGUUKMijjQQl2l4yD90yBSoSzEeK3v5WR8xIsJBriKo:bk7SufQi2l4A90RoStKRW8awBrif
Yara None matched
VirusTotal Search for analysis
Name 76d1de8bce336088_nuocb6ju.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\nuocb6ju.txt.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 5720591d1980f6ded6a7b096d17d4695
SHA1 0be3b91557b9cd60ef19b53b804a0b727748521a
SHA256 76d1de8bce3360885f44f45336922252dbfa9ff0b4e3ea2d434ca56ddefd0113
CRC32 527EDB63
ssdeep 12:bkEvSko0m9fYHT3lWRi4y1+7BO/IqKPh0jyFT3Di8EgbDgTV2sNq:bkeShtgzVWXy1+7NBGyFThEKgTV2sNq
Yara None matched
VirusTotal Search for analysis
Name 45e4e071f48b152e_13.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\13.WNCRYT
Size 44.3KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 992f996cd0f338681cc3692bb4ca12e3
SHA1 01d4c29c5817f2a33b9b33929bb2aec7e904b574
SHA256 45e4e071f48b152e76faa425185dd52bed69ea0c98e1fb562a1f1256aa50bd32
CRC32 BD2B1581
ssdeep 768:T6iHYrcmA9lql7RsCrxy2T294wb9AdD68MI1jdwNs0JIMfKltw0kHoKgCxUqL:n4VA9lql9sCrk2s4w9AQaDwaJ7vjKgMD
Yara None matched
VirusTotal Search for analysis
Name 944a48a7de4beca7_msg_08.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_08.txt.wncry
Size 760.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 11aec4367dc036124ae902047d6a0b4f
SHA1 1343239a7114a73d58f4cd37c040dbe7c92e1d24
SHA256 944a48a7de4beca71eda9f410b5a2d3d54373594703ebd7800151e89e40cb692
CRC32 BCE1B202
ssdeep 12:bkEfh0EFJGKyQ8hKDlkNMKwOnP4lW4Yl+cw/IAsh+utUGU2xxzmbVwr4QEFzieif:bkMNLGq8hcjbOnPoWP8ciI/tUGxxjrJ/
Yara None matched
VirusTotal Search for analysis
Name c9fe2223c4949ac0_629.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\629.WNCRYT
Size 288.0B
Type ASCII text
MD5 f9a9ee00a4a2a899edcca6d82b3fa02a
SHA1 bfdbad5c0a323a37d5f91c37ec899b923da5b0f5
SHA256 c9fe2223c4949ac0a193f321fc0fd7c344a9e49a54b00f8a4c30404798658631
CRC32 D594D47B
ssdeep 6:SlSyEtJLlpuoo6dmoAhgqH5oAZF3vGoAZF3v6loAh9+3vnFDLq:4EnLzu8mhgqHFZF3vGZF3v65hI3v9G
Yara None matched
VirusTotal Search for analysis
Name 872f9966b6c41e6d_396.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\396.WNCRYT
Size 2.3KB
Type data
MD5 e13d4f8dedf076fda58bd95cec521e09
SHA1 5229548e06e1620623bae679f427ad8389d71547
SHA256 872f9966b6c41e6daa284f1e410ecae39693db6940e7a3e356eb2e216b70701d
CRC32 8691215A
ssdeep 24:Y3qpSAEMOVWeK0cKlnb1zbTWzb4ziWMww0FACKjB/cpXC4rC45UC4YAC4yq/D:YqSAvOVWeK0cKj7WAWWFD+B/R36B3q/D
Yara None matched
VirusTotal Search for analysis
Name 1732b081443d1e29_usertile42.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 01756f45662d7cff811ff986e2fd4e66
SHA1 fd67e79512c5386dda615835a40dfe5f286437bc
SHA256 1732b081443d1e292dd1a4477ecd8be81fa350cf3b3ce6dd222567b7585a8895
CRC32 8F757023
ssdeep 1536:EW+ywCSMyCAIShzpXrHCnD2I5Sel1UFaXUfmdQsZvZP:0MyCtShzpkDx5SeDPUgF
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 37f9fdbda46731e8_emmet_epp.js.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\editplus\emmet_epp.js.wncry
Size 377.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 40b7db2e167c78e49cf61d21acf552be
SHA1 77f195a9137dc9c36ff1837948bede7da3a39e82
SHA256 37f9fdbda46731e843f25460151081117cceec06036757fdb8ef2e97bb32e097
CRC32 69EFD563
ssdeep 6144:E89ci5QZDiyRcgSxdYsTuQWqfbdwedUbYybvkdtECCJ2++QUkqfxqW3UgAv+:DOi2+yGgSLYsFWEOmS78d9CV+QUkqFUM
Yara None matched
VirusTotal Search for analysis
Name cee2b69c43ec9e1f_readme.doc.wncry
Submit file
Filepath c:\users\test22\documents\readme.doc.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 03ab1fd3dbd389e2a294309cbb5fcada
SHA1 57e4b7d5a91223e28078b426fa249ce6627497ac
SHA256 cee2b69c43ec9e1f2574979e2ca4222b1612f35f5705afaf64795d1cfdc22010
CRC32 89B0CA74
ssdeep 6:bkEMikJ8VVdIMuqkP+noRN4BHVoN73Fru93Ol9uJwJptj:bkEMiCaVd7k++N6VAmtJitj
Yara None matched
VirusTotal Search for analysis
Name f3403cc1d39070e9_192.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\192.WNCRYT
Size 10.3KB
Type JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 800x600, frames 3
MD5 98052da18954221335a2aa0d04fa233f
SHA1 dcd9bc93b6e3106135a2e747a3d229279f904ced
SHA256 f3403cc1d39070e9296fd54bc3326498c9a5522574f674bc1e030de321eb1854
CRC32 496F29E1
ssdeep 192:D3/KvFeMSNrV4Razm8ZlQzwal+H7YL3/GA6uPn+fvLVG7SOmXTsKguPA25Z:DvjNr+gzm8Z8wu+HUL3/f6uPn+5GgmuT
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 865880d505b95d80_msg_02.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_02.txt.wncry
Size 3.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b715bb3772c70b4a72767a0361952921
SHA1 3d83dbbd21d2a992530b378fec9d57770413a8dd
SHA256 865880d505b95d800a4cd8593a1db4e7746109fa41f66eacb3344bfc227b5e8a
CRC32 93518BAC
ssdeep 96:o79n71QllleJ4mKYq2zgzOswNPVmaWaZC:e97almWYZgaswCmC
Yara None matched
VirusTotal Search for analysis
Name 3b53a7da944e77d0_704.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\704.WNCRYT
Size 79.0B
Type GIF image data, version 89a, 12 x 12
MD5 c8a03fa624fe52f2e23ff5f4cb4295b9
SHA1 08fcba6bdf6a87a505ded2f142fd21304a3919ac
SHA256 3b53a7da944e77d00ebb1b352ece6b6e50572e0222678087b86bb163a3969150
CRC32 00FC1A6F
ssdeep 3:CkkXlhetwltxljpWer4LhsUszoWAi:HePV4Lq8i
Yara None matched
VirusTotal Search for analysis
Name 51f430ca5d52405c_44.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\44.WNCRYT
Size 2.9KB
Type ASCII text, with CRLF line terminators
MD5 9919164f3cc23080ff51272b81778d93
SHA1 2c4d6295fa0d48fc2f08a711477ff6ebb481e7c3
SHA256 51f430ca5d52405caabb6dece894a77915615bb71dccd100dc37bd29bc725581
CRC32 491B3B22
ssdeep 48:Gv8mFoB9S9mEW3WPET9mHRLCL+VLyLyPfAjkmNzNMmbz26MmbzqMmbzRMmbzF9mT:GvtFw9S9lA6ET90VXxCHm9/ZcP
Yara None matched
VirusTotal Search for analysis
Name 47888d136b9444d1_izaiwdonvhsgmwxjg.docm.wncry
Submit file
Filepath c:\users\test22\documents\izaiwdonvhsgmwxjg.docm.wncry
Size 537.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 46f2d47825218446558ab537054ecc3b
SHA1 a0d4c6e71c605cc71576817a420c4aa3a97978d0
SHA256 47888d136b9444d1fc4071a32f69be00896862961c8f3e500150bc49064b7537
CRC32 809DC1E7
ssdeep 12288:hzkd+EWR0QZ8e44xDzBocU3ejQ8OhLMdAVm8CiKe69fffDJv/nOF:hod+E4qe44xD1ocU3ejQL4Ve6FfdvOF
Yara None matched
VirusTotal Search for analysis
Name 073c5d92a2fa7bfa_vsjjfakhemtn.doc.wncry
Submit file
Filepath c:\users\test22\documents\vsjjfakhemtn.doc.wncry
Size 367.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f6472637d323f42176e140bbd7c97185
SHA1 297d45a24e98936caad66216c350da58df56e9b2
SHA256 073c5d92a2fa7bfabde66fb38e30723c9d597a09719e50c80991eee0270e89a0
CRC32 66BFE757
ssdeep 6144:1Yh2fn989730vKr/QSNn2Duo8kaWbP/byqLKsaB/yEIO9HF1A1xKuZWcPaJzcJmJ:1YhI98Hr/QS9imq/by6KPB/uyHOZPaJL
Yara None matched
VirusTotal Search for analysis
Name 1e5902164a0ae536_586.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\586.WNCRYT
Size 239.0B
Type ASCII text
MD5 6e8ede13db59fbc370572ca72d66e36c
SHA1 a0be976bb2269ecb935661972c427cdd70bdca1e
SHA256 1e5902164a0ae536d9e4430b6cb29884b718fc4df5901583f13a96d848266ad4
CRC32 DD5FD937
ssdeep 6:2MqdSOGVKfetEX8sEuGLRxtqdSOGR74pN6Dzqv:2qbcmEdEuudXUpN6DzU
Yara None matched
VirusTotal Search for analysis
Name 5c08faa89ebb4fc5_pwrdlogo150.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\images\pwrdlogo150.gif.wncry
Size 2.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b6a42fe1a1579d266e32dfe0db033e1c
SHA1 bf52a2fdd67011091ff5b17ad9edbb935a4bb55e
SHA256 5c08faa89ebb4fc5d5ec9f9df0915b0b9ae36f8c4878de903d7548c847dd5695
CRC32 4ECEE87F
ssdeep 48:bkwG8Q3MRX47Cp21YXgksO7zM7V5TPWCnMSTMhXaZ7yJtuYdX/7LRK49L:oXn8Roez1GFzTpZ74tuE/w4x
Yara None matched
VirusTotal Search for analysis
Name 8f300cffc83467bb_ucnhash.h.wncry
Submit file
Filepath c:\python27\include\ucnhash.h.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 bf73b16a417f00fa0ff07f7d8e23f910
SHA1 3bcb7285da8d652f54dae9ce9086df6622ed9299
SHA256 8f300cffc83467bbebe57a87c3842cdd45caa4ea7645453cd8a1278f00367c73
CRC32 949D3ADD
ssdeep 24:bkxy0WWX/p124CSvETPjQ+i/tyksKdBgVVt53DF/3mSF+qd7v:bkIhW64CS1+izVdBgphDx2SBdj
Yara None matched
VirusTotal Search for analysis
Name 6b796d3457164cc7_35.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\35.WNCRYT
Size 10.0B
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type ISO-8859 text, with no line terminators
MD5 b6c6336344949a09313c055e7480f335
SHA1 b954011fd516b73b021609874810919b0661063e
SHA256 6b796d3457164cc7ccef58489d03f6aea5296a6ce57db7de541c9838068b8f8b
CRC32 D6A7B8CE
ssdeep 3:+:+
Yara None matched
VirusTotal Search for analysis
Name 2adc900fafa9938d_m_german.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_german.wnry
Size 36.3KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 3d59bbb5553fe03a89f817819540f469
SHA1 26781d4b06ff704800b463d0f1fca3afd923a9fe
SHA256 2adc900fafa9938d85ce53cb793271f37af40cf499bcc454f44975db533f0b61
CRC32 B77F1017
ssdeep 384:SheftipUENLFsPzy3EFHjHdN26G2VSA1Ieo75Y3kmA31dv61QyU:Shef3jHdfG2oe1ZrS14w
Yara None matched
VirusTotal Search for analysis
Name 0c5a3f2279b70c25_406.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\406.WNCRYT
Size 3.3KB
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 830e48e7946343bbd9d2637858563ffd
SHA1 e9a7714b8388ca4cd5dbfcb90448ddbd9d56fac6
SHA256 0c5a3f2279b70c25a2dabd29a6ede0d46a881280f6c2927d1e90073f2030041e
CRC32 9AB6EA80
ssdeep 96:P8lUZmBGbvUbgX0ZUK0BnMyk9znChMuJf:kFkbUkkuKAMKhMO
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name fef4d666d64bbbfc_readme.txt.wncry
Submit file
Filepath c:\python27\lib\idlelib\idle_test\readme.txt.wncry
Size 5.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3d70ebc66b0239e36eae752d69fa2828
SHA1 2c930332239b84eb353ad7737f5124573e74a321
SHA256 fef4d666d64bbbfc4285fd0ed26683942b3e7160bb1d019a71d73272273c6026
CRC32 6362C284
ssdeep 96:oPiQQoPFZsTd7LbHoUAusQe4+5P/yGVeIyTuiZNCy190jsfTfQSo8HdCZs3KN+YD:LZAFZs3+5P6AyTrJOj47s8+szC
Yara None matched
VirusTotal Search for analysis
Name a4f6696d2c3969bb_idle_32.gif.wncry
Submit file
Filepath c:\python27\lib\idlelib\icons\idle_32.gif.wncry
Size 1.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7746ca4c48c3fbccd8e4216d5d5bdccd
SHA1 4eb9b1f8727411db46b5affbbe4ec3abf51533e5
SHA256 a4f6696d2c3969bb0ecfba5de65dfd9eb2c48ceb1b7e7b29f4d0b0300b510d74
CRC32 BE19F6DB
ssdeep 24:bkblF20AMGETaW+HlPbwG+jheUVLrsfsObQhCe1ebL04s2grNyvNj:bkb35f2bFDwTUfhQhC+Y7jONyl
Yara None matched
VirusTotal Search for analysis
Name beee7b7a733f96ea_orav2tl2.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\orav2tl2.txt.wncry
Size 584.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 841ef2c00241673e91657244beb34b1e
SHA1 44614b4c2de44a17b5a547277b8d0d9700d08c34
SHA256 beee7b7a733f96ea11beb4445a90f80a9285288052a79acaf1f8aa5c55906be8
CRC32 8E0107EA
ssdeep 12:bkEH9V4bZ5XTauzex4SeCPAZ0FWfcSJEdlBNLahY9oyh05b+1:bk6f4HjauzWeCFaZJu/Wm05u
Yara None matched
VirusTotal Search for analysis
Name 83d043a7ceb335dd_icon_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\icon_128.png.wncry
Size 3.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a7bc7fe92a198ba7e9008b21bfa15336
SHA1 8b90834546abb8b85c5ef043e3ccf27284c6cc3f
SHA256 83d043a7ceb335dd049f8593cf09ae2b3971cfa6e3c7bc56972e5319a7c9d35d
CRC32 DAC04D7B
ssdeep 96:oj+UZQQZrxpx70wrw3I7HN5abGhkRozjWoGWAqkGgEWEO26:fyZ57drYI7zeGaRozpGWAkg9EOn
Yara None matched
VirusTotal Search for analysis
Name 4200ba4f53a87070_extend.txt.wncry
Submit file
Filepath c:\python27\lib\idlelib\extend.txt.wncry
Size 3.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 cfdfe07b33cca9bf760779ec78b854fe
SHA1 57d590a899924a21e77751ca0fea5b9c20bc5931
SHA256 4200ba4f53a87070f2b2581c3fcbbb89eef628b361d9c2216026c42de91e46ba
CRC32 BE9638D0
ssdeep 96:ozF798HvJAgxOVVfvFX2/04SP9q177NSiI3pi/wP:eF7yN8VVfdm/0DP98RfYP
Yara None matched
VirusTotal Search for analysis
Name 505ccfd91dc952c3_155.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\155.WNCRYT
Size 5.7KB
Type ASCII text, with CRLF line terminators
MD5 82dff2672115d101cd47a8fa9b6abeda
SHA1 0e8e7fc2f191760c51dbeafa0fc32445a7374cff
SHA256 505ccfd91dc952c3373672526e966ddcdca9d5f2dfbf84b8c8adb7bcd1ab8e76
CRC32 806A2A67
ssdeep 96:64MF9imys4SYsCupcQS7tFqz5LvLRGUnD/:26SdwStLj9
Yara None matched
VirusTotal Search for analysis
Name 9b09096817234c32_fa.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\fa.msg.wncry
Size 1.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 90920a27340360780645a535f59341b9
SHA1 5fb91ec19ff35beebeb40eaf8e63aca895addcd5
SHA256 9b09096817234c32a451d4ca5e63505b4fe213bda50eabcc5109d53fd8093d54
CRC32 F17AFE24
ssdeep 48:bkBi4/zEifuUXCJzqCCRqDZ2Z/G/hE+q/zZMTA/5eDT:oBpEifniqtq1evM0/2
Yara None matched
VirusTotal Search for analysis
Name 609824cc9c4f6c26_device.png
Submit file
Filepath C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
Size 43.4KB
Type PNG image data, 300 x 270, 8-bit/color RGBA, non-interlaced
MD5 7051c15362866f6411ff4906403f2c54
SHA1 768b062b336675ff9a2b9fcff0ce1057234a5399
SHA256 609824cc9c4f6c26c529ea3eb6f112c1a7c74d5ed58e25b6f9d88dce5944626a
CRC32 D0263725
ssdeep 768:535IyJCYFakAnKI1Uu0IIjMwFtNy2Sp9oRnMcHCe+X28hGlrBw/21Qo:7C0AKImaIjM+A2K9mnMcHX+G8h2
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name eb77bbdbb6490070_591.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\591.WNCRYT
Size 406.0B
Type UTF-8 Unicode text, with CRLF line terminators
MD5 4c4b99f3edd32cc511237b9bc537de2f
SHA1 8b68afdeb831717cfc4a5e62e5ac1a3c887e9fdb
SHA256 eb77bbdbb649007038570ad2b7c6c6ce45635def8cac065279cc602f93ddcd41
CRC32 59DC350D
ssdeep 6:hum8cKD8VAC6ypLRi0iBAyytJFRSOGLAZTpst8mvjFBy53JHmbgLQBA2MPFy+xky:humhpWytLRSOoA/st8IBA3pHQ2nD5
Yara None matched
VirusTotal Search for analysis
Name 16d204dec6d7274b_installed-files.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyautogui-0.9.50-py2.7.egg-info\installed-files.txt.wncry
Size 728.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 c0fe269782de04fef6c9368e2b482b3b
SHA1 282d97874e9ff5952f630b3fe0dbfa67d93fbc33
SHA256 16d204dec6d7274bc00cdb4b049b17289de41bb84f167f58d3607ccc3a358ad8
CRC32 B5C7984A
ssdeep 12:bkErFgK9AohPowCvcWw4ryCiZFDQSx3QmqKPh1HbqCraBksoQTPPAqVqnX8l:bkAb9A6Iw0kbQSZLGC+ue7PAqMX0
Yara None matched
VirusTotal Search for analysis
Name 606d8421c4a7065e_sysmodule.h.wncry
Submit file
Filepath c:\python27\include\sysmodule.h.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 76628a0a86d5db0301c0b4a43557642e
SHA1 2d30b4d58817e9fa146f5a4bf66f468fa093887f
SHA256 606d8421c4a7065ea3624d347f550afde189e55429c5fb9ad9ee8e6d8420ebf4
CRC32 C51853E2
ssdeep 24:bkAc3yN1LaE89+nUr9gdF+edy0f8vo09h4i5eN6wbdyHjH:bkN3yi9eUradEcy04Ai5eN6wJyDH
Yara None matched
VirusTotal Search for analysis
Name 797d7b287d05789b_hydrangeas.jpg.wncry
Submit file
Filepath c:\users\public\pictures\sample pictures\hydrangeas.jpg.wncry
Size 581.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5b91224a10046f398cf6cda4c9a5d0ae
SHA1 51de1ea31afa4c5ca79c1c0f6892036cb323eb48
SHA256 797d7b287d05789bee36d56b81d8b4053ee0205005a5da9c73a7ae378b367b6a
CRC32 6D0377FE
ssdeep 12288:toqdXlk3Xnr5LKp6fZaOQT14arrX4pkWUmBX8vSW40siCfMN8O1y5E3Ve:ttdXlAUEfwTTXr8yNmO400k0MVe
Yara None matched
VirusTotal Search for analysis
Name 19ac3dfea103fee4_news.txt.wncry
Submit file
Filepath c:\python27\lib\idlelib\news.txt.wncry
Size 47.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b470c2b5ea4e1483969ed917d202d62b
SHA1 4ecbfb01c30a28daf32c82596c673a92c8e1f494
SHA256 19ac3dfea103fee419aaa11ffd05d6d94be2440726ec0298759193b11651c63b
CRC32 3F2A5ADB
ssdeep 768:x3TCtK/L5sRaTak0y+0knLtiRY/5wBCETNB+PtPcp+CZL6M9ALr0qA9wQVyTDtoZ:hOtqL5+qakzYLIRYq9KZ/BMGishGNBJb
Yara None matched
VirusTotal Search for analysis
Name 831f611ee851a64b_680.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\680.WNCRYT
Size 910.0B
Type ASCII text
MD5 441cc737d383d8213f64b62a5dbeec3e
SHA1 34fbe99fb25a0dca2fda2c008ac8127ba2bc273b
SHA256 831f611ee851a64bf1ba5f9a5441ec1d50722fa9f15b4227707fe1927f754de4
CRC32 33D2862D
ssdeep 12:4EnLzu82mCBuvFYcEfmt1qWjefjESRsToOqrlHvFguSixTRs1OAfC67:4azu82nBuHEfKxjeby7cl9gbZUAfCc
Yara None matched
VirusTotal Search for analysis
Name 9321a0dec80af922_452.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\452.WNCRYT
Size 18.9KB
Type Zip archive data, at least v2.0 to extract
MD5 0f7ac77f516af1434438f5ba50c51d38
SHA1 6dd2675be2d798cca938f31b0e78136eb0759344
SHA256 9321a0dec80af922ecde3a2770e630fb4ab92a488aca3bd5602d3746d197c4fa
CRC32 5B3769CB
ssdeep 384:niP6sD8Tk3NHBIaSjXvdobshvLLcbAmpjq/i+eAIJ:nqD0eBIaSh+sM55v+eTJ
Yara
  • zip_file_format - ZIP file format
  • docx - Word 2007 file format detection
VirusTotal Search for analysis
Name 3a1d05875283ca3f_245.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\245.WNCRYT
Size 2.0KB
Type ASCII text, with CRLF line terminators
MD5 4189a638a15d18986b5115f3f9329fbe
SHA1 5eeef91d71eb5e95f01b0dd57cea52ebed58f2ef
SHA256 3a1d05875283ca3f3326287b16622cd79d9be3d48ba15cd801e64b1471ffafbb
CRC32 EC3AC0C6
ssdeep 48:KfKv5yeR0iPfP24r1ZnjBXgZsZScj07pJA0rwnlkHUKDjZTZrZLa:Lwk02ZZn1QZsZA7pcKDjZTZrZO
Yara None matched
VirusTotal Search for analysis
Name b1a7e8a341a1f795_700.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\700.WNCRYT
Size 84.0B
Type GIF image data, version 89a, 16 x 12
MD5 540b5e792e4a09b6af2a4362fb2b78fb
SHA1 26268a6c8de95b4bf0d5a97f02e74ba34acc5c08
SHA256 b1a7e8a341a1f795f0890116f68368ff4bb0f1e0ce73691719dc24e3927463ad
CRC32 EA48D692
ssdeep 3:Cw6NlhCEchkltxlDnAxuJx+umMzgrE:R6N0nxYx+AgY
Yara None matched
VirusTotal Search for analysis
Name 6ded08fbf36b556b_databases.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\databases\databases.db.wncry
Size 28.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 0ab1347d897d738246336885b86fb40e
SHA1 ed4e85a730900b042198cedc6653122ba70abf57
SHA256 6ded08fbf36b556bd6162342377fb794687136020677b25f9ce3e00a199e57c6
CRC32 09516D1D
ssdeep 768:lhtrGxiK37y2bANrI2jo8+lXYNpNSbY9gzsvBv:3trUi0DAHsxYrNSE/pv
Yara None matched
VirusTotal Search for analysis
Name a3f5f384f78457ce_561.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\561.WNCRYT
Size 641.0B
Type ASCII text
MD5 9217f53a775172f2f20567c26147f53a
SHA1 9c75ac8715eaea0cab69d9c4f3f4a48be0c836b5
SHA256 a3f5f384f78457ce361021961bbf2155b4028a2781b6b6a35ba869c2f50ea5bd
CRC32 063C5ED0
ssdeep 12:mvS0QiH/XomN8AFe0ke6XWZTheZdSJ+R8aycTo/dUwsFMRxURxzm:YS0QwfJN8AFe0H6wheZdSJ+R8aholNsC
Yara None matched
VirusTotal Search for analysis
Name 48afb4de4de45093_gl.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\gl.msg.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c09cf170fcc25b89436fc5bb61572a5f
SHA1 b92d3fb0900b39873122de85a6092741e2ea6a4c
SHA256 48afb4de4de45093ae8d3f8a24e74fd1a0e1fbda43365ec63c922c5795b9c23f
CRC32 5A91FC3C
ssdeep 24:bkVFa3Uacc2HAESpXPtkI4MPBgbwP0HzJ/I57VQXhFTzGDwkddUa42:bkTa36c2zwftkI4MPcw8H1I3CjTOwkd9
Yara None matched
VirusTotal Search for analysis
Name 34ec243c237e7671_435.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\435.WNCRYT
Size 16.0KB
Type data
MD5 2c2b5f4367591898e0bdf69652ef84f4
SHA1 b633a453ccc04b7791c79c82e0c6519f61491563
SHA256 34ec243c237e76716f31655847795a2b00f91e687f365193930fc431ab5d6891
CRC32 EDEFB92D
ssdeep 24:h0q54sc//0E6igTsi5QkU//M8yKIDka5I8M//:z54sc6igTs//M8a5I8M
Yara None matched
VirusTotal Search for analysis
Name 3b1f0975a19438d1_structmember.h.wncry
Submit file
Filepath c:\python27\include\structmember.h.wncry
Size 3.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8c237ab8d0c892f69f9a7b6bdd2dca9a
SHA1 de77aef78eb854d2db21b04e00d56120196e486b
SHA256 3b1f0975a19438d1ca6ae812b6ee4f9626b784453b0a725fd2752b5c15f2c461
CRC32 31A42AE6
ssdeep 48:bkJLz2CK4pxUFmzxwLPp6S2xUPLM+CiLNF+cuwq+/vhTGYJrvYv+Gw5PtOuvUOz:opzjZAmzxwLAilF+cVpxwWvVso9z
Yara None matched
VirusTotal Search for analysis
Name 56894ae1243a836f_pyfpe.h.wncry
Submit file
Filepath c:\python27\include\pyfpe.h.wncry
Size 8.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ca07c85afc7747a33840d037cf1f4175
SHA1 f187baea1737afc56e88315901f53479aecf02c3
SHA256 56894ae1243a836f3dd61ce4b97346fcabf157b609d5e777c23f1a54e9657422
CRC32 7F12E9BB
ssdeep 192:PNZLpbQlqqSti2nHaZ7MJR2WSr8MpoIZR5mqga3XiKQf:PnLZNqStnHaZ7DWSr8qoIZRb3XvQf
Yara None matched
VirusTotal Search for analysis
Name 7dbc9c8a00859144_minusarm.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\minusarm.gif.wncry
Size 344.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 24d6a8c7dfa746b0ffe51d423f67b400
SHA1 942aa49a1bf63a210b26e1daa2ebb6b4cc7c3c68
SHA256 7dbc9c8a00859144cdc8c099a0b3f3e7597ea15b0424d052db3b21c049725e77
CRC32 3FE253FC
ssdeep 6:bkEPoPAc5EzVu/BpjZwDWa5X9SsRRFszfIeU7fBiND/ChrvaW7tVfz:bkEcnkmNZw/19ST7UDYF/CwUVfz
Yara None matched
VirusTotal Search for analysis
Name 237498ca7b93dcd5_538.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\538.WNCRYT
Size 839.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 e1b96aacaea5bd1c3b67622bb8572882
SHA1 bda07384669032ffd3d5936cd42969facefee776
SHA256 237498ca7b93dcd5dc2296a834a0f2d58df91d26cf12e95d3f6efa1262503c7b
CRC32 8CB3C495
ssdeep 24:Shrqi/vhRlDuYHLFquD2mXpB/3mOkFq3Xm0yj:StVztuYHLTtXpYvfjj
Yara None matched
VirusTotal Search for analysis
Name 9ac7b38f2663797f_topbar_floating_button_pressed.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\images\topbar_floating_button_pressed.png.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 1f471e3dc385c87df2711f314be4bf26
SHA1 dc194903b2957e57b0ce6770136387b1dacb5cb3
SHA256 9ac7b38f2663797f887a270a0f00d0af324bc8af1e42863dcdf83490f59c6668
CRC32 5E80ACAF
ssdeep 12:bkEjkt3Z8zkCmTTgcyH0DCCkhapaiR1W9X:bkkkQkCmTMcBDReKaF
Yara None matched
VirusTotal Search for analysis
Name d992573ab0f6c8dd_readme.xls.wncry
Submit file
Filepath c:\users\test22\documents\readme.xls.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 56b6f9d87596a228043f8f226ac73e59
SHA1 74d9de3eff16c2105639e7fe9b0591a01f31089b
SHA256 d992573ab0f6c8dda28671326a4abbc608568d67d9e429097ac5cb985b878013
CRC32 E7987829
ssdeep 6:bkEkIah3yJPzJ0ZeTDWtjafhAJUY/eKoWmO4lF2T:bkEkIahEGeP/uJLPd4ls
Yara None matched
VirusTotal Search for analysis
Name cc0bf1895f644a51_srcfile.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\srcfile.gif.wncry
Size 360.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b99c929c1789d8dbd8cbb5af6cbb0cbf
SHA1 e8481c48ff409d127d1ce96738088c30619cf448
SHA256 cc0bf1895f644a5187774c7e6ba8267f611bad94a2695962c7324809eb252e44
CRC32 12011076
ssdeep 6:bkEAmoR4jsHPx6+WWvn0HM7AXiA/LgDoMJgbeFIyCzNIB6dv3kXv/x1L8fkj9n:bkE9M4j+JJP0sBA0u6WZ2BUv3kXvxj9
Yara None matched
VirusTotal Search for analysis
Name d3e8d47e8c1622ec_background.png
Submit file
Filepath C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
Size 126.7KB
Type PNG image data, 1213 x 270, 8-bit/color RGBA, non-interlaced
MD5 9adaf3a844ce0ce36bfed07fa2d7ef66
SHA1 3a804355d5062a6d2ed9653d66e9e4aebaf90bc0
SHA256 d3e8d47e8c1622ec10adef672ca7a8992748c4f0a4e75f877462e7e661069698
CRC32 2B8870B6
ssdeep 3072:fyUCC0XrT/ltzUKWzzsnQjjEWHUZ/HIO5tg9MlHuPPDF:fdoT/ltIXnsnQjjE4I/HIOrtOP7F
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 29d872f8376f4243_en.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\en.msg.wncry
Size 3.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ffba95e6027eceddf72a69abc6e44111
SHA1 c3d2a301e2f5578c21acf1edae4f20e57befe181
SHA256 29d872f8376f4243e5d311499e52d152820ce95ba2d01dedba601f47281ad10f
CRC32 8A95EACC
ssdeep 96:oX3FZ/bkHWY+97GsthzTiC/FYLf+cdIaRLA:AZzoW99DtVR+Lf+cRlA
Yara None matched
VirusTotal Search for analysis
Name 25d1a0d0b764685a_iterobject.h.wncry
Submit file
Filepath c:\python27\include\iterobject.h.wncry
Size 840.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 952db4eef787ac66eaed0a9ab4f7525b
SHA1 39929c91c9a0b7af03019f00be220fa6a2588213
SHA256 25d1a0d0b764685a65539f9ae00864f3f67fc441e45f6cb2abd6832aa42cf464
CRC32 2956E682
ssdeep 24:bk4iLva9Hkm9FomU+JgJpy0Biy/l/0+8y5HUWFsS:bk4zkm92m7JgJA8P
Yara None matched
VirusTotal Search for analysis
Name d5f9234dc36e7ffa_730.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\730.WNCRYT
Size 160.0B
Type PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
MD5 8803665a6328d23cc1014a7b0e9be295
SHA1 9da6ee729d5a6e9f30658b8ec954710f107a641f
SHA256 d5f9234dc36e7ffa85f35b2359a4f82276f8395efa76e4553507ea990b27fc6c
CRC32 CFAC16F2
ssdeep 3:yionv//thPl3xWrA4RthwkBDsTBZtnAkx/RPJDmV7bScsP4a9zln94FptVp:6v/lhPKM4nDspnAkZJNmgPdln2TTp
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 4ff66cb36c055d16_cmath_testcases.txt.wncry
Submit file
Filepath c:\python27\lib\test\cmath_testcases.txt.wncry
Size 136.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4f71c3a4fb06800998f8157863d2d84e
SHA1 fa81db2ef7640fa2e07859822c4fdf60c827c510
SHA256 4ff66cb36c055d163e481df9edd89718c6b934d8d8a903d51986fff891162677
CRC32 DAA3318A
ssdeep 3072:wh7UuwfsJfpdyb3HwoLBqPZQA4rVl7DznXbPAueAhli9eMkAUrk4+MJAuwli:w2KLyLH9VsD4r77DznXbLeAnYxkAB4+C
Yara None matched
VirusTotal Search for analysis
Name e9422a621933c0b7_617.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\617.WNCRYT
Size 797.0B
Type Non-ISO extended-ASCII text, with CRLF, NEL line terminators
MD5 8915db12d90e75eeb7e61602defc9a0c
SHA1 e26ddc1288adbb495bea87a843e889edab62d0da
SHA256 e9422a621933c0b7c6bd2712fdd66c7acbf97ba0dd9a08d449f84f95949e464f
CRC32 FE2BBDC4
ssdeep 12:tFnbki4JIoqumiTgdFy9ro/WB75miPSrZMOSUeomLV1in0roSx76XKB+xASinL3o:tFnIOugDI0KwWJbmn8KxASinbyBnpnOI
Yara None matched
VirusTotal Search for analysis
Name 5f1128f136fb1e76_fowratdvst.docm.wncry
Submit file
Filepath c:\users\test22\documents\fowratdvst.docm.wncry
Size 625.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4c0c08d4e744f15c981b114c43539ee1
SHA1 e5a28daae2f3fa610e8e513c4143e047c925216d
SHA256 5f1128f136fb1e764441a4f038776dc5c93247fa471ffb42e8d5cbc9728da557
CRC32 93BE8BBF
ssdeep 12288:ebM7Tw1nfJR/7VkDX92jNzWEeQ2JsUJ/6ShTL5eE/HBNxnC0t+ZXxHDly0B2MC:ewTw1fJl7VhjNdPtk/6SZLTf5Zt+ZXdI
Yara None matched
VirusTotal Search for analysis
Name a172a468d96b4405_20.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\20.WNCRYT
Size 469.1KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 06d8fd3dedb111c964830538e54f36e0
SHA1 fe2aaadfeae9da34827b61f2cf5133df4894c9d3
SHA256 a172a468d96b440585b53aef59188168d07486474c7c2e1ec048658118c61354
CRC32 164B4FFE
ssdeep 6144:DLbndCdk5MY1l0uDiquINUUJysrDxUvcLnxsGRLbndCdk5MY1l0uDiquINUUJysJ:DLrdCiVOuD46Dvt7RLrdCiVOuD46Dh
Yara None matched
VirusTotal Search for analysis
Name aec40a58aa1319e8_de.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\de.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 542dc53b85b282a839e86182bffbf051
SHA1 b0c11223547f4ccd8138833c2449d98f18bdfa76
SHA256 aec40a58aa1319e898e94605672dde459350d5f4c894e9f56d32c779fe7221ff
CRC32 9733677C
ssdeep 24:bkbr2I6JVNVsldtKoi1Ij99HycHPc52DHQSxa060nzKFY6x1TW67HGlY:bkbrOJVNKlux4ycQoHBxzLKFjx1Tv7Hj
Yara None matched
VirusTotal Search for analysis
Name 80513a9969a12a8f_625.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\625.WNCRYT
Size 812.0B
Type ASCII text
MD5 63b8ebba990d1de3d83d09375e19f6ac
SHA1 b7714af372b4662a0c15ddbc0f80d1249cb1eebd
SHA256 80513a9969a12a8fb01802d6fc3015712a4efdda64552911a1bb3ea7a098d02c
CRC32 FA769D96
ssdeep 12:4EnLzu8U3S5dkTo7eqepFHvFgt1BAI+5zS17eM5Qz3q6owjI9I3vd3v6B3v9dy:4azu8UlMe5pF9gXDT9egQTqr+rv1vivi
Yara None matched
VirusTotal Search for analysis
Name a2e6f1b601cb64e8_jrrninqjezypfu.txt.wncry
Submit file
Filepath c:\users\test22\documents\jrrninqjezypfu.txt.wncry
Size 147.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 31799f300dcf02eb1a6fbe21abe15a33
SHA1 80a457c28594024ada32975b1c9afb25a90a361c
SHA256 a2e6f1b601cb64e8afee3302725634eded800d3fce4fc0b46f1a6ced27092365
CRC32 EBF8B2CC
ssdeep 3072:iIbqpUQkIJH+VYZwNsBpU1L3rDU6dXBvkemTq9rHgI5UTH5W5lBnV:iKqpXtG4U3rQk99mTq9cI678fnV
Yara None matched
VirusTotal Search for analysis
Name c3ab850438e7db30_es_uy.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_uy.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 673144b347573c4d83bfe892e4c964d1
SHA1 65e471d776c462eaa74d6f48cc8bb96bbc518140
SHA256 c3ab850438e7db30282d173b49363e4033d58ddf4ff26b93aadf4b911ab55330
CRC32 C81D9AA7
ssdeep 12:bkEBi51p+LmfYeh4rYeHFQHk7jy0NajVnaTbv2lMzoEURVU:bkjvp+QYpr5HFQHTdaTbOlT0
Yara None matched
VirusTotal Search for analysis
Name a1daecf15dbf4a57_dont-use.txt.wncry
Submit file
Filepath c:\sandbox\dont-use.txt.wncry
Size 344.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 9eab1c931e066aceee847d2fae0b3cbe
SHA1 08aa7529281f3df4a4582ce26e3eaa73dced47c2
SHA256 a1daecf15dbf4a5736e1ddb9f1fce0f9bb02e2374b983bff5b73b8da336000df
CRC32 FFDD22AB
ssdeep 6:bkEDlMSpDPcGjekb5XoOY/g0VjrfFnxa1kgFNIAxGIzs3T//hl8R:bkEyQbc8e2YOY40Vjrdnxaiwy3T/5uR
Yara None matched
VirusTotal Search for analysis
Name 43da37a79884e3d7_709.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\709.WNCRYT
Size 842.0B
Type ASCII text, with CRLF line terminators
MD5 737f4968dc5fc6bf27054460618876dd
SHA1 68b671ee9616c616a02a60c748d149770f1a1746
SHA256 43da37a79884e3d7e09c60054103cda9bd215c5850ac4c51eb881aa36a8795b5
CRC32 799F7481
ssdeep 12:L60unZvmwE8JSyB0bNJqHSN0GTDs5IodfFCvMHPK8fz9zTBASfYSMebcTRO:LmZvmr8cb6Hm+dFqMvjz9/BVMQcT8
Yara None matched
VirusTotal Search for analysis
Name 75de8e9eb7a045c4_usertile29.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 6a944c920d471248013a35096b1ce218
SHA1 00a1267a6e631710fc71eb2e2e590e0c693296de
SHA256 75de8e9eb7a045c484cdac6b3fd30fda99ee17cda8d0310897d0b73c2d1c4f87
CRC32 B94E35EE
ssdeep 1536:W0DmyDgb0E4je6Qp0PzjQ0d/Zm5AELc/eW+bR2TRB86:WOmy9jekfEu/eXR2TQ6
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 26f04821a50e8c52_504.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\504.WNCRYT
Size 478.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 ec668cba46b4ec3d017750c4cf0a4ef5
SHA1 bbc5216b4a8c4b8d6a341d876fc86d9b66f00958
SHA256 26f04821a50e8c52ec2cdc4afe5eba728511694b5c3da9270329d65c0a5d09d8
CRC32 FBDA4ACF
ssdeep 12:k116arny0x4JKmVNbXmMQymLXgVB0d+Aey2jf0x:S4arnLx4JRbXmom8jAeY
Yara None matched
VirusTotal Search for analysis
Name d5bf4c13bea077c6_301.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\301.WNCRYT
Size 4.0KB
Type ASCII text, with CRLF line terminators
MD5 9c303d505e0166d08effe46d40495c1d
SHA1 33f697f1ae5e2541a778da44b840f693f5b60c32
SHA256 d5bf4c13bea077c646bffb3a379e863b60c90cf7b0c0771fa6955ed2e0c6ff7e
CRC32 E2F0BEDC
ssdeep 96:LrGdbPJhFfVS7Az41SPwHvkfoFdjMsKhcncLHteQMhILymfLU94NVq:H6L1VSkcQP8DuicqeLymfE4NVq
Yara None matched
VirusTotal Search for analysis
Name 1a681b8e46c839c3_folder.gif.wncry
Submit file
Filepath c:\python27\lib\idlelib\icons\folder.gif.wncry
Size 408.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 06944e48a49e028f9a6beffb18e2512f
SHA1 f3a74dd9e769f0ff6cfc7a9bf076d256742c283c
SHA256 1a681b8e46c839c3e0b6850a2ae1b366d3624ede69340e9fd08d46265ae51238
CRC32 944FFE5B
ssdeep 12:bkEdvtj9kbO5Iq0n+NRXLmGTh6zuyrwXWpqX:bkWuppn+N9LHxytA
Yara None matched
VirusTotal Search for analysis
Name c9be2c9ad31d516b_631.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\631.WNCRYT
Size 321.0B
Type ASCII text
MD5 27b4185eb5b4caad8f38ae554231b49a
SHA1 67122caa8eca829ec0759a0147c6851a6e91e867
SHA256 c9be2c9ad31d516b508d01e85bcca375aaf807d6d8cd7c658085d5007069fffd
CRC32 BAEE692A
ssdeep 6:SlSyEtJLlpuoo6dmoa/5oaQ9woaAx/G4FLoaYYW3v6aZoaAx/T+3v4x6HK:4EnLzu8cpZF4F7xW3v6ah/3v4Iq
Yara None matched
VirusTotal Search for analysis
Name 6d3e8f9e8dd22cd3_475.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\475.WNCRYT
Size 378.0B
Type PNG image data, 36 x 16, 8-bit/color RGB, non-interlaced
MD5 d63bda555cd07af2d332180f375e61c0
SHA1 b94e32fee10228132a363c6474236640a62fcca7
SHA256 6d3e8f9e8dd22cd3287d10b62263fea794d494167e74174c79ee44a0ce98510b
CRC32 AF329B9D
ssdeep 6:6v/lhPN/kVR/C+lLhWviWfIyIpFr69z9bmi793ka9HVJE35tGbK7+XjpbV7yxibp:6v/7G/Rhqiyok9b9906stGbKyNV7B
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name be107f5fae1e303e_635.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\635.WNCRYT
Size 321.0B
Type ASCII text
MD5 787c83099b6e4e80ac81dd63ba519cbe
SHA1 1971acfaa5753d2914577dcc9ebdf43cf89c1d00
SHA256 be107f5fae1e303ea766075c52ef2146ef149eda37662776e18e93685b176cdc
CRC32 B2D11694
ssdeep 6:SlSyEtJLlpuoo6dmoJ5oXo2e4FLoe3v6aZo27+3v4x6HK:4EnLzu8l4Fj3v6aE3v4Iq
Yara None matched
VirusTotal Search for analysis
Name 332a8c38ade63b00_selfsigned_pythontestdotnet.pem.wncry
Submit file
Filepath c:\python27\lib\test\selfsigned_pythontestdotnet.pem.wncry
Size 2.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a76558d3d3d09cc35258b35373f27e0d
SHA1 935de64c6dee11eafe1e398911d1ccb7a7582e20
SHA256 332a8c38ade63b00b0f7e11bb4960f6644b412c9438154a27d1e87d45e923e4f
CRC32 41CE7804
ssdeep 48:bkdV281llXTDgi3ie/nTIHyWRs34gAvMiacivcUVlxVriNGrD9Wjj9eo:odj1l1oi3L/nTISMW4MrcivvVm6mH
Yara None matched
VirusTotal Search for analysis
Name 3faf84e3dc054023_183.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\183.WNCRYT
Size 6.2KB
Type JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 640x480, frames 3
MD5 6ae700031429f72a8af56ded77baa4b1
SHA1 b0b9576d0f20f520744d2904ac6b09e14705ceb3
SHA256 3faf84e3dc054023b218fe71491a608a138c41a15da9b54eb33df35edb991e70
CRC32 4CDE4347
ssdeep 192:4bRP79kpWqgvoIndMGdx/UCEB/0VD78rh:4bRD9s2Mwx/Ur/0VDQrh
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 8d50364fd42a8d7d_exec.png.wncry
Submit file
Filepath c:\python27\click\click_image\exec.png.wncry
Size 776.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 64d90a5a171974c7648c40e766785c6d
SHA1 6c3a35ebcc69365a60080abf0b99d21d4ad659de
SHA256 8d50364fd42a8d7d9464064418abe443f7b151f25f02c60e9b19212bdf27a0fb
CRC32 64753B6C
ssdeep 24:bkNQg12m40rAUPkYRKI/skyxJC3nJfRPEHQq:bkNF1B4hUxRKCs5kJfRPEr
Yara None matched
VirusTotal Search for analysis
Name d0101474d455f487_231.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\231.WNCRYT
Size 2.9KB
Type C source, ASCII text, with CRLF line terminators
MD5 d6e7c73d1bc041419af7d022c0380162
SHA1 50c7f9650f5c5fca4d1d1299d8a6d63e1d02da9d
SHA256 d0101474d455f4875b51852518c7fce359373708147936727697f2b0ec5764be
CRC32 55CD3000
ssdeep 48:SXSXQX4MdXLU/89LShjXfWsGozckd908+Y+znbGq2Z+9unPPciByKQznkFKvdD0:SiAhI/89LSpYo/d9D+YgbGpounHXQTkT
Yara None matched
VirusTotal Search for analysis
Name f29442022707622e_alternateservices.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\profiles\qxo5wa6x.default-release\alternateservices.txt.wncry
Size 888.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 8a1a9492e08c436e2c3250ef4e453265
SHA1 8d3903461a242ca58db41de346c553998028239d
SHA256 f29442022707622ee0ebeb3ab88f2e2bdf8b7222f0486c80bf667034a11da4ed
CRC32 DAF7F8A7
ssdeep 24:bk0yo2ZQhaSeEzge1GuTy3jG4Dn+hjfMGX21ht:bk8K6VeEDGDjGKn+hzXu7
Yara None matched
VirusTotal Search for analysis
Name 6b373002687f1e6d_pydebug.h.wncry
Submit file
Filepath c:\python27\include\pydebug.h.wncry
Size 1.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8aa32ecc7f44a78c511bc968c8bcd04a
SHA1 1430a2917e2045e2f1f97900f0302b0327031f38
SHA256 6b373002687f1e6da18aff01515acce056dadc94739f2ee8c0516920270921e1
CRC32 5F5E5867
ssdeep 24:bkYwxWPgIPkihJV540OdL1kfEQHbYeuL4EQCQSDDuKQ3JzP5JwRvV4+zB11Jw2W2:bkYwxWf8e56R19QH8PTQPbrW6+fjKIbh
Yara None matched
VirusTotal Search for analysis
Name 6fc4098826ca6e02_702.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\702.WNCRYT
Size 60.0B
Type GIF image data, version 87a, 9 x 9
MD5 8ff1cebd68cf66bcfbfd9079acb500c2
SHA1 aafb265ea8da893be4fe87f520194a0ace9b2fbc
SHA256 6fc4098826ca6e02ed0be4060014861e494913e6684abec63b022d60c1c73011
CRC32 B01CBEAB
ssdeep 3:Mfsl0HTjl/I+ZPlNm9gE:dyW0Pla
Yara None matched
VirusTotal Search for analysis
Name 2dbfb55b484545b9_228.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\228.WNCRYT
Size 2.8KB
Type C source, ASCII text, with CRLF line terminators
MD5 d63054d05b04611af3fe09695aa1a92c
SHA1 f3a46f0da6814c9ad3049a678f87007a113030ae
SHA256 2dbfb55b484545b94247d1ce65702f1460adc970edcd0dd4a86b2957902728fb
CRC32 87FB0780
ssdeep 24:Loc1CmZXQFGM9n4O2D/ot/wk9CBC8iL/mILW9QVTd7Ng0gP2SAvJlpFJUdPWQkPs:sc3gThak9Q6v69CFJ9yMohJpWeWhcuc
Yara None matched
VirusTotal Search for analysis
Name f5789d4d4c35aa6a_cnwcmkjayf.txt.wncry
Submit file
Filepath c:\users\test22\documents\cnwcmkjayf.txt.wncry
Size 602.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 9cc4f92b4be4cd364b8ce50688a3e2fa
SHA1 318f676516eb5f0e54ad1ad0b3da25c09486a917
SHA256 f5789d4d4c35aa6aadc32c0b45ce32eeed61ff733064b424b936dc0954ae9263
CRC32 674925CD
ssdeep 12288:GIslksCxEMT+r1LAA6uZANar0qaabxr/f+xdUwrY/JkcZEAtCryPR:GFGs2TecAVZANar0ex2dFkkti5
Yara None matched
VirusTotal Search for analysis
Name 750c2c4d95407b68_template.pl.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\editplus\template.pl.wncry
Size 360.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 08c5df6140e583065c11faa6c970a9ba
SHA1 3ea43d9dfa84020e1ffd3c513490fe0835140365
SHA256 750c2c4d95407b68bad65d4ff9106aed9e1cabd6f9b94e74830b98ec0e2a7cf5
CRC32 01B55BB2
ssdeep 6:bkEtnYpsWh+NxwGxwF189teQEkkoT0yva1j5VWx9t3NCh/QXnUSUgEfcOHyJlr:bkEtHWoLwoiwe7kTBvO5gXt3NiIkZ0O2
Yara None matched
VirusTotal Search for analysis
Name 379949a655a10713_flapper.gif.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\images\flapper.gif.wncry
Size 69.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3736aee67f4f455bd59d92a646d6ced5
SHA1 c3e679e2612b8486daec0b2978798a1d23bd767f
SHA256 379949a655a10713a5922e4fb9ac8f0c08af60b0f7b47a98532efdb3abf46440
CRC32 46C3E6A3
ssdeep 1536:mc7QceEZF/35N79VRuj8zKWQ6N7DgWW4X4mnPq1E:r7tF39buaKWQUnJoEIE
Yara None matched
VirusTotal Search for analysis
Name 2d22952b1eddc011_492.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\492.WNCRYT
Size 633.0B
Type C source, ASCII text, with CRLF line terminators
MD5 65ffe2262cd4b16809b2de0188b01ebd
SHA1 fa2d9b9785b83248984867f912340cc3585aa3b2
SHA256 2d22952b1eddc011747a1a2c45bbefc95e81bc5db468df0dd659fa6a3c2f5ef2
CRC32 F591B902
ssdeep 12:08mrnVJqVL1bfhtXn6ugn66PZNErbZNEr1POG7WVE:j2JSb4M6hNa1Na1GymE
Yara None matched
VirusTotal Search for analysis
Name cc826c93682ef19d_651.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\651.WNCRYT
Size 251.0B
Type ASCII text
MD5 74f014096c233b4d1d38a9dfb15b01bb
SHA1 75c28321afed3d9cda3ebf3fd059cdea597bb13a
SHA256 cc826c93682ef19d29ab6304657e07802c70cf18b1e5ea99c3480df6d2383983
CRC32 F7135FC1
ssdeep 6:SlSyEtJLlpuoo6dmoIgUFLoQ9X3v6rZoI9+3v9f6HK:4EnLzu8jUFZ3v6rS3vMq
Yara None matched
VirusTotal Search for analysis
Name 0aed3a6519863918_247.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\247.WNCRYT
Size 2.2KB
Type C source, ASCII text, with CRLF line terminators
MD5 2cdcf422c8432af89e9ee019730b48e5
SHA1 8a30898972a6f9c02eebd64ddf8b8d651f7106c5
SHA256 0aed3a65198639181a8409e27584e4f7408913c9182e69ecef86503360ed51f9
CRC32 4EAA3131
ssdeep 48:4s54I8ejrWpIgkqIbsn8d/mf3U5wR2RYn:1p82WpIJtA8UEy2Gn
Yara None matched
VirusTotal Search for analysis
Name 306e09801681ed28_397.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\397.WNCRYT
Size 405.4KB
Type data
MD5 57603f59144b7aa4f35e0610a537191a
SHA1 9a7157462099b85cd662374d1222531c24164980
SHA256 306e09801681ed28a6876d75e4ed0dc1926c4e128c5b694d7d24d1891bf97ef1
CRC32 5B7219B1
ssdeep 3072:7cV79+qXMDXLxvSeUDCJlgSbrwci0k38TCmtmu6JklwvRJ1C:MDCJHCPmtmu6JklL
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name aef17b94a0db878e_85.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\85.WNCRYT
Size 1.8KB
Type ASCII text
MD5 ec736bfd4355d842e5be217a7183d950
SHA1 c6b83c02f5d4b14064d937afd8c6a92ba9ae9efb
SHA256 aef17b94a0db878e2f0fb49d982057c5b663289e3a8e0e2b195dcec37e8555b1
CRC32 E93E642F
ssdeep 24:4azu8k5Fezk+wR+9Gb+Oa+U5P+wRa9Gb+Oa+UD:46ZzCNb0d5bQ
Yara None matched
VirusTotal Search for analysis
Name 62ce260f5e10fc17_717.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\717.WNCRYT
Size 24.0B
Type data
MD5 2034995f0bbaa16db835b462eb78152a
SHA1 ce19b1a236f95307067d4979f8dd96c70d69c18a
SHA256 62ce260f5e10fc17bf63faafa39912febf61d20fad51cc11606a295801743799
CRC32 9DDC3F68
ssdeep 3:illhlnll:ilL
Yara None matched
VirusTotal Search for analysis
Name 5643f600ab421c52_307.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\307.WNCRYT
Size 5.6KB
Type ASCII text, with CRLF line terminators
MD5 6046e7427262489da216eabfc11c6f89
SHA1 f72a1719cd25c94523f1f209e324b1b1d2e873a3
SHA256 5643f600ab421c525797dda085143c362e6d0dd5601de0c10068fd625879bc3c
CRC32 B7D0BB17
ssdeep 96:ROlDXlgRDXjePlRx3b98Bk1lXAQM6vBIratioLANd43kWDqpeiEJv:eECtRxCBaooIryild43kWDqp92
Yara None matched
VirusTotal Search for analysis
Name a341b43e0a07fcb9_usertile28.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 48f8ed9f48d19265562803b0ee219a91
SHA1 4984fd3b8e278e92022f257ea46cb0301c72797f
SHA256 a341b43e0a07fcb987aac58646c6105c52106616f6fae3948865be5023cffddc
CRC32 FA7C2AF0
ssdeep 768:IDeQCBx9MIv+7XMCJdX95M4ny+9U6MCIDq+N5ocA/e5UchM8:pnP9QLo+vUlVPNbAAU78
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 00f119701c9f3eba_124.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\124.WNCRYT
Size 1.1KB
Type ASCII text
MD5 c7bbd44bd3c30c6116a15c77b15f8e79
SHA1 37cd1477a3318838e8d5c93d596a23f99c8409f2
SHA256 00f119701c9f3eba273701a6a731adafd7b8902f6bccf34e61308984456e193a
CRC32 DBE0F6FC
ssdeep 24:4azu8YYy/FY+Cnwj4EbJK5O9g+tQhgQmy/L6GWGvtlMsvWT9:46al4ETw/rWQtVWh
Yara None matched
VirusTotal Search for analysis
Name c71a07169cdbe996_666.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\666.WNCRYT
Size 950.0B
Type ASCII text
MD5 b940e67011ddbad6192e9182c5f0ccc0
SHA1 83a284899785956ecb015bbb871e7e04a7c36585
SHA256 c71a07169cdbe9962616d28f38c32d641da277e53e67f8e3a69eb320c1e2b88c
CRC32 91825310
ssdeep 24:4azu8LpP8ihyz/ptFOBViNef9kekIsnyFo0:46J0i0zRtUB0c9dkVneo0
Yara None matched
VirusTotal Search for analysis
Name 75aa686ff901c9e6_103.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\103.WNCRYT
Size 1.0KB
Type ASCII text
MD5 3350e1228cf7157ece68762f967f2f32
SHA1 2d0411da2f6e0441b1a8683687178e9eb552b835
SHA256 75aa686ff901c9e66e51d36e8e78e5154b57ee9045784568f6a8798ea9689207
CRC32 6D52ACAF
ssdeep 24:4azu81WjLHkFQSMnKIeCPHy3CAVfbku5SJ:460jwyLTySI4J
Yara None matched
VirusTotal Search for analysis
Name a80ca694dccfe8ee_237.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\237.WNCRYT
Size 8.4KB
Type C source, ASCII text, with CRLF line terminators
MD5 958421ea055f38a3a54538a6c84795d5
SHA1 1a8980239c7c9be453d95537eb3d793ab0439c1f
SHA256 a80ca694dccfe8ee65e3bbd2dfc57adf2be9464ca37efe2b84471ff1fd61cde7
CRC32 20752246
ssdeep 96:HSAPSBvFuQZU5f+U+HnnGD1XBW08uQ5kws46oQcbwM+G+Ofq:HnP6NuQZAfgHnT5046oQG+G+gq
Yara None matched
VirusTotal Search for analysis
Name 6ae53dbbe2e98b17_bytes_methods.h.wncry
Submit file
Filepath c:\python27\include\bytes_methods.h.wncry
Size 3.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6bc54edd52eb85930fe339ca4b4c41a1
SHA1 e63ab70d78fd3a7d3e9002ed219d7d727b71d3ef
SHA256 6ae53dbbe2e98b1706209eaa035717917f7734b4d75ec94a1a29a35d9bf9891d
CRC32 15A4950A
ssdeep 96:oE/9EnsP1v4PVKIfR5hLwJ0GWZOPDMm4qnC:l/Ztv4PVZfRjcJRWZGDMm4qC
Yara None matched
VirusTotal Search for analysis
Name 1800c8ec457feaef_137.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\137.WNCRYT
Size 4.4KB
Type ASCII text, with CRLF line terminators
MD5 e659c759ecdf4b5728636e2f46e54686
SHA1 fbc38344b82aed8ad117ca9cf2017a15aec80d41
SHA256 1800c8ec457feaef748762c8059251e5c8f160f004b7a83e1f9a50da5b68e6b3
CRC32 52F56923
ssdeep 96:mjv/XTfjLp5ICtKPHQzcWiqnJpLjhKgGJjVx9YTG4UjpnyKl15witkft3Ut:8FyCk/QzcDkJpdG1Vaspbwitkit
Yara None matched
VirusTotal Search for analysis
Name 72316f08cc2609fe_de_be.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\de_be.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 eb8782d775b58ac2524cc4378c6c8ddf
SHA1 4854bf8db75f77144a428fe18c036f1f65eb9a38
SHA256 72316f08cc2609fed7631aa0c3329138881b6bded000d16f60271fb788dc6065
CRC32 B248BAF9
ssdeep 24:bkC6i+HzjG6/34r2N5aOOxOiapAeMcSde91xY3t2xn74fukVfiZJk+hDTJikTaJ9:bks+H3H34rXOOxOiapAPO1i3t2x/0iZo
Yara None matched
VirusTotal Search for analysis
Name 7330b1d5313cb973_wer491e.tmp.appcompat.txt.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows\wer\reportqueue\appcrash_setup.exe_micros_86cde99aa8ced0581a26266c215ad6c0632fa95a_cab_00455052\wer491e.tmp.appcompat.txt.wncry
Size 20.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 eab18ce85afb99ea369a039760a365ae
SHA1 bf2f28955ec9a14ba71c2f36c65eede097e66486
SHA256 7330b1d5313cb973484be2aff9d6aa957d124690c34b6c67f009c7a23bdf6c0f
CRC32 029F7196
ssdeep 384:R0nYOJIyR0PYUvqrSsXnyY/dLloRrnjEvFGv8MZ12QLZsCvljMqWsoum1jb:RKjJIlRvqOsi8JotjH8bQ2CdM/su1jb
Yara None matched
VirusTotal Search for analysis
Name c2a3a0be5bc5a46a_123.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\123.WNCRYT
Size 2.0KB
Type ASCII text
MD5 3a7181ce08259ff19d2c27cf8c6752b3
SHA1 97dffb1e224cedb5427841c3b59f85376cd4423b
SHA256 c2a3a0be5bc5a46a6a63c4de34e317b402bad40c22fb2936e1a4f53c1e2f625f
CRC32 9543F97B
ssdeep 48:46CpQ7kvicQfAQPlQoBBCZAitBmZ/QhQoQaQPTeQgQonQ4FQEWFkt3Wd:hCpgkvzRo6QBw53weFHXFgIGd
Yara None matched
VirusTotal Search for analysis
Name 72f20024b2f69b45_m_spanish.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_spanish.wnry
Size 36.5KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 8d61648d34cba8ae9d1e2a219019add1
SHA1 2091e42fc17a0cc2f235650f7aad87abf8ba22c2
SHA256 72f20024b2f69b45a1391f0a6474e9f6349625ce329f5444aec7401fe31f8de1
CRC32 487B7288
ssdeep 384:SheftipUENLFsPzy3EFHjHdf24G2/ezV6YQUdZYlujeMQ9RXmhRweo75Y3kmA31S:Shef3jHdrG2fuhZrS14T
Yara None matched
VirusTotal Search for analysis
Name b070572ba7cc41a5_dont-use.txt.wncry
Submit file
Filepath c:\sandbox\test22\dont-use.txt.wncry
Size 344.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 cbf68ff05eebf1c32c2a24c25139b9cf
SHA1 dfe7b65e1d095d5c7da01fe0ab89d427ba781ea8
SHA256 b070572ba7cc41a5d788f92e542af2ed79a194a42363b08f746c07be2e0f4221
CRC32 9C806718
ssdeep 6:bkEjIn6LFRvnn+hy/k4IDaAnht1PjYE0PliA2mOP8S7U1UmykHGn:bkEjHRvnn+o/k4+htlYtFFl1XG
Yara None matched
VirusTotal Search for analysis
Name 8c1a826039558e5f_66.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\66.WNCRYT
Size 2.9KB
Type ASCII text
MD5 ae99ad41faa0f00d4dd04dd5a9b77715
SHA1 006e524fc425e81ab50cdcd47a22a8faae316d27
SHA256 8c1a826039558e5fffb23605197a35250188300605244fa9ad8594b6731911ec
CRC32 8E8E35D1
ssdeep 48:RFYG8BZvy3DQfgvZVyj+DsmnA540rZh2Phv4hhpTkTj:UG8jqQfgRZorZoP94hTTej
Yara None matched
VirusTotal Search for analysis
Name 5743d9cfbd6a2e67_438.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\438.WNCRYT
Size 6.0MB
Type data
MD5 3de3413d1a2df84759d361ed90f3e9bc
SHA1 656d54ef4688c5439fe772f8887dcf09233ced9b
SHA256 5743d9cfbd6a2e673f313b6760c5871fe38db5dde4ed2bcd8ff2cba5cddf496a
CRC32 895DAA0A
ssdeep 98304:VY8NuXgH2Fd/xzj3uNKZCF/RJsJQY9Sm:V9+vD/xef/tgB
Yara None matched
VirusTotal Search for analysis
Name 1ae90fb25884df3d_debug.txt.wncry
Submit file
Filepath c:\tmpuvzci8\modules\packages\debug.txt.wncry
Size 280.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 5599fa889bad497d72ccf1fd04040831
SHA1 7a14819ef69e54462a2eb532921db87761a5984e
SHA256 1ae90fb25884df3de63f2b4fa836f536d011a99f445f3edcd9a6381ddd4dfab7
CRC32 F53B9F77
ssdeep 6:bkEUMVPdb2ayTCnkbl3EO+5TJNqAmBstefWv+oGQwZa:bkEUnOneEOeSBstewz
Yara None matched
VirusTotal Search for analysis
Name a015209378d7c4a5_fr_ca.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\fr_ca.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 53ba736b7beadb18273e59f51fcd9fde
SHA1 790dc9ab0eb4a7d97e67d818dbbc13b139913307
SHA256 a015209378d7c4a51fa566eda93e8eb1669812c1ca86f94de9107351b105d8aa
CRC32 53E2FD9A
ssdeep 12:bkEcMceUtYbfmfNEPpMykEYbKP7tZybfhlPFRDD4nhOs:bkMceUtSOCPyEkbfzjEnUs
Yara None matched
VirusTotal Search for analysis
Name 651fdfa79895bc20_test_doctest3.txt.wncry
Submit file
Filepath c:\python27\lib\test\test_doctest3.txt.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 f576e8983e44e66164eeb4a9828977ed
SHA1 0a60f9453901cbc8cc7ccdad40f17ec89c1082d7
SHA256 651fdfa79895bc20d54caee4c47ba74c9fae23bc3f2043e576abaeedc4a93686
CRC32 D5B35B21
ssdeep 6:bkEHc0k2BZ/YOkO9t/kVLkTDVMyLFmekcmVBKjphJ1GBrH+mAG+BcfOXTGsC4qQZ:bkE80XwQ9mg3lL3nrGtHZ6c8g4qU
Yara None matched
VirusTotal Search for analysis
Name fa86e3e9a690baf2_473.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\473.WNCRYT
Size 615.0B
Type PNG image data, 61 x 17, 8-bit/color RGBA, non-interlaced
MD5 16546d18302115b3f40d20e6be0d9f77
SHA1 cae41ae9755443652b8dcb3f933d7ebc73bc9434
SHA256 fa86e3e9a690baf24e395b85c11a8e4786521fe9533d8e59855a710f41576bd9
CRC32 F15EB8AE
ssdeep 12:6v/70/PTIQzByP+3DTJ9D2I3D4InmgQYGbSUPRv4VYEfZ5wEf0r2k7iO7:xceyPSDF9D2I3EetE+WRvZEf90yy7
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 0b9f37ed407f6b34_python.tiff.wncry
Submit file
Filepath c:\python27\lib\test\imghdrdata\python.tiff.wncry
Size 1.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8bfcef8120c468762931d0a60c0eecbe
SHA1 14deb237dd1edb4b8e0fd0b1daab06cb70b4b844
SHA256 0b9f37ed407f6b34416d41b70f986c8977d1372548fa39a16d6e8db2719d0165
CRC32 D78E9FD7
ssdeep 48:bkjJwbeqC5eQZrdS2SMl7sf/YaijmirW10:oFUekQPdlYQv7
Yara None matched
VirusTotal Search for analysis
Name 729bf1c9b0be23be_448.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\448.WNCRYT
Size 216.3KB
Type UTF-8 Unicode text, with CRLF, CR, LF line terminators
MD5 45def8e676ad77f3b1fb61f863c7dd58
SHA1 26cd2f215f048b5532a8156a9351d33460eb752b
SHA256 729bf1c9b0be23be57db4a43bf83f3c25fb0dd4a60e44a0dcffb601c6c2adc5a
CRC32 232693FB
ssdeep 3072:RR7dwbOV+oXK+aYzZqoZo/yPwoH296XHCgjvRW/rReOmSjoxwLBDgiiZ+3rOpbD2:pwbOEopaYLa0K0r6q+yaXD
Yara None matched
VirusTotal Search for analysis
Name 50df3e0e669502ed_95.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\95.WNCRYT
Size 1.2KB
Type ASCII text
MD5 fe2f92e5c0ab19cdc7119e70187479f6
SHA1 a14b9aa999c0bbd9b21e6a2b44a934d685897430
SHA256 50df3e0e669502ed08dd778d0afedf0f71993be388b0fcaa1065d1c91bd22d83
CRC32 90CCEF03
ssdeep 24:4azu8CouOZBQpsS9C58mTXv8/s5pkPXvRvm:46nZ6psX8mT/cYpmfFm
Yara None matched
VirusTotal Search for analysis
Name 4c839b90c20e3b53_iconcache.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\iconcache.db.wncry
Size 2.6MB
Processes 2632 (WannaCry.exe)
Type data
MD5 65fc122922f27b8fd91ec8e43b2fc1a8
SHA1 3a76e624c4ea2ddf01494e710ac682d68cf9833b
SHA256 4c839b90c20e3b53efcd97c8996318ffe9edda25b95e6138d9ba6a01410f8eeb
CRC32 04A4D813
ssdeep 49152:MGRfnmX9sYXyY9mnVBMzNC9Prrw+FqA3PYjlakATb5uEMF6v8EyBNtQjAq:BdmXaumeN8rrl46PYwbTb/MF6vEQ0q
Yara None matched
VirusTotal Search for analysis
Name 10f6602e5fda9cde_gbk-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\gbk-utf8.txt.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 aed9fa996b75f2b05d8648d764fea984
SHA1 1905fdea7ad81e928f86dff7b7935cf4716b1d25
SHA256 10f6602e5fda9cdec9c54c23f57e37e730d67bb7e9573d5c2ccfeaa436746492
CRC32 122452D1
ssdeep 24:bkGu9eXVKrECMm9FRAfY4RIcRvvdz7e0RIgVpBCBrlPmPFSH+gl6najGh:bklbrFRAw4RblvdueIMUBrlP2wl6z
Yara None matched
VirusTotal Search for analysis
Name bb86b4d452299e70_242.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\242.WNCRYT
Size 5.6KB
Type C source, ASCII text, with CRLF line terminators
MD5 b1c06c11d82ba8bf1e63bc12cec876d9
SHA1 e7f301bbdb79b1695f20849747a74c0f764ec3f0
SHA256 bb86b4d452299e701cac90d6502d57fe0af487f04fe31f6bdba6d67a8dcfde95
CRC32 E218A73D
ssdeep 96:YhGtiEFUtSuv+ZZMi5Jx3Rh0fbpNHG5GCcoyE/p0+DrJ26ZHg6f:dKm/dx3RWbpNHGzcoyERptV
Yara None matched
VirusTotal Search for analysis
Name aee5f37e012d7a82_zipdir.zip.wncry
Submit file
Filepath c:\python27\lib\test\zipdir.zip.wncry
Size 664.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 ae35f257a37546182f1d76f97bd36888
SHA1 ebc431b869e2268db08c5017f289e292694adb21
SHA256 aee5f37e012d7a8258201295a7d2be5d2b638b2cdd4a95f822b441e2191f7bba
CRC32 197F50CC
ssdeep 12:bkEc1NEM9FTPQoHOH9YBrEizcy3QLFQgwwXUNRAlqrB823a4NO:bkn1NEmjQoHoSxhcy3GBMLtI
Yara None matched
VirusTotal Search for analysis
Name ff8b39c3ed3d9bf8_753.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\753.WNCRYT
Size 95.0B
Type ASCII text
MD5 9b0f9ec25c2a2fc256f877e7e8c3836b
SHA1 4e5bdf02d1f3579524b22ad49c0bb0e0e0668b21
SHA256 ff8b39c3ed3d9bf8930c78d45e5da85ad5a72f71d1226ddf8572f6b0d172338a
CRC32 08A7D23B
ssdeep 3:ydOxqJEW2tQ2MWcER1R6V/wdBdQLV2ecX:pztXMEMV/ocgecX
Yara None matched
VirusTotal Search for analysis
Name 6461832b479a1dc7_@wanadecryptor@.exe.lnk
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\@WanaDecryptor@.exe.lnk
Size 953.0B
Processes 2980 (cscript.exe)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Sun Jun 18 22:16:36 2023, mtime=Sun Jun 18 22:16:36 2023, atime=Thu May 11 08:22:56 2017, length=245760, window=hide
MD5 07c2b5aa06814392cdf7a8f9278f57e5
SHA1 80d7a62afdb4545516ede57e8b16d694d3c77feb
SHA256 6461832b479a1dc75804cba166293e12b44d0f86ba64864f663d801c726e0fde
CRC32 FD471380
ssdeep 12:8RXeX04cZCrR8EvSWMlR+/HJrc7DCzUoPizCCOLM/2o0awua4t2YLEPKzlX8yhdN:8UlsERdglR+c7DNzNR/96PytdN
Yara
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name c2fdf09647a3bace_en_nz.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_nz.msg.wncry
Size 584.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 cf19f2516ce6c7466916681da504f0b2
SHA1 a3320d68ae437bf1015d48265bafd689539edbdf
SHA256 c2fdf09647a3bace30cf2f417bcfdaab125de386e49483d416282c751b196c66
CRC32 58A5C2D1
ssdeep 12:bkEJhUP1fSfnMKfbZKOiMYPMZXF/ysITZRM+Ua4jp6Hkou8hlB/2r75zVoDFln:bkQUP160tC/Z4s+Rkn6EYhlBixCDTn
Yara None matched
VirusTotal Search for analysis
Name fff2f08a5be202c8_96.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\96.WNCRYT
Size 1.2KB
Type ASCII text
MD5 022cba4ff73cf18d63d1b0c11d058b5d
SHA1 8b2d0be1be354d639ec3373fe20a0f255e312ef6
SHA256 fff2f08a5be202c81e469e16d4de1f8a0c1cfe556cda063da071279f29314837
CRC32 2019DFDE
ssdeep 24:4azu8OJccwdQSBJr/S3tFA7C28/sF9AaD5rYrvtAvrG:46w3wdJB1/6FA22c49XrY7tWrG
Yara None matched
VirusTotal Search for analysis
Name c238df51bf8d9f5d_usertile37.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 cc8c03ba8764e73e4b079eb47da8c3f1
SHA1 2259f5c10142ac24613aa47c11550e7af8163846
SHA256 c238df51bf8d9f5d8c36081a83f31c1338cde73d3347b9ba6c7f62892e367a44
CRC32 7423119F
ssdeep 1536:Lu8qdRQb/ysG4m2/JApUwU04NKnIZ9pV4ogCS5cUQv:LuLdRQbKdn2xJwUDNKIKCAWv
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name f07e2973b1696b65_iso2022_kr.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\iso2022_kr.txt.wncry
Size 792.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 7bac95297566bcd7e7a3a60a38154939
SHA1 4d9a84b013d4e66c819c1520a5ac617b33fea664
SHA256 f07e2973b1696b659f04aed3c20dd8667a37de71abeabbf4c47502041f0cd168
CRC32 420970CE
ssdeep 24:bkqN6GkC8JxJHdJuWm6uxAkQrsgYpCTMeOpGu:bk7Glo9IHukQ9YQweOsu
Yara None matched
VirusTotal Search for analysis
Name 7099fac95fcb2433_requires.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\mouseinfo-0.1.3-py2.7.egg-info\requires.txt.wncry
Size 792.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 6ae5addbf8adce12255e06bcfc0418dc
SHA1 170bf8b5ce66beb2fef842296cc4dee52059a70a
SHA256 7099fac95fcb2433fb223d5ea72b4b6a35d04bdab8807c3a2823a85e34bde873
CRC32 C4C545B0
ssdeep 24:bkK42xl/fWZWAR94LgepandqogyxFM3H6:bkwfW4oeL6n9TFMX6
Yara None matched
VirusTotal Search for analysis
Name 419b5f32629b747a_usertile40.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 8850c1f63d9932bb2d8e957ed72d8fdf
SHA1 44271a436bed981ced2c5f3839733bbaa54dc8e3
SHA256 419b5f32629b747ac897aa66acf77ef2320d4f066470d616e21fd248a4a55f29
CRC32 AF8403A9
ssdeep 768:F/us2/jKGLrCOGLEayHtOSHDmUxzVUAar10LKX3Tnu2HY0ct377nnEZt7G:F/a/E4ayNOaDbne0ZDBV772G
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 6f984f67dbd368cd_43.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\43.WNCRYT
Size 55.3KB
Type ASCII text, with CRLF line terminators
MD5 1d069de731f56c3e525c3ca023d70616
SHA1 c788ec2fa95dc08dced3cd1d5b5ed19e9887826a
SHA256 6f984f67dbd368cd668942f0026dd9d59918ec9db7e81f0457892b878aade1d8
CRC32 B9979496
ssdeep 1536:bXPWf9rwQctWI3lWXHK3MvmQsJWdWuowWrzWZW0WKFepBnN4:buhcYI3lWXK3MvmQtIuotOMJ1pBnN4
Yara None matched
VirusTotal Search for analysis
Name a932fd307c4bdc22_546.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\546.WNCRYT
Size 85.0B
Type GIF image data, version 89a, 14 x 11
MD5 5a07aca97e595cda407bdb8a2eb380f5
SHA1 db0b01d62178cb54bd97e8b76e0be4ceb8c6f9c1
SHA256 a932fd307c4bdc223ae39165f413b2a530b2dbf6323e8a272865da6627535ea3
CRC32 09B50EB6
ssdeep 3:CJX1lJ4lYF1eTtDdDjFXgiAvhxWe:ADJ4lYPepDdd/AvhxWe
Yara None matched
VirusTotal Search for analysis
Name ef8c6b34bc8b219f_zh.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\zh.msg.wncry
Size 3.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5d69b3cdcf2e5550a5093eb5e906734f
SHA1 3982a613ac0d5b8774891fbb503b6135582b3d8b
SHA256 ef8c6b34bc8b219fa967fc19cafa4599246a4612fb9d0b9af404dd49d946487e
CRC32 2257B5B7
ssdeep 48:bkoBL3ns449mRmjuPb05EXava97aLx0vSPp7FrfYWJ/bxNwyGtbMRLkxt6aqn90w:owkm0aXaASpBrfVdxcMY6aec+Q0
Yara None matched
VirusTotal Search for analysis
Name 4855ae49469c2c9a_705.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\705.WNCRYT
Size 180.0B
Type GIF image data, version 89a, 32 x 32
MD5 1dbc69e845ce84f1ea888039d8b1a221
SHA1 8512a535c25e9b91721e20fb19816c217f916dd1
SHA256 4855ae49469c2c9aa238564d41c57e75ccd4a391156b273a042096382cd3c732
CRC32 D0B6DB77
ssdeep 3:CsliXMcyltxlXlChh/U7KPhx3IpVl44fyNynfP7T2QQLwFlIeXn0EnjNth:NlI3hy7Iz4pVl8Ng7T2QQLEIIn0Ehth
Yara None matched
VirusTotal Search for analysis
Name 6c0eab186e3aeb04_it.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\it.msg.wncry
Size 3.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 37ee6bf7b9010187979b3f3dc0273d2b
SHA1 9d4fb671d33c3e1888433390007a2f1dc431115a
SHA256 6c0eab186e3aeb04d79a2b059b8c2e49113f4211f1b1087c3926a5269cafb206
CRC32 AD0C30D9
ssdeep 96:o8q9EfrGbsfiWdEwNKKwPw0um52CYu4HI5Uw:vDDGbsaWmwo26b5Uw
Yara None matched
VirusTotal Search for analysis
Name 82a80ffa2a595cb6_517.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\517.WNCRYT
Size 800.0B
Type ASCII text, with CRLF line terminators
MD5 502ccf6d5093e782f26b261f587911e3
SHA1 1506210a370a3de5205c266eec3cf7f5347af6a7
SHA256 82a80ffa2a595cb618a0d9f3896e586e24d67c1449d9300d618ae3b126be2676
CRC32 FE0BF4B1
ssdeep 24:aWdIleW+UtSzCF7fjFSVlJClJEVVlJylJyPlzat6Sd:aW3WPErLCL+VLyLyPJc
Yara None matched
VirusTotal Search for analysis
Name 8b4b8f276e552774_495.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\495.WNCRYT
Size 366.0B
Type C source, ASCII text, with CRLF line terminators
MD5 433edecd683ae8e834ff3cb5350b26f5
SHA1 cbb79295e6e6fc611f10ad55bda11126057f7fb7
SHA256 8b4b8f276e552774a4105e89b9eec3441646634a2442f3723ad1f92a435375d8
CRC32 FD4BB83A
ssdeep 6:mRreMtV2Q02tVmjQ6zvWJU9qWJYUW535yerOigKeMILkC6IxjQ6dnatFPD:mRreMtV2etV0AU9rYUg35yOxELJdatFr
Yara None matched
VirusTotal Search for analysis
Name c2d6b21e92b0f038_4ezdv0ho.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\4ezdv0ho.txt.wncry
Size 408.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 f6da9552fc7c49f4dc936e4ea353e3c0
SHA1 912dceb0e412beaab1e9e254b20eae60cdfdae45
SHA256 c2d6b21e92b0f038be5e256cca97e5b783236457b6e519459a384d7da7976099
CRC32 7AC18627
ssdeep 12:bkEa/Zx6sbQF/p2xX1AjiczR+O+X94U6O2g/v:bkL/TBQF/pi2jioEaUx5
Yara None matched
VirusTotal Search for analysis
Name 3477b6ad5eb14a20_curl-ca-bundle.crt.wncry
Submit file
Filepath c:\util\curl\curl-ca-bundle.crt.wncry
Size 217.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7e73db3f5b9f7bc270faf9874278ea2d
SHA1 0eaf0485dc2637082e4177f57df28b528d72da3b
SHA256 3477b6ad5eb14a20699c55cc630fb32d29966f487e2d0cff9199a95eadb8ca90
CRC32 C1C0CB39
ssdeep 6144:Gmxbs0v1TmKaj8rF3uVDqbygaxziTOy57OS2:PDv1Tm/jRRqaxziiypO1
Yara None matched
VirusTotal Search for analysis
Name 55f42499c4bddd85_714.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\714.WNCRYT
Size 4.0B
Type ASCII text, with no line terminators
MD5 cfc38c834ea57efaa322e245c856a5e3
SHA1 81a126ecfc4f6034c6972742a94d00fea78c2899
SHA256 55f42499c4bddd857daef89d3bf40042a779f222d883135536ee440afa7aa5e5
CRC32 A1AD1F3B
ssdeep 3:N:N
Yara None matched
VirusTotal Search for analysis
Name 2e6c724b2aae1602_usertile18.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 1ef0b094eb051cfc99e3dfa991c669c5
SHA1 2534e234cbed0ccd69f53208069686ec5c617ccb
SHA256 2e6c724b2aae160291a7df88d394514535171833eba1dd20204f9d5788f0f878
CRC32 AA8A02BB
ssdeep 1536:cFl/AXwgyNjTmrc0SNe9Qb63dAqHcg0C4opYbXz9fPm6Hj/H11a/8eseHPMhx75h:cFOgxX0MVhBCPfZDg
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 208aa0dbe74a1276_gbk.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\gbk.txt.wncry
Size 1.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fa7ff61449b95a3e6bc9838fac3e409d
SHA1 9176924bcee286e656640e76e7408aa440a2ef3b
SHA256 208aa0dbe74a12760602a88d53b0b3e9bfe402093c4a34aae9a840c89e37bc32
CRC32 103FD723
ssdeep 24:bkKaOSzN0b5yuZHFh7XtiL9gRW9cmjPwtk9gWfalmDn:bkGSpucu1F9XtgqmjPw2iWf4mDn
Yara None matched
VirusTotal Search for analysis
Name 3c2f5f631ed3603e_622.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\622.WNCRYT
Size 251.0B
Type ASCII text
MD5 27c356df1bed4b22dfa55835115be082
SHA1 677394df81cdbaf3d3e735f4977153bb5c81b1a6
SHA256 3c2f5f631ed3603ef0d5bcb31c51b2353c5c27839c806a036f3b7007af7f3de8
CRC32 BF9E61A7
ssdeep 6:SlSyEtJLlpuoo6dmouFygvNLouFqF3v6aZouFy9+3vR6HK:4EnLzu8YAgvNTYF3v6axAI3voq
Yara None matched
VirusTotal Search for analysis
Name 1a36e5558bc153b5_405.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\405.WNCRYT
Size 3.8KB
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 a846d750fc133506b54053ec4a90a395
SHA1 827b02e1ed08b21440aef7d2830d534409fb2868
SHA256 1a36e5558bc153b557b31507acec141c42f376390b2b78b9131efd01c9ad639c
CRC32 6B7DB013
ssdeep 96:XDxlfH5vo+XkLW+jKXmuYFTfXfVb+WcaA:llfH5vo+0B6wZX9qWc3
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name f6e2b0d116d2c9ac_111.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\111.WNCRYT
Size 1.5KB
Type ASCII text
MD5 a4c37af81fc4aa6003226a95539546c1
SHA1 a18a7361783896c691bd5be8b3a1fccccb015f43
SHA256 f6e2b0d116d2c9ac90dda430b6892371d87a4ecfb6955318978ed6f6e9d546a6
CRC32 AA947D3F
ssdeep 24:4azu8cVBfHVnYgY+YGkYeY02Y7YkMXjDHMXjqKKyvtuvFd8vUPvwEq:46ojlmpYEY7XjDsXj+0t4zaU3wt
Yara None matched
VirusTotal Search for analysis
Name 47231b4b6b6c2e4d_3.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\3.WNCRYT
Size 31.3KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 4ebf872b896afbe49369b0625b4c25f6
SHA1 aa9683b03e0016f1b47e14ddafe72976d78d2b40
SHA256 47231b4b6b6c2e4de82330d93991817a139603f368e73919225ba5eaa1c13841
CRC32 DF24A8DC
ssdeep 768:VGkRk1yearoEvJJkO4AHV6K+UXK5bQD5Tw:ta1yearnJGOTDXYbce
Yara None matched
VirusTotal Search for analysis
Name 89361a1c4b1388f9_nxala68k.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\nxala68k.txt.wncry
Size 424.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 55a721f0329e1a53e4d23f10b7270232
SHA1 a17d0228835238d3078304d6b187f620bc109ff1
SHA256 89361a1c4b1388f9ea76aefb9cc0c944928ae6370399b425bc794f7531464c7a
CRC32 B7A290E9
ssdeep 12:bkEpjrNONsz7I6JPjeV0ClJ5rYHobzTV/9u7a9k:bkkfcNYE6JyV0CT5rYIb/V/I7Qk
Yara None matched
VirusTotal Search for analysis
Name e96031499df7b1ea_sources.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyperclip-1.8.0-py2.7.egg-info\sources.txt.wncry
Size 600.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b8083cc256511064161e38652911276f
SHA1 9c23b2b587aa7360f971f0399ae7d19517baa7e8
SHA256 e96031499df7b1ea75694c1f07c45b48c8de6b224dc91767ba85365b690648e6
CRC32 1CF68329
ssdeep 12:bkEqkKFt1n3fjHrdUUYaGagmJibst1H2zKLTSvFoeJplAvOODJSWm:bkYQPjHpULXag64WH2zKL/edaOODLm
Yara None matched
VirusTotal Search for analysis
Name edb421b4ee6cc8e9_618.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\618.WNCRYT
Size 610.0B
Type GIF image data, version 89a, 16 x 16
MD5 d5d8eb13dcc0f4a1400f90c3d0be67ad
SHA1 fee60635ce8a277d5c47e06bb9bafe074d939fb0
SHA256 edb421b4ee6cc8e9ffc0b719b31279ae4bb8821f52a19e8f32ad77d4aca3e51e
CRC32 06A290C9
ssdeep 12:dzDB+3fcNKXO5cCZDKFuBgJRvbhktdSXr:dcUNKXO1KFFkder
Yara None matched
VirusTotal Search for analysis
Name 6319a9453b3cf649_256.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\256.WNCRYT
Size 14.4KB
Type C source, ASCII text, with CRLF line terminators
MD5 1d675dedbc7daefa700780fa2121701b
SHA1 728c17248f4750d8fc3246463b6e17dd7e8ea737
SHA256 6319a9453b3cf649870b849574063cb4327bac1f61b397dd521d314ac64d4856
CRC32 A096BB2E
ssdeep 384:RWIqYVwvJTKLbho7xg+vVm2T5daiVIxKi:ZiJTKLbho7G2Ndqxl
Yara None matched
VirusTotal Search for analysis
Name a7b6bde29d8a8834_175.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\175.WNCRYT
Size 19.7KB
Type XML 1.0 document, Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 245aacc44318defe09e516ed07a98483
SHA1 17d163fe7ef776ff75d36a3941d4fba3d157c767
SHA256 a7b6bde29d8a88341947c1ab6d4b469bcd4e9b3cc2bb01a01b6f158f4af75e41
CRC32 BF5E0156
ssdeep 384:o0arauaqaZOFkWcdcwhJpKpdPcaTak6FjvRaGaHA3N0b6YaWo:o0arauaqaZqkWcdcwLpKpdPcaTafjvRL
Yara None matched
VirusTotal Search for analysis
Name 9c6388a80150ec70_259.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\259.WNCRYT
Size 1.8KB
Type C source, ASCII text, with CRLF line terminators
MD5 92711bbef70342a697a4f748079ebffe
SHA1 e6157486159b3580b0711f36246911bdb893b56d
SHA256 9c6388a80150ec7022a93e637151e55b87d78eeb5d76705ee7733975986e1b08
CRC32 226FC382
ssdeep 24:ifx35f8fyJrXJflCyJlk8caNccFNClLsL8clKsLLho59:i35f8Mj9hnNc0NQsQzs4
Yara None matched
VirusTotal Search for analysis
Name 43cb0abceafb0243_wmxfdlmbat.doc.wncry
Submit file
Filepath c:\users\test22\documents\wmxfdlmbat.doc.wncry
Size 341.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 da2377e9090a1c6bd62f3ae2e63f2a6f
SHA1 aa01940b4ca39381222839be4013211b16725f3a
SHA256 43cb0abceafb0243a85f9913df4172335332dc04a6151c242bb71a43735523b6
CRC32 E57E7205
ssdeep 6144:76uKQtbMn5fK6KGNLUeThHe8mzVuUnMNdWS+8VH3irRLRI+M3foGVVf:7AQ+5SUUed4zVu+mwBY+M3jf
Yara None matched
VirusTotal Search for analysis
Name 7aed2adcdaceeab0_enterww.cab.wncry
Submit file
Filepath c:\msocache\all users\{90120000-0030-0000-0000-0000000ff1ce}-c\enterww.cab.wncry
Size 128.0MB
Processes 2632 (WannaCry.exe)
Type data
MD5 c07ecd0683c6c710ce4d7747f17a68b5
SHA1 9b208eb45185ee750727c0acd001ef4e193e16ec
SHA256 a4cda0f84046d4abf72ba792a8028c65bd12c198bba3a451b661eb4e9c570bf3
CRC32 343AD81D
ssdeep 3145728:vfv2H67X6eMWkGRRJVXvDBn/oMZy1eCn4utou6hYs:Xv2H6b6WkMVX5Kwk6h9
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
VirusTotal Search for analysis
Name de570ff1c3c232b0_ms_my.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ms_my.msg.wncry
Size 552.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 4f3d3c23e70fb2a910a61963df991930
SHA1 de294adb1ddd668b66fbb57b613e40bbf08f6d7f
SHA256 de570ff1c3c232b02a87c7117883f8b5225a28331df5546104c1e0a484aef45e
CRC32 E128A739
ssdeep 12:bkEYJS4fOAaalb1ABevJrHffB7wDH0yQf+H0j5Dhdq7n:bkXSn7aPLvJrBA0h+UuT
Yara None matched
VirusTotal Search for analysis
Name 970a6e750bccef9d_00000000.res
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\00000000.res
Size 136.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 2644344828a32ffe111fcf219e0beaab
SHA1 07f60cce6ad8e34da90a48674e7460e520979c4c
SHA256 970a6e750bccef9d3e1f5a02f8f0c94717bef1a1b1afde48ea4f0c54d544be3f
CRC32 137ED0EF
ssdeep 3:/Wl//bl/ll0ll7/:/R/
Yara None matched
VirusTotal Search for analysis
Name fb5f94593a1c0b5a_idle_48.gif.wncry
Submit file
Filepath c:\python27\lib\idlelib\icons\idle_48.gif.wncry
Size 1.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fab142f3d971a6488c4ce6fc47c25d98
SHA1 dc3c9c388679f2096034e3714a287beaafa5fd86
SHA256 fb5f94593a1c0b5a95ce0b6ccfcb9497108f1037c530fc7cdc93e41b16fea912
CRC32 B9D381B4
ssdeep 48:bkolo+2U85OCVIoibFy18HPBvwUplfr/aY72S:oZ5UWIo0vHPWUpFr/tJ
Yara None matched
VirusTotal Search for analysis
Name 5e66725073ff7ba6_580.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\580.WNCRYT
Size 419.0B
Type ASCII text
MD5 163c23b413d73d51235a89553a8bfcb0
SHA1 9a552eca38dda549d222e2c544d7537d016d80ee
SHA256 5e66725073ff7ba6e948b18d9f31941c7312e4a79b8266851818ccbeef9a0c91
CRC32 409DE11D
ssdeep 12:mv70QRiWomN8AFe0heaycTJack1snpakVJ:Y70QRDJN8AFe0heahJc1snpakb
Yara None matched
VirusTotal Search for analysis
Name 1bcf8774864a012d_msg_28.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_28.txt.wncry
Size 696.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 38cbb8a728458a6aee4b73a5afa90183
SHA1 2916159b75b78d158c1b994d9a4bda27d788ec20
SHA256 1bcf8774864a012de31cdbf7f7f094f9d523d9fc647159527fd851c5771be50d
CRC32 161DEA43
ssdeep 12:bkEgGOyj9nWMXSFyiQbmKjkJxIygisHVIHdgf4Ze7pDQbdaE4rGoqxuMdBv1KDVa:bk0JAMCFybmKjTywVE6hk0EiGoqxXuVa
Yara None matched
VirusTotal Search for analysis
Name 469c8a7bbca8a67f_485.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\485.WNCRYT
Size 270.0B
Type C source, ASCII text, with CRLF line terminators
MD5 ef325605b8543385361518b5851c081c
SHA1 e5547aaf812f76add841c4dd473ef6b87f9bf5d3
SHA256 469c8a7bbca8a67fd17bc728a1d6d4225c4c0566475774b5deb655462f058659
CRC32 D2F31404
ssdeep 3:YkLko+6P2Q0Pjo+6h8FOQI28AGRKmGjQ6QMtZb6TzJ581iHe7YJ581DFEvGHGjQc:BD2Q0u8Ad2xjQ6z3ueBhG5jQ6dKQ
Yara None matched
VirusTotal Search for analysis
Name 043dece6ea7c8395_125.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\125.WNCRYT
Size 1.2KB
Type ASCII text
MD5 b2ef88014d274c8001b36739f5f566ce
SHA1 1044145c1714fd44d008b13a31bc778dfbe47950
SHA256 043dece6ea7c83956b3300b95f8a0e92badaa8fc29d6c510706649d1d810679a
CRC32 0F93CBBD
ssdeep 24:4azu834j4PV3sSAT3fk3TEJbAT3T1cPyF3eYuCvte/v3eG:46TUG3sPk3TEkcPyFpuEtenJ
Yara None matched
VirusTotal Search for analysis
Name 4430dc574d252abd_288.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\288.WNCRYT
Size 2.2KB
Type C source, ASCII text, with CRLF line terminators
MD5 e0d7549517d1cd8db7861df726566912
SHA1 9dc74542a73775a67d53368d63a766c38d2c69fc
SHA256 4430dc574d252abd7cc44f1383385d23b8df24a67ea34341197aba5f4eed01d9
CRC32 21582F24
ssdeep 48:3BHRKMYYbQL7CSMs99yr2+CkXEIeadYXBupJYcM:rKMHsXcXEgdW2lM
Yara None matched
VirusTotal Search for analysis
Name ab670ae5efb052eb_traceback.h.wncry
Submit file
Filepath c:\python27\include\traceback.h.wncry
Size 1016.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 54cb20efd7c71501571fa185bd75ae1c
SHA1 e1d1ef65ea210f80f41110bdab3cb239c9371368
SHA256 ab670ae5efb052ebbca97627af2e9e8e5010c3032d36fb1162e8388607a2138f
CRC32 3A983342
ssdeep 24:bkcFg3gflbqZrD0dKshwG9a/V3OLbtb7UTrx/dPjWjjOBBJFAQ:bkciuqZkdKsh10eLbtb7UTrxVrYXQ
Yara None matched
VirusTotal Search for analysis
Name 3e49b58ff60f1bcf_timefuncs.h.wncry
Submit file
Filepath c:\python27\include\timefuncs.h.wncry
Size 856.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b13fc0f7af44b352a05aa9f267e44b81
SHA1 251cc8efdb7b6fc9a15a15cee0758f1fc05f7431
SHA256 3e49b58ff60f1bcffc50e5259cd2ac20e5175f36cd3a9a96035969074926a526
CRC32 5C66E7E4
ssdeep 24:bkgdjp1aX5a0ce5S6E0qSUEvzsxj0w3HX0nYKHuTuG:bkgdjp1CaZe5SxNSdQJh
Yara None matched
VirusTotal Search for analysis
Name 7e34e5b527c6c5c6_tk.cs.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\pref\tk.cs.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 066a93e9d589552ae7b6d677c0ab731a
SHA1 5f5bf7ddc9f59ce86bb35eccfc5a79967602459b
SHA256 7e34e5b527c6c5c65a49dfcb790c4e78941af3f7c884cd24e624d5b23b7a8295
CRC32 F0B89CC4
ssdeep 24:bk2XccAZmoB0fG55x8VxJh3bu1Xq4FeD2KfjWXOhIzUyc1znoaBMrqNjm1r:bkxxZm48nfbEq4Fi2KbqOh8tIznoa6+O
Yara None matched
VirusTotal Search for analysis
Name 1da030c58811244f_dependency_links.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyscreeze-0.1.26-py2.7.egg-info\dependency_links.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 654fcc1ea46f5a4c668e78e39ca9fb18
SHA1 0dd970e6b487b50d2e976561dbb1e32b1ed82d7e
SHA256 1da030c58811244fd208c500272a61d6d88d776495cea7192f009d66dce43e5d
CRC32 66ACD8BF
ssdeep 6:bkEfZUeUtKBfnjp0TOgOc96/GGvoSbfeV7cpolxBZ50CWf9UjwXlwD2ESxRC8:bkEfZUWpjpqOgQ/eks7tnBZ5fEyjrCEa
Yara None matched
VirusTotal Search for analysis
Name b9352f2565260219_173.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\173.WNCRYT
Size 606.3KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, datetime=2009:03:12 13:48:39], baseline, precision 8, 1024x768, frames 3
MD5 fafa5efeaf3cbe3b23b2748d13e629a1
SHA1 54c2f1a1eb6f12d681a5c7078421a5500cee02ad
SHA256 b9352f2565260219db72fc1fc896113a26c85866b69c50d3970c4d9f5cce830a
CRC32 595E4C28
ssdeep 12288:bIjmBzE+CEKDmyQVZrgnnFq4DRWQcCuP6lr9Fg4naJU:8jGnKDm6nFqWe9ilr9Fg4naJU
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 9396df7a35586f57_459.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\459.WNCRYT
Size 12.5KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 0f100d29ce549efdd7576eede57de386
SHA1 2fba78b44d78d8545bbd8efde327bb89b0ae6fce
SHA256 9396df7a35586f572b4467adb47c38a9df45f618171fcf1a310cf5b9ba76b3ba
CRC32 55F1B7AD
ssdeep 192:RaniqRcDMfdaWaT7A7pKPuFXJrFFw8AxSqCFO:nydJnwtmO
Yara None matched
VirusTotal Search for analysis
Name 5da350176d134650_pystate.h.wncry
Submit file
Filepath c:\python27\include\pystate.h.wncry
Size 6.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6e38b2f10125aaf1946a7f16cb6f01e0
SHA1 6b776cd910696b4afec9a1928d6a5f5f4a29f238
SHA256 5da350176d134650b6105f53d74289d3ef730223a77cbaab230bba99b45f3455
CRC32 613AC132
ssdeep 192:LCI2zFQrBW7fJ88T5iAO++YU2PhNd+bhW1wuHC:LZ8ToAO++yhNdA3
Yara None matched
VirusTotal Search for analysis
Name acae7e763802fded_471.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\471.WNCRYT
Size 503.0B
Type PNG image data, 35 x 21, 8-bit/color RGBA, non-interlaced
MD5 476898d9e9a8eeb0be7c7c8851b1324b
SHA1 630ab41a35b21f5ede03f867db14bcdbed831bb3
SHA256 acae7e763802fded633028422fbb8d0ec288938038aa9726cbeea311874f348b
CRC32 07082FB4
ssdeep 12:6v/7sK/f3M/s7RCVCeuxMeCckzyEMwFMT6992WiM8N:JQf9RkrutCckzdVFME92WiM8N
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 78116e7e706c7d1e_83.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\83.WNCRYT
Size 1.8KB
Type ASCII text
MD5 4338bd4f064a6cdc5bfed2d90b55d4e8
SHA1 709717bb1f62a71e94d61056a70660c6a03b48ae
SHA256 78116e7e706c7d1e3e7446094709819fb39a50c2a2302f92d6a498e06ed4a31b
CRC32 62CB7AA2
ssdeep 24:4azu8J5Fe6k+wR+9Gb+Oa+UcP+wR+9Gb+Oa+UD:46I6CNbtdNbQ
Yara None matched
VirusTotal Search for analysis
Name a045181ce68489f4_gv.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\gv.msg.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 cac10acea04defdd89d36757dffa1576
SHA1 1c95fca49d8167e25ed80c8b64a1445736211f28
SHA256 a045181ce68489f46b6bc354c45ae6af2cf86b110d3964424ba8a9cd7a70a7be
CRC32 2415FE55
ssdeep 24:bkbuGIX6+XH3JeOS2E4Ch0bxM+QCVqUj/VQyPNwZRTsbefz3GTu0ZD8ZZYPi:bkbuGH+33EV4CKb7Q8qwdifzWyeVK
Yara None matched
VirusTotal Search for analysis
Name 43ca32980fe32e42_ffdh3072.pem.wncry
Submit file
Filepath c:\python27\lib\test\ffdh3072.pem.wncry
Size 2.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8e5d809b4ca071b771d02d6bda83a26e
SHA1 09bb2692c5a93dfea03981077f820b7c8fe00b23
SHA256 43ca32980fe32e42b8c83e6ba61799ef34ded2ea98a80d25a3a4daa997abd0d3
CRC32 80FECD43
ssdeep 48:bks6oIqhz0FdI7rRwxkhqCFcGUxi2JgBDEcaOFmIR2KQdzn1O+SKY/BN60nVr:osBudIPXfy9i26EOrQdxO+SS0nF
Yara None matched
VirusTotal Search for analysis
Name 9c69094c0bd52d5a_135.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\135.WNCRYT
Size 1.4KB
Type ASCII text
MD5 3bd0ab95976d1b80a30547e4b23fd595
SHA1 b3e5dc095973e46d8808326b2a1fc45046b5267f
SHA256 9c69094c0bd52d5ae8448431574eae8ee4be31ec2e8602366df6c6bf4bc89a58
CRC32 2F19DD12
ssdeep 24:4azu8pNu9UT5xDHy2W82yGWnf/oxHFBSWWS1D/avSv16:46Oixzy2IyhwZ17cU16
Yara None matched
VirusTotal Search for analysis
Name 257aec1add4a3c34_greenbubbles.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\greenbubbles.jpg.wncry
Size 6.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 81733491b15b42d249f5de512edae3d9
SHA1 e1ca682ef866a3dcb176939f9f344ea2d86f36b8
SHA256 257aec1add4a3c34ab874bc7bb2fde26fc0547ee4225d37c83e4e26b696ca07a
CRC32 1DACDB6C
ssdeep 192:g7insdd6p5WNfsvMeJWnwnmJuG2G+ii0g:hm6pXvMeAwnmJy7t
Yara None matched
VirusTotal Search for analysis
Name bd70ba5983169808_ssleay32.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\TaskData\Tor\ssleay32.dll
Size 694.8KB
Processes 152 (@WanaDecryptor@.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 a12c2040f6fddd34e7acb42f18dd6bdc
SHA1 d7db49f1a9870a4f52e1f31812938fdea89e9444
SHA256 bd70ba598316980833f78b05f7eeaef3e0f811a7c64196bf80901d155cb647c1
CRC32 6C5192DD
ssdeep 12288:hXhKnXI0Fkw80VEJtzwIA6Ouah6ESyrWlp36Z:thKnnkw80VEJtzwIAiazSxlFw
Yara
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 01decb095b92b20a_tupleobject.h.wncry
Submit file
Filepath c:\python27\include\tupleobject.h.wncry
Size 2.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 04fce06b9e62e1d17620ba1462b6d78c
SHA1 0fd0d5f1060aedaa66035fdb17b2c9d9da70a275
SHA256 01decb095b92b20a09a9cfa84aa77d89d7f3a83c81ba4482e3cea12e8a26afdf
CRC32 1661C5B3
ssdeep 48:bkZUTOa1GKx4OD6LR0bWmk/8WJSoGIyqRc4JCV6nWL9Jw3L6r6s+iQKr:oZ2Oa1GKGOSuFvySoGIHRc4JC0nWL9Mq
Yara None matched
VirusTotal Search for analysis
Name b3de971f88cdd821_usertile11.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 5861d4e6983be2b92122bcfb7d239eb5
SHA1 892a1af54e23a9960f63eae6369c526ef325b77c
SHA256 b3de971f88cdd8219cd9bf4a1212107b4052f468caac1f196d756ddf095acb48
CRC32 DB5AEB30
ssdeep 1536:lWOjL0MSj6GNG5dWgFk1w/NwWoc4ZiIK66a:IOjLyPM/WgK1IwWoc44N66a
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 24b58de38cd4cb2a_640.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\640.WNCRYT
Size 251.0B
Type ASCII text
MD5 4c2b2a6fbc6b514ea09aa9ef98834f17
SHA1 853ffcbb9a2253b7dc2b82c2bfc3b132500f7a9d
SHA256 24b58de38cd4cb2abd08d1eda6c9454ffde7ed1a33367b457d7702434a0a55ee
CRC32 B5DED039
ssdeep 6:SlSyEtJLlpuoo6dmoYePWHFLoU3v6rZoY7+3vPUe6HK:4EnLzu8OegFp3v6rHS3vs3q
Yara None matched
VirusTotal Search for analysis
Name a99513891fd98dab_msg_27.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_27.txt.wncry
Size 888.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b76a0ccba7e2dfde1e5b5db111f03b17
SHA1 55736cd155e62190a17188fe26b837f4b9d5ae25
SHA256 a99513891fd98dabfba0dfc2c40de0c8ff000b4cf102f6b64d46e0483c757598
CRC32 867CCB1C
ssdeep 12:bkEImRrBsPbIO66QbXomoadYsp2vycphYWoAY2YJkfzZsLQGnMQQORbTHgIPVH3k:bkM+JMomdp2RhiAlbZyMQrbTH1tiQYv
Yara None matched
VirusTotal Search for analysis
Name 72c80a8d5951a729_wmdefault.cs.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\pref\wmdefault.cs.wncry
Size 1.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 33b15317fe74cf7b20e646bebfa39f2c
SHA1 a93ada9fc2dbd9da2503396f03fa519b4ea53501
SHA256 72c80a8d5951a7294e15a30bee060b00a44e54d6e8b569945214e9b2ab9dfa00
CRC32 5E3C0F05
ssdeep 48:bkkIcnQSavNV2gvmjy/rZNwY6kWx61Aer:orcnQSavNMgqyzTa613r
Yara None matched
VirusTotal Search for analysis
Name ab160bfdeb5c3adf_664.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\664.WNCRYT
Size 281.0B
Type ASCII text
MD5 8b27eff0d45f536852e7a819500b7f93
SHA1 caed7d4334bad8be586a1aeee270fb6913a03512
SHA256 ab160bfdeb5c3adf071e01c78312a81ee4223bbf5470ab880972bbf5965291f3
CRC32 21DCE241
ssdeep 6:SlSyEtJLlpuoo6dmoFt2poF+3vG5oF+3v6X5o++3vnFDoAov:4EnLzu8btn+3vB+3v6+3v9dy
Yara None matched
VirusTotal Search for analysis
Name 1f8be68fb25f66d0_393.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\393.WNCRYT
Size 188.9KB
Type TIM image, Pixel at (27035,38502) Size=35115x459
MD5 dbd4f820d42b0d9f6592212a66716203
SHA1 5ef6f88cde3764b88367984b59ec31c0fec89bf1
SHA256 1f8be68fb25f66d01ecfe27305769b0747c9a04f2eb745e543ea728c620f90bb
CRC32 2ED3C7D4
ssdeep 1536:fx8K0D3uhiu6w2P4/4sY2Weg8D8nI42Js5Z4667iYuDo9:fx8K0D3uhiu6w2P4/F42Js5vah
Yara None matched
VirusTotal Search for analysis
Name 22326779f5599fe8_usertile44.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 44840b46ae11971c62f6ea59273bad91
SHA1 79477b9308b0fb13e7c274c4b8f06f7c36a91543
SHA256 22326779f5599fe87151ac35ba694b47322eb990967d7b22c4a45194ff53e08a
CRC32 21FDEFB7
ssdeep 1536:tN5MNELaTghEwCDekzvOqi1w377cwWz/9XQw90MW:H5d+TQCjzWqx77cwYLm
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name b007a8c582991388_696.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\696.WNCRYT
Size 159.0B
Type GIF image data, version 89a, 32 x 32
MD5 d158bf37409498d7c94eafc092942faf
SHA1 07d1f4a0c2dbd1a9dd7a6af2957ced47126b3e18
SHA256 b007a8c582991388b12891a8b46445de6809ef6d52aaa43bf8d946ac8f9f6d43
CRC32 8F385386
ssdeep 3:Csl1/PQE/xlXlyW2+qfUzZ4xd8qyG3QWOoAyUpbmbvSVvLrlBdi1en:NlNQEETcud7yH/yfbvYlBr
Yara None matched
VirusTotal Search for analysis
Name a2658f63cec805a0_nl.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\nl.msg.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 10d8dd9b4d67850de86b5027838d53ec
SHA1 e26dd4f33ccc5ed4d7fecb933c4ee233131b0b1d
SHA256 a2658f63cec805a06fe301f1e3b6573874db79ad1a65a3c1f5fb5638f89000e3
CRC32 BD097B22
ssdeep 24:bktz3wOxqAfN8V6CicobuQfEaK4Ba1GwTHN0NxZTLHxzXoBgh:bktz3TxnV8V6lEtlrwwTHN0NxxLFD
Yara None matched
VirusTotal Search for analysis
Name 0a5963362ff83a50_common.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\common.js.wncry
Size 36.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7810c1594e09ba5097b7901f8510336c
SHA1 09a48c234620cc971743b17bc99e41b0b257ccdb
SHA256 0a5963362ff83a508900b1105351219a2c86c8f13d2662c79eba2a395b654b2e
CRC32 B90A6E24
ssdeep 768:JLaMYkNA+tUaqwwRf76auhiYbV2Lp0ghXsykrmES3XLLDr:91NAqLh73pbVWjhZvzXvDr
Yara None matched
VirusTotal Search for analysis
Name ec0583072ecbccff_es_co.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_co.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 7b92036bd2c1b3d25abf2b7b3062bf13
SHA1 38e558a0c503959529629b25d01f605b29ac98b3
SHA256 ec0583072ecbccffb53b27c6d2e179bd81d9f44be15f548ecfab488e34aaac3f
CRC32 45F72CA3
ssdeep 12:bkEopyAMu5t0dw2kkU4sLFETJ4tu5qw7qY6e2crEuvgpL:bkly80dwFk7sLYAu5P7nrEuvK
Yara None matched
VirusTotal Search for analysis
Name 1d16b2a1c76cabc6_8.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\8.WNCRYT
Size 954.0KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 9e963532376b9759b2a7187c73208e74
SHA1 56333166221ffa496773c866ca8e701bc343a067
SHA256 1d16b2a1c76cabc6b242f62caecf7bf1e4e73872b4bde25e9d453d0078211085
CRC32 201377F3
ssdeep 24576:aUmet5c/2Tr/Umet5c/2Tr/Umet5c/2Tr/Umet5c/2l:aUmevc6zUmevc6zUmevc6zUmevc6
Yara None matched
VirusTotal Search for analysis
Name 0b4c939dfde52a04_552.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\552.WNCRYT
Size 276.0B
Type ASCII text
MD5 91d3af0cb115e7288660dcdc74827ccf
SHA1 4dc9f8f4914d4bffa4dd58d05bc63c86b2797e93
SHA256 0b4c939dfde52a04b8ba6f28bd166c2c1254bc0b518549cb778ac1a9660537b5
CRC32 51C8AFFB
ssdeep 6:1qQQ0QNWkLWiLWuRkLWMEZJ4LWERgLWvuqonc4Hqoje:1A0Q16MCAw
Yara None matched
VirusTotal Search for analysis
Name 45c8c085a131385f_mirroring_hangouts.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\mirroring_hangouts.js.wncry
Size 627.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 89304a373aee79e883e9324fd891a5a9
SHA1 72491853fc5acfe832ba21bfb5e9c1c3ec67d7ff
SHA256 45c8c085a131385fd6f91e0093ea7736eeb60eb0390e30ee1474eb86c2933405
CRC32 D01ACC33
ssdeep 12288:IJFJPQgbZr9Y+nTWcoyCIo1DOx+Ms3u62Nm0dQHxIhrWn:IFQg1pYKTTvobMYH2Y0dQarWn
Yara None matched
VirusTotal Search for analysis
Name 6832dc5ab9f61088_650.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\650.WNCRYT
Size 251.0B
Type ASCII text
MD5 148626186a258e58851cc0a714b4cfd6
SHA1 7f14d46f66d8a94a493702dcde7a50c1d71774b2
SHA256 6832dc5ab9f610883784cf702691fcf16850651bc1c6a77a0efa81f43bc509ac
CRC32 04C86A45
ssdeep 6:SlSyEtJLlpuoo6dmoX5rQZnFLoHE3v6rZoXa+3vrQZg6HK:4EnLzu8vkZF93v6rm3vkrq
Yara None matched
VirusTotal Search for analysis
Name dc4cd077da8b17ab_593.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\593.WNCRYT
Size 331.0B
Type UTF-8 Unicode text, with CRLF line terminators
MD5 5527c818b331b9b7e7a8b74fd8f7111a
SHA1 41edcbea9422e6face7906542fcab255c6cd1b9b
SHA256 dc4cd077da8b17ab75fb50c8cf8df6e4b868e51557ab60dff3e2705c1434f0df
CRC32 141C3D53
ssdeep 6:hum8cmx85PbFDqIJ4LiyOR/KN00yivCLr+huvcCcsGkWkP0rvmCy:humExa+my2+fJCP+huz4ruCy
Yara None matched
VirusTotal Search for analysis
Name ceebae7b8927a322_556.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\556.WNCRYT
Size 4.0B
Type ASCII text
MD5 365c9bfeb7d89244f2ce01c1de44cb85
SHA1 d7a03141d5d6b1e88b6b59ef08b6681df212c599
SHA256 ceebae7b8927a3227e5303cf5e0f1f7b34bb542ad7250ac03fbcde36ec2f1508
CRC32 C2971FC7
ssdeep 3:Mn:M
Yara None matched
VirusTotal Search for analysis
Name 402751fa49e0cb68_r.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\r.wnry
Size 864.0B
Processes 2632 (WannaCry.exe)
Type ASCII text, with CRLF line terminators
MD5 3e0020fc529b1c2a061016dd2469ba96
SHA1 c3a91c22b63f6fe709e7c29cafb29a2ee83e6ade
SHA256 402751fa49e0cb68fe052cb3db87b05e71c1d950984d339940cf6b29409f2a7c
CRC32 6374CC8F
ssdeep 24:ptrPzDVR5Gi3OzGm0Ei5bnBR7brW8PNAi0eEprY+Ai75wRZce/:DZD36W5/vWmMo+m
Yara None matched
VirusTotal Search for analysis
Name cb27007e138315b0_127.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\127.WNCRYT
Size 1.2KB
Type ASCII text
MD5 931a009f7e8a376972de22ad5670ec88
SHA1 44aef01f568250851099baa8a536fbbacd3debbb
SHA256 cb27007e138315b064576c17931280cfe6e6929efc3dafd7171713d204cfc3bf
CRC32 09C829E9
ssdeep 24:4azu82qJw7W5wO6jwbNU7FtHhoJCLov4v2:46iWrvGtBo6+O2
Yara None matched
VirusTotal Search for analysis
Name b3481a5a2f512f96_zh_sg.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\zh_sg.msg.wncry
Size 632.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 bb87c49f8a146c2cfce2e67fba0b1f89
SHA1 47f8d73a4a83723ad39073b8bc0721ac917f6463
SHA256 b3481a5a2f512f969451d49dd5e50dce138290ed317832e32bacc5af0b147560
CRC32 F252034B
ssdeep 12:bkEqtei2cHGyZoxee9lVbrk6EhzQco9nZgmVgXchCeLw7cUGZeVD:bk5VH5oMIlVP2h0n9nPichCeLwFGaD
Yara None matched
VirusTotal Search for analysis
Name ace4390f4d5625a8_minus.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\minus.gif.wncry
Size 344.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 843b2e13fd284b002f984c053b5014c4
SHA1 cbb79f5111b47d419b63ed20163573afb2b0b5e2
SHA256 ace4390f4d5625a81466a0d5996fb8a0736f0157e673eb114741c109d22825e8
CRC32 AB7E2B47
ssdeep 6:bkEmeeCshbuhKe6Z1U/KMGoo3ouGHFQhN+OlJM9iTqVbiNaGtU31hq9:bkEmzCshb2Y1U/G33o9luN+O4ZpiNazc
Yara None matched
VirusTotal Search for analysis
Name 95ba22656bbeadbf_topbar_floating_button_maximize.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\images\topbar_floating_button_maximize.png.wncry
Size 456.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 efd1b1325fa2f561ae93162d5435f04e
SHA1 4320ec2aeb1fbfb568af2950092bce487e81013f
SHA256 95ba22656bbeadbfc49332d4304f06650930fe36c752113ab718f189233426b7
CRC32 6B29CB36
ssdeep 12:bkEoH3ogZh0Vbi5WvpgyITDnzJvAv7fsAQZlZosh4nXeuJd5:bke6+V2LymzJ+7mPZosjuD5
Yara None matched
VirusTotal Search for analysis
Name a08788a65b61de03_445.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\445.WNCRYT
Size 4.5KB
Type GIF image data, version 89a, 936 x 180
MD5 b0da04c4049849951068a9cf74de5375
SHA1 76857255da3161b1fe5cfb9a4f904d4734978838
SHA256 a08788a65b61de03588e26747590663109f5640cd7e921f7ea847c187e37a293
CRC32 507BB91A
ssdeep 96:F2UWF46BwHI3msWaYwRZnUmIJmhsGatCgujmv5M:3g6I3lb2UuGcCov5M
Yara None matched
VirusTotal Search for analysis
Name b23f416836f59d81_allsans.pem.wncry
Submit file
Filepath c:\python27\lib\test\allsans.pem.wncry
Size 5.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a7e86bb371c9295e92750f5d880b734a
SHA1 7307bc4d26868417d2fd94581963e449e57d618d
SHA256 b23f416836f59d81a4e0aff3ecd30f1f65ec309305558b9b1e44b572a2083836
CRC32 95570CCE
ssdeep 96:ohHhvKo4P996ryFvlxmmXyjq+omSTvbMpgosn/1tCIfePvlrgXiiSvx1:eKo4T62FvlJyjPlSb2gJdtCIfe3lYTM1
Yara None matched
VirusTotal Search for analysis
Name 4e6648aa1307cb4c_intrcheck.h.wncry
Submit file
Filepath c:\python27\include\intrcheck.h.wncry
Size 584.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 61b9f014eda308eaf752736bb52c9394
SHA1 5635fe9ba2e7a82923ed89f14ea9e499036a2a8d
SHA256 4e6648aa1307cb4cf4a7673cdf6d405d72244a11264855f6f81716a71b0d3971
CRC32 460DEF3D
ssdeep 12:bkEYm+IJUC4d1+5+KveEJfs6AJjXr1BLlp17ymuIQmffDZrB+pcRnnQNn:bkrm+/C43+5+KGEJU9rXvAdCrZrB3RnY
Yara None matched
VirusTotal Search for analysis
Name 5544e31148edf7d0_143.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\143.WNCRYT
Size 8.4KB
Type ASCII text, with very long lines
MD5 39372ce223e6f5faf512936833ac82e2
SHA1 62a84dd84accac75847bbb453cb4e1a1b0151ece
SHA256 5544e31148edf7d0380425875fac92164e577bb72d3ff054182d6b0f26eb49cf
CRC32 7283370C
ssdeep 48:tCrF5o/cmSHbkI8+ETnFI3mC2hk9I+c6M30UPfMNDz9BybFkm5w+kGR8MOFiL0xc:wp5RmSHlsFerVIfM5vsam5VOQAkF
Yara None matched
VirusTotal Search for analysis
Name 269b8f92ecef6a03_18.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\18.WNCRYT
Size 875.9KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 ea6e7435e7ceb7895a9fddff1c2743fc
SHA1 cb6cd1aba39057d360e3a824a6d67802243d4915
SHA256 269b8f92ecef6a03679b1be821b81785387b021686a391c7444e552b4c90b44c
CRC32 5D44159B
ssdeep 12288:Z9/212tjjOrqt9/212tjjOrqt9/212tjjOrqt9/21K:/u2ZOmru2ZOmru2ZOmruK
Yara None matched
VirusTotal Search for analysis
Name b647448e0b3f157a_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.3_0\128.png.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 27c961f866d0a68f7d09cf2feb1f86e4
SHA1 b022cfbf4d42f149cbaf80c21ba19f28ddb97b1f
SHA256 b647448e0b3f157a4b32041cbda84131524083fe0ba06485e1422ab870403e24
CRC32 267F36C1
ssdeep 48:bkoZkSR6Iv4vYTK4LOWc965tppwmDLA3heEz/vl9HQ0Ng:ooyIvCIKmrvppwmw3heEjHQ0e
Yara None matched
VirusTotal Search for analysis
Name 87a0f9a1f0038e82_debug.txt.wncry
Submit file
Filepath c:\tmptqb9ww\modules\packages\debug.txt.wncry
Size 280.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0b06ea1827760478b90a3df5a273971e
SHA1 be447fde00726238e62ec8c3c52c9b5315729336
SHA256 87a0f9a1f0038e82a21aea546e6e4f38dd141f809ccaeb8febc52e13e8f89555
CRC32 158F13F0
ssdeep 6:bkEDmsM0AsXaQGoBqpCGHhFlloBS2zXnkTMvT1s5ejIBU3Y:bkE6sMfsXaToBinHjolzaMv1F
Yara None matched
VirusTotal Search for analysis
Name facda0069e8f558d_529.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\529.WNCRYT
Size 319.0B
Type news or mail, ASCII text, with CRLF line terminators
MD5 63ca765e5743f12e853c3f8780b77af4
SHA1 f40011cc1fa501461be71d92b04545acbd37b4bc
SHA256 facda0069e8f558d0bb554e84914d0d4880e7b80d9e02265aa6b6bbe2190dc4c
CRC32 BAF86C38
ssdeep 6:BYLQAQ6b8FpROQ8KIFu4RRyqQQIkXgsyqMMZyIdvXbINLS/Wzdn:+LQAQfWQkuURTQdkwhqMMoeQS/Wzdn
Yara None matched
VirusTotal Search for analysis
Name 709a949ea55e7a61_readme.txt.wncry
Submit file
Filepath c:\python27\lib\test\leakers\readme.txt.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 16d8115a5973da7801df60dc506c9353
SHA1 f3b9b8a3e209d369f6bbf7432299dc8bd1a96fd4
SHA256 709a949ea55e7a611dba8623610f04f45c61e9c2d4f9a66d69c74fa479d1f1f9
CRC32 37983FA8
ssdeep 24:bkIwZtAjqeoY4OPNbXMl/pTgXoVDCzyHcpxs5DwP9+Jb5sHFZWUxsrUw:bkiRRjzMBpTNqcwUJcyUxsrUw
Yara None matched
VirusTotal Search for analysis
Name 307ccc12179e5704_msg_17.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_17.txt.wncry
Size 632.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 ce10295df8c953221449f6a486dbcb54
SHA1 fe61c982a1d997ea496b8e33e1e9264af3b7f655
SHA256 307ccc12179e570451cc6909044a0eef2e50bceb4b126dc6b1fb0b2f96642808
CRC32 4D1EF2FB
ssdeep 12:bkEjdvobBH21Kxrzd/nsimHP82A4poe1XkI8Z4myFa70vjbSDkHPpboaPmLXzdh1:bkoNSfTgP8QoaXIG58Q7p/P8XRf7CjW
Yara None matched
VirusTotal Search for analysis
Name 40b37e7b80cf678d_m_bulgarian.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_bulgarian.wnry
Size 46.8KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 95673b0f968c0f55b32204361940d184
SHA1 81e427d15a1a826b93e91c3d2fa65221c8ca9cff
SHA256 40b37e7b80cf678d7dd302aaf41b88135ade6ddf44d89bdba19cf171564444bd
CRC32 0D11BFEF
ssdeep 768:Shef3jHdCG28Eb1tyci8crbEw6/5+3xFkbP0vyzbZrS14e:SheU5De
Yara None matched
VirusTotal Search for analysis
Name 22ac702d199da784_{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x0000000000000008.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows\caches\{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x0000000000000008.db.wncry
Size 169.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 991d36f807286da0a917b44432ce06fc
SHA1 a7ca5f5627c71db273b1e74e46a0aa9ba196b52d
SHA256 22ac702d199da78414a7cc606f4a9ccdc4290ed411716575afbf677de9ca3db7
CRC32 D035F6B1
ssdeep 3072:yVTeO1d2Kz18aGWkhCrUxAcrFVbJcMR0wUkgwrVYYtEstK6BEo:ywO14KR5zmAcrFVbJuJkgwrVYYWX6eo
Yara None matched
VirusTotal Search for analysis
Name 767accb9ab75a327_17.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\17.WNCRYT
Size 339.9KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 19f80e5a5d2af0729d6ad2efa2a64208
SHA1 64fb1c1e1ca5df6155bc6d603aee95858cdc5073
SHA256 767accb9ab75a32777c94537552079868f90e1f1eae152d2f03f9281d190da70
CRC32 6CF4A64C
ssdeep 6144:eJ3EvaLCKKFRbd5Almwlk3X1ptoB5hI6EmHMXztkgDWuFPqB8J3EvaLCKKFRbu:emYOFRJy8EB5hwzDWCqimYOFR6
Yara None matched
VirusTotal Search for analysis
Name 847c14c297dbe4d8_644.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\644.WNCRYT
Size 251.0B
Type ASCII text
MD5 44f2ee567a3e9a021a3c16062ceae220
SHA1 180e938584f0a57ac0c3f85e6574bc48291d820e
SHA256 847c14c297dbe4d8517debaa8ed555f3daedf843d6bad1f411598631a0bd3507
CRC32 B9F0F498
ssdeep 6:SlSyEtJLlpuoo6dmomerQZnFLou3v6rZom7+3vrQZg6HK:4EnLzu8xkZFH3v6rM3vkrq
Yara None matched
VirusTotal Search for analysis
Name 840ab19c411c918e_@please_read_me@.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\@Please_Read_Me@.txt
Size 933.0B
Processes 2632 (WannaCry.exe)
Type ASCII text, with CRLF line terminators
MD5 7a2726bb6e6a79fb1d092b7f2b688af0
SHA1 b3effadce8b76aee8cd6ce2eccbb8701797468a2
SHA256 840ab19c411c918ea3e7526d0df4b9cb002de5ea15e854389285df0d1ea9a8e5
CRC32 568F0793
ssdeep 24:ptrPzDVR5Gi3OzGm0EigS1xbnGhRQhbrW8PNAi0eEprY+Ai75wRZcet:DZD36W3KghvWmMo+S
Yara None matched
VirusTotal Search for analysis
Name ff21bf84b011ce89_logo64.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\images\logo64.gif.wncry
Size 1.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 755363e39e5b6292edee121c1a12f188
SHA1 a6690eefd8da63e468cce8435640190bfeec20af
SHA256 ff21bf84b011ce89524a91ed939b91bbb21c447ba222772d4e7371fe0e008186
CRC32 EB77631D
ssdeep 48:bkRks4BZpMA8f2moUeSvy3FSWERwjAEktYu3:oRksmafTVd6kWERAwau3
Yara None matched
VirusTotal Search for analysis
Name f94a153b84a95e0e_icon_16.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\icon_16.png.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 f4b0480313e26ea54c0340452250b976
SHA1 48d7eede51ec2934e8a546b7e9ee6da017f1af15
SHA256 f94a153b84a95e0e638d90ffdd80a560635c4f0ea00bd0113df1410d30c6bcf9
CRC32 0E31DE52
ssdeep 12:bkEu1p4Rlmy7Z5tQzu+pC226re9gutvlZ8+U3JIy6adK2:bkm6yd5twu+m6q9hv7I+udJ
Yara None matched
VirusTotal Search for analysis
Name de68810ab584cc18_minusnode.gif.wncry
Submit file
Filepath c:\python27\lib\idlelib\icons\minusnode.gif.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0d7b61e78cd5c80a57a3c7adf5e7ef34
SHA1 2499606a4fe29b60e106c4a67db3cc67759f8f04
SHA256 de68810ab584cc18ba17649b7d2ba0618db3d10d9a7003c093898f11f1a5b77f
CRC32 E9E6F75F
ssdeep 6:bkEXQdJoAojAu9+UZlRC3rAHOQUg0ZJALBt5q3iw/+zpKIWBph:bkEXol2+k6AHLaZJALBO3iwcox
Yara None matched
VirusTotal Search for analysis
Name 2086ee8d7398d5e6_645.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\645.WNCRYT
Size 251.0B
Type ASCII text
MD5 ccb036c33ba7c8e488d37e754075c6cf
SHA1 336548c8d361b1caa8bdf698e148a88e47fb27a6
SHA256 2086ee8d7398d5e60e5c3048843b388437bd6f2507d2293ca218936e3bf61e59
CRC32 B03A4E41
ssdeep 6:SlSyEtJLlpuoo6dmozgUFLoro+3v6rZoz9+3v9f6HK:4EnLzu8ZgUFcF3v6ruI3vMq
Yara None matched
VirusTotal Search for analysis
Name 23f0e91ba155ee47_278.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\278.WNCRYT
Size 4.4KB
Type C source, ASCII text, with CRLF line terminators
MD5 f66c16e08766c90046ef978dabfdbcab
SHA1 01a61e69d8c3593592d52a7095dc9c37201b6e21
SHA256 23f0e91ba155ee4792a3c38d70132a5ad8444747ae46889127e1002886b8473f
CRC32 588A7FFF
ssdeep 96:ECro6ViuYEA4JKLka13QRNqo8XfnxMJJR+yqT6fCQCgnvwM0sjRS8x5YtrYpOeMU:lrViuYF40ka8f3hobW
Yara None matched
VirusTotal Search for analysis
Name 45087315000fedba_craw_background.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\craw_background.js.wncry
Size 532.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 99c009b2d5af9cd1735c8b4b9f54ec5b
SHA1 9089df93249088fa4a3b08afdd319b480ede173c
SHA256 45087315000fedba2547af01d557ccf1f54004063a774f1a50b049fbc17e38c0
CRC32 89168D4B
ssdeep 12288:ymdcGu0ufSO9t9xvy6Q4ONd1oV740di91B7h9HAvKtknKQKYY9uwPW:yme0uJt9x2d1IU0WLhlAySnKQ+9W
Yara None matched
VirusTotal Search for analysis
Name bdba00d535409701_shift_jisx0213-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\shift_jisx0213-utf8.txt.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 9c1754afdaa53bb628058cfeee27ddb3
SHA1 8710efc6a7b911a02f800950746fe780f1323823
SHA256 bdba00d535409701ec05318391357c10ad7232472a84fe3f32b4c446a5399aad
CRC32 C073955C
ssdeep 24:bk8AmdZc/joPiju/l5L0myhFVbodFIPLjzn18FNqv+t9Ags94PEs3jN0br:bkSEoPDjPOodQGFcWXXi4PEsTq/
Yara None matched
VirusTotal Search for analysis
Name bf43d54a11349329_bitset.h.wncry
Submit file
Filepath c:\python27\include\bitset.h.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5b7f3ac2a0db3c79809a1d2295484463
SHA1 df005c7605aca2b1b1a9bc583f109f9117415496
SHA256 bf43d54a1134932945aa55af2809fc6c1b49da47136435e89a8f9abb22898c7f
CRC32 9A45370B
ssdeep 24:bk2xkMeuabfPeoCWWfTdJrXew5DMMryYiLOYH35Vnucjmtp9/90O1:bkwBibfD8Tdpl5o6TYXT3+z/9R1
Yara None matched
VirusTotal Search for analysis
Name ecd46cc5732ef68d_big5.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\big5.txt.wncry
Size 728.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0f551d605dbf1cdd78e81bc7b78a0e14
SHA1 4013ee7dedbc07d09f0a878db7bdc155f3d60cea
SHA256 ecd46cc5732ef68dd2c7835a47ec0c79ddd0cad060054b50bdcb804ef5bf8f31
CRC32 3C6DBCE7
ssdeep 12:bkETsdVWkTOVjwWGcgxkEMGih/rpctZXr4jquer66zPGgbaGD/I7rHgTf6Zv3G9r:bkWWoPVtGcCfpihpctZ+qbrvGgmy/I32
Yara None matched
VirusTotal Search for analysis
Name c7d84001855586a0_109.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\109.WNCRYT
Size 1.2KB
Type ASCII text
MD5 8e205d032206d794a681e2a994532fa6
SHA1 47098672d339624474e8854eb0512d54a0ca49e7
SHA256 c7d84001855586a0bab236a6a5878922d9c4a2ea1799bf18544869359750c0df
CRC32 450D4A72
ssdeep 24:4azu8iYJcc8jYShjLhQ6I3S68gvNvlNUhsFNlVGvNmv5svc:46Wi38jBJLhQ6I3EgFtNo4NlVGlw5Kc
Yara None matched
VirusTotal Search for analysis
Name 5c5922d66ef333f3_tfwgfauyxrlwstg.docm.wncry
Submit file
Filepath c:\users\test22\documents\tfwgfauyxrlwstg.docm.wncry
Size 498.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 9a7defde6a355b7d43e5426033f3e666
SHA1 5e3aab62448ef11f26d3f26d51af2f110fe07da4
SHA256 5c5922d66ef333f36d509ed534b5375f63716c66f9c910cc21ddb06544bb0cdd
CRC32 06944FF1
ssdeep 12288:7K3ztgbfprhUYH58mVlp0Q3XcA/QqqbrAyGj8BMoRx:7gzWbfplUYHN0Q3M9qqvAyMmLz
Yara None matched
VirusTotal Search for analysis
Name f19a80d1c7d5d758_319.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\319.WNCRYT
Size 1.3KB
Type TIFF image data, little-endian, direntries=17, height=16, bps=1242, compression=none, PhotometricIntepretation=RGB, name=python.tiff, orientation=upper-left, width=16
MD5 d8580e24bfb05ec687436beb33838368
SHA1 99eefffec67780cc34ce21ea7c5b5b3073719011
SHA256 f19a80d1c7d5d758dcea82276e73150454212a5136b19c5fc2727786132ddafd
CRC32 AD435478
ssdeep 24:A483/ZTCDhEcPuoVUCpMZRkJr1/XKX5guBg7xS:+cVEcPu2hQ5geKxS
Yara None matched
VirusTotal Search for analysis
Name c4113eeb9c550caf_msg_43.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_43.txt.wncry
Size 9.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 506943b744cc02898fae9e7f0a9d0442
SHA1 e32dd4b6b18198c9561557049fad9883701553cb
SHA256 c4113eeb9c550caf8d4cdfb6d54f03bed839678b18db2c4f51d9aca6967fecf3
CRC32 58D5FAD0
ssdeep 192:44lXFQTLhC6ooBW7+BwoClU8KKttE9PaR1siDiH2C3pSdWs8cH14cEHODkErI:4yV+Lh3jQ7EwNFRyiDc/pA18k14VHOvU
Yara None matched
VirusTotal Search for analysis
Name 9f0b6adaacd0c97b_exit.png.wncry
Submit file
Filepath c:\python27\click\click\click_image\exit.png.wncry
Size 920.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 da9d091d47d650ca4eabd4d47680caef
SHA1 611d5221a22c4819d23a97bdac19224c3d053248
SHA256 9f0b6adaacd0c97b00a529727ad09839e8018ccb52f127b66b9450832355600b
CRC32 596235C1
ssdeep 24:bkiqNr8NO/4MuGbs6xWg0FxIXs8AoeFfhU0sfXNu1Vx:bk9dWO/XuGbf8DIXs8oFfhU0n/
Yara None matched
VirusTotal Search for analysis
Name a792f6cd2b49ac57_524.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\524.WNCRYT
Size 605.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 0a68cea3953359e58de5b0df338cada1
SHA1 13a7589aa4a3036ba88e371835616a7f3bd9e45f
SHA256 a792f6cd2b49ac57da11e017cf46b6b516298e21c5a9539c15e8fd9f1774df5f
CRC32 77513DCE
ssdeep 12:k116arny0x4JKmVNbXmMQTLNwtFNg0H8aFhrXgVB0d+Aey2jf0x:S4arnLx4JRbXmzwtFqGF2jAeY
Yara None matched
VirusTotal Search for analysis
Name 45f0957a66fcb8fb_usertile39.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 65bfce337e2c25ad0b890ebe3a1a1a0c
SHA1 4d0c963426990fd6a1332f050c1cd72722409cf2
SHA256 45f0957a66fcb8fba8485a9adc0d65b79a8b4733c616c943bb22bd2d3c218ffa
CRC32 6878719E
ssdeep 768:SqYZ+QPdjckbVXxNN9cCTfn2LtoCKdCZhukKoNYdA:E/XhzHsZ9FNYdA
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 6403db3597d8f331_usertile43.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 bf54b355d171471bece614e6583488b2
SHA1 3556f13234855d9c74d7100d8d3c229a496f7f72
SHA256 6403db3597d8f33188d0fe0cc1ff166c7cf91df5c6f19db36002eb6b5481c892
CRC32 A0EA68DE
ssdeep 1536:Lv5XZPkGSSzcsKZltwT3BGkPseJ877pos:DVZ8GNalto30kJI7pP
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 444b05404888547a_badkey.pem.wncry
Submit file
Filepath c:\python27\lib\test\badkey.pem.wncry
Size 2.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 876d5729ad2d05986df63f30f75bd1a8
SHA1 cf1c88a0082a78f6fa2d4db10996f31a4bed30f4
SHA256 444b05404888547afe177c50b2a2a95082608f222e881ed0092489ef072c70b5
CRC32 33977A92
ssdeep 48:bkp+/i0JVdDPG+McYsIMRLD8uoQnXpbxyG4f6iTdXUbfAPZ1V/D/Dg:op+K01aQYIV6A59yG0BCAFrE
Yara None matched
VirusTotal Search for analysis
Name 178eb0114b193e56_dtoa.h.wncry
Submit file
Filepath c:\python27\include\dtoa.h.wncry
Size 648.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 6dfd219d38a8cb546eabfe072722e47e
SHA1 60cff309954013526ac55c40ba650df2047399ad
SHA256 178eb0114b193e567455bd10e4e18a4f64ce9c71ecddf662b24f3093b57d4228
CRC32 B4BE0C20
ssdeep 12:bkE9RIZIMg9CB21vt9AWGB7CqPDf9tJMe0rpAf3X+q+m9yJXA:bkjZIMilt9AB7HPDf9tWlUom9yJXA
Yara None matched
VirusTotal Search for analysis
Name 176265aba1fc8fe2_cobject.h.wncry
Submit file
Filepath c:\python27\include\cobject.h.wncry
Size 3.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c3e9168f490abe1455e96746df792fbf
SHA1 cc41d96d9ed93fef6bcb8e30925a4ecece0e0dd5
SHA256 176265aba1fc8fe20307dcb36e43671b428cbaa8ea240db77079c99824d5a343
CRC32 63FBBB81
ssdeep 96:or4qlTpy+VfjqDEJSt9PdDMF4yYlUVDffH6:c/ldy+VfmDE0tY4jSVDfy
Yara None matched
VirusTotal Search for analysis
Name 5947425ea05ae206_262.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\262.WNCRYT
Size 2.7KB
Type C source, ASCII text, with CRLF line terminators
MD5 2b13febbe54438bc580d6b19ea35977b
SHA1 02d0c3567de77b5a574e9dbf4b383475b0994cc9
SHA256 5947425ea05ae206c2a36ebbfe3da14459cf7b6a41a78a38baffde7f17cbd9b2
CRC32 39455861
ssdeep 48:34H6XuJDTohMPnXDEJwlJ37xH0EHyLN3WNPCCtr8v41iGIS5PZKACXbAtyy/:34guJDT0MPnXQJwlxfypWlHpUvSVZKr0
Yara None matched
VirusTotal Search for analysis
Name f531cfe799f27eeb_611.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\611.WNCRYT
Size 875.0B
Type ASCII text, with CRLF line terminators, with escape sequences
MD5 7d50a47af6de7034e9f4d284d8ddd7bf
SHA1 fbbb71ed7bd6deac93ba4dd2bebcbcb932a4a738
SHA256 f531cfe799f27eeb15df59a44bc3372c72249e432f8ff741b575d062704c8e3f
CRC32 23EB005F
ssdeep 24:tF8mxdBVjYp797NZicebzoPygGlVuvcw9JDE1:tF3VxiRKz85Gruvcw81
Yara None matched
VirusTotal Search for analysis
Name 561dcc00f4c50385_dependency_links.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pytweening-1.0.3-py2.7.egg-info\dependency_links.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0b9de794f7042843523f073f7039f1ef
SHA1 974323a0642dd5d15b09665712b9c4d7de7cc098
SHA256 561dcc00f4c503857f8f77d702e70579604376b224eb406c2b0110d08aedce7d
CRC32 E09AD751
ssdeep 6:bkE0uv7LJSdAtWv8xAChiIpPyoWoaoid8nreHVm+7vkqKQaX064:bkE0uv7LJNwWAfcW/38n4mS8qKQ601
Yara None matched
VirusTotal Search for analysis
Name e383b20484ee90c0_684.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\684.WNCRYT
Size 279.0B
Type ASCII text
MD5 4ee34960147173a12020a583340e92f8
SHA1 78d91a80e2426a84bc88ee97da28ec0e4be8de45
SHA256 e383b20484ee90c00054d52dd5af473b2ac9dc50c14d459a579ef5f44271d256
CRC32 17784743
ssdeep 6:SlSyEtJLlpuoo6dmofm6GPWHFLofAW3vG5ofAW3v6X5ofm6T+3vnFDoAov:4EnLzu8hNGgF493vr93v6uNK3v9dy
Yara None matched
VirusTotal Search for analysis
Name af59d0dc5efc62ff_402.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\402.WNCRYT
Size 3.3KB
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 0364e82a1ad38a53a6b0b0ed08884b95
SHA1 1450f185fa55e8124dbdf2754b6934793c4fa606
SHA256 af59d0dc5efc62ffea46db1faacc7201b79c3a1eec0c5c9d7ae6ba7e5ded059e
CRC32 5861B9DD
ssdeep 96:UZ0yJ6rSbF3UwBYFSm1Xyt8y6+d0mpfGHz:UpJ6rsxKZ1Xu8z+hfI
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name c33b109af5fae896_fa_ir.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\fa_ir.msg.wncry
Size 712.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e573a6cc16e822db990e225f61fbac1b
SHA1 4f6252dde1eae09b86d00e19be9fcec97d180962
SHA256 c33b109af5fae896eec1cf82e4dfce64bb3aeb6d2dcc04c0b12d03c9d737ccd7
CRC32 85F7A1A8
ssdeep 12:bkEfq3sP0D0kwGZnQ9h/4wb5yctkESbtx0U1cgEjpX4jeJcKFm8KUreoGwyeD4WC:bktO0RwGZEFltkE7U1cTpgeWKFmRyxDu
Yara None matched
VirusTotal Search for analysis
Name 49128b36b88e3801_118.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\118.WNCRYT
Size 1.1KB
Type ASCII text
MD5 98820dff7e1c8a9eab8c74b0b25deb5d
SHA1 5357063d5699188e544d244ec4aefddf7606b922
SHA256 49128b36b88e380188059c4b593c317382f32e29d1adc18d58d14d142459a2bb
CRC32 6D4148FE
ssdeep 24:4azu84LFiS8LMKZoNfSZTNTQhFCNZvtWvg:46Oi5LMKZASZTEF2Ntgg
Yara None matched
VirusTotal Search for analysis
Name ac79e45b45318c58_276.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\276.WNCRYT
Size 1.6KB
Type C source, ASCII text, with CRLF line terminators
MD5 5f02a6a05927c4b7d1447b08ec29791e
SHA1 f9eb7fd0a5ac755fb32997d554118a44bc429b56
SHA256 ac79e45b45318c5885729125b82505f10a28f97cbad40cffb33624b03b4fa681
CRC32 263B82B0
ssdeep 48:B/RPSlPSyPHGNS1PSJbNn5txTl7jh+PTlQv:HSdSEa6SJpTxTFjh+biv
Yara None matched
VirusTotal Search for analysis
Name 684c5cd31fd5675f_39.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\39.WNCRYT
Size 10.0B
Processes 2632 (WannaCry.exe)
Type Non-ISO extended-ASCII text, with no line terminators
MD5 48cca477ca0f5f3c938b102cc20e5fd0
SHA1 3a42f6c870a15eaf50e541a6d94febf7c4351d31
SHA256 684c5cd31fd5675f065c4bdf4c291ee1464c5afe444c4e1b2efc0f30e3fef243
CRC32 D9191558
ssdeep 3:vzn:7
Yara None matched
VirusTotal Search for analysis
Name fb5d399c9c19c860_readme.txt.wncry
Submit file
Filepath c:\python27\readme.txt.wncry
Size 55.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e7ab5bf139da44ceb116b09b488784b3
SHA1 371947965eafcfb8c4836a82e8ecfa985d40c15d
SHA256 fb5d399c9c19c860e60e8c8857668a1cc0b8e60e33cab762b704e32640417b53
CRC32 9A87DEC9
ssdeep 1536:g4I5KQHNXs9WgtDyCqqGAdIy0ZkmDdfHTXQERAJxvjPlZH:kN29PxvVCyE1HTXdeFjPlZH
Yara None matched
VirusTotal Search for analysis
Name 16f94f3d8591481e_706.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\706.WNCRYT
Size 1.0KB
Type ASCII text
MD5 f0b4ff535d48556a6b69576281f53657
SHA1 3d731b0cae326e693d3644826f7706cacb0e6e88
SHA256 16f94f3d8591481ecf33b333eb83d3cd623792cf0a9238a7eba52aac03af460e
CRC32 E35EB6EC
ssdeep 24:Y95NV7iIlG7WGcAXbCXspXOrZXFdgdsHlkterdyGJB:kNV7iIlG7WGcArC8p0Z1+mHlmeRyGJB
Yara None matched
VirusTotal Search for analysis
Name 97c95be6398c9f82_269.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\269.WNCRYT
Size 8.4KB
Type C source, ASCII text, with CRLF line terminators
MD5 4915fc51fd9bd23e1d4d09c526e473df
SHA1 7e7fd0cc75a311b4acd1ad74dd1105785fa26e48
SHA256 97c95be6398c9f82b48ef65c5a2f7e19f96494037314404a4300957df12379d3
CRC32 62739F39
ssdeep 192:IHVJuHFn+++MM+HGV/DbmoRc8dSQvSg4FnrGaU0:yVJuHNjI+HGFGoR9d9N4FiG
Yara None matched
VirusTotal Search for analysis
Name 0145597ec4d9b9e7_weakrefobject.h.wncry
Submit file
Filepath c:\python27\include\weakrefobject.h.wncry
Size 3.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a6ca8c58f577f8978e8e62a633cc4ad5
SHA1 ffcacf1207e89fbc7c6c016dcf1eb08419b339f1
SHA256 0145597ec4d9b9e7510f170f7b62392c631c808fb24a34f693ff917efcea7b42
CRC32 19510C6F
ssdeep 48:bkgvnGfjt4Cj6ucHLwxbHA/uhjoXkAwYSWa+vOQ2wAmznqBHMsly6sDdKDUDZa8o:osGfqCpcrsNuLwZO2RwzzsARhBZO
Yara None matched
VirusTotal Search for analysis
Name 3c0b989b0193c3f3_zh_tw.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\zh_tw.msg.wncry
Size 632.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 59d89bf55ca8508eaf0d3eef2a73ba55
SHA1 015f9387482086e24fcb55db9a394adb3251428b
SHA256 3c0b989b0193c3f32e2f04ef6b5056c4a2f8f952e27957ef662357dbbc786343
CRC32 BA2EAA80
ssdeep 12:bkEfy7k1FxthA7QrLOrCkg7E8KRPLBiWsmDU4qYvah0HoHmIK9ArPz4j/M:bk1k1FxfqQrqukCURPcZmD9jy8oHmItR
Yara None matched
VirusTotal Search for analysis
Name 0126ca4fe3720dd2_pymacconfig.h.wncry
Submit file
Filepath c:\python27\include\pymacconfig.h.wncry
Size 3.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8b47b486806f39c242c25eebf29f75c4
SHA1 b3f490427710021506b1178c30aed84f3b68c244
SHA256 0126ca4fe3720dd23ec7f89399f08e3a74a92e6cb9a2f86d5c6177cbd8565857
CRC32 2AFF6962
ssdeep 48:bkAAeoowLqVptr1dZCK2IWWHGJ2BUyXF9ePEcMSSTf+EVHzFSTkn2HNUvPc2uib7:o+w0tr1dyKGJwLNSozFSwn7c2dxp
Yara None matched
VirusTotal Search for analysis
Name fc8db68142704d98_te_in.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\te_in.msg.wncry
Size 696.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0cef681d61380ec6543e70aaf15430d0
SHA1 8cfbce35220927a9ede291150e8fc4312d7ab258
SHA256 fc8db68142704d982b1050b098c9c79e9247aa3aaff3358b7f157a74cb8ede6c
CRC32 8A3F6FC1
ssdeep 12:bkE2ZB6bFc8PmnsD2pySAa/tk+sHbOq8jpgUY12nokgCsP9ZbaYX6B2ocIJ9:bkpDkcpnY4zsg1dYgsT9ZbzKYoLJ9
Yara None matched
VirusTotal Search for analysis
Name b85c9a373ff0f036_626.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\626.WNCRYT
Size 300.0B
Type ASCII text
MD5 f8ae50e60590cc1ff7ccc43f55b5b8a8
SHA1 52892eddfa74dd4c8040f9cdd19a9536bff72b6e
SHA256 b85c9a373ff0f036151432652dd55c182b0704bd0625ea84bed1727ec0de3dd8
CRC32 F03738AB
ssdeep 6:SlSyEtJLlpuoo6dmoCwmGjbJFLoCws6W3vULoCws6W3v6p6HH5oCwmT+3vjb0y6:4EnLzu8brJFqs6W3v3s6W3v6QQJ3vK
Yara None matched
VirusTotal Search for analysis
Name 9e6e4772050998a5_469.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\469.WNCRYT
Size 10.0B
Type ASCII text, with no line terminators
MD5 eb6b6c90251ab33cee784713c451e6d8
SHA1 451685e9efac4a6dc1fee73ec53ffb6b2c4c38b5
SHA256 9e6e4772050998a5c0dc3c61acf3dab0a7e594566171fa5746d6b62f9598efb6
CRC32 22598B08
ssdeep 3:IS:7
Yara None matched
VirusTotal Search for analysis
Name e9b579fb99e820aa_eula.txt.wncry
Submit file
Filepath c:\util\tcpview\eula.txt.wncry
Size 7.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d6e9ab093dab43f0afb200dd03a78ebe
SHA1 d4d8b150e0d82ced903e323371ccfe0ff789253a
SHA256 e9b579fb99e820aae6ea7878805c2c64809229faaf93c89d743d93dac68b8533
CRC32 A82B6BC9
ssdeep 192:B/I45Eoh30+Z2RJ5wNdU03XD0H9vzNsvZjeOMG2/QlC+ccf9M:tI45ph332RJ5wPrHod7Nshm8yQ2
Yara None matched
VirusTotal Search for analysis
Name 4ccae0bccf24ff17_195.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\195.WNCRYT
Size 3.1KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 128x128, frames 3
MD5 3131186bcf361f47298f4bff2a261811
SHA1 4cec47e776addfa0589a8167dd0b39f407461538
SHA256 4ccae0bccf24ff1707b59db81248cdc12eba9b363d85d035ee4132b8014ba3cf
CRC32 0F9BAE06
ssdeep 96:avX1MHt9VVnNM7wcdRToXPIHotMkyx0RgBin4+YaF3:Bt87wQyg9kyxbg4+YaF3
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 71a273fb4de0653f_7.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\7.WNCRYT
Size 754.3KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 e735ac41f19ac290596dd443cba0b3ce
SHA1 e61de44485de5a4131a0ea500f2cec0b27beff46
SHA256 71a273fb4de0653f19544a674b38b4a42ca28048daa32c1da48a4136a08bb9c1
CRC32 EC583405
ssdeep 12288:ZVXdnOTmrXMKpZka2pVXdnOTmrXMKpZka2pVXdnOTmrXMKpZka2B:jUTcprcUTcprcUTcprM
Yara None matched
VirusTotal Search for analysis
Name b65555d6fed11068_msg_16.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_16.txt.wncry
Size 5.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3cbb0384c7b894bb63ceede91272c92d
SHA1 7fdb466d2e6448ecd2ee170b9e836e85a70d14eb
SHA256 b65555d6fed11068fc14666563fe608ddc91391370569f5408bdd007ee3652f1
CRC32 5AC4E769
ssdeep 96:oMrW7vFS7mtnah7S//+Ag9s0HkyM/0HsL0KxJRXeYiaxn1j17DJL9x:vrW7vFOmtn6S50esHS0+JRXetap7Dnx
Yara None matched
VirusTotal Search for analysis
Name 228744874f05eda8_gray.cs.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\pref\gray.cs.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 09b67f7c0eab9eb000934c5705fe0d7f
SHA1 1078032c53d22e7411484e6756c49a75ad400933
SHA256 228744874f05eda8e3f617b87aa4455996ddde32f87927708ba4bddc77343590
CRC32 F1F3D1FC
ssdeep 24:bkLeZ24IHGANkLQX1BNPK+24tEZz0LtYuBJpYhQWyGeBtbJaXkYUL8jcK:bkLjHziwLk4+ZQpYZhMGe1a04QK
Yara None matched
VirusTotal Search for analysis
Name a6bd5a37a3ee39bb_239.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\239.WNCRYT
Size 6.8KB
Type C source, ASCII text, with CRLF line terminators
MD5 4afcdbeb9143c4ff061c1e0e7aee3648
SHA1 5c9bbc77184ed71a4d1d9e46ee64d9f97a2592f4
SHA256 a6bd5a37a3ee39bb59b8ef657797a55b6383dc4dc05648228032106ac7293eae
CRC32 1167A70A
ssdeep 96:gWt/XgzYK1Sb+1Nlm/sxsi2cVKQtEJkZtpaKb4Crdx8fp0:gUvT+kqh2/Qt2K0idOa
Yara None matched
VirusTotal Search for analysis
Name 13248fde6c300667_usertile21.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 28d31b34be2c6b050707d9ae2884a30a
SHA1 d52285f42ccc6d0d0181b7107253e73ba5901d80
SHA256 13248fde6c3006677b77f240b3c2ac48576810aaabfe36711a009caad14b7b1c
CRC32 B576E7E0
ssdeep 1536:f6RypfueQk/MtPeRAZ8JHIxRNUm8eF14O3:y8fkKwP3zx3J8Cem
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name ba8c8bdef26788db_752.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\752.WNCRYT
Size 247.0B
Type ASCII text
MD5 0e437dc8cdb8d59af6121f4b1862b09a
SHA1 45a19344a0ced5a09752b42058f970979f77852a
SHA256 ba8c8bdef26788dbc08d05f8160de69a4d14e276fe54d46c156a0e53698b035d
CRC32 5A32870B
ssdeep 6:CnJ4mTVYVLOiqbwxc80jZ7bVirmTVtjGMQmXSwxcdXLETTVVLVknxc+xxcX:CnCmTVYVL1e94mTVtjtxuETTVfCDQ
Yara None matched
VirusTotal Search for analysis
Name 7962b8e17ec87559_johab-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\johab-utf8.txt.wncry
Size 776.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 acb57cfbe5818240ba46752d91edc889
SHA1 2ff4c71452eaf61d129601d1677782d3ec7750d5
SHA256 7962b8e17ec87559f997d178f4ed99bd961963e4100952a225065f5153c372b2
CRC32 ADA5C466
ssdeep 24:bklOLWuOPpHNIok5bwot5JMSG01RqSXr+Vg/trrI4IW40U:bkloWuUSr14S7jBzIR0U
Yara None matched
VirusTotal Search for analysis
Name 5c7396e373a9ed21_graminit.h.wncry
Submit file
Filepath c:\python27\include\graminit.h.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d87a01653ead4969654c92a8dc351388
SHA1 362e3fc5a4c0ed7b10ebcf6eb0b46440b85e47d4
SHA256 5c7396e373a9ed21979a386fe20d3f991f7a0f221727f1b497f89567e90fba8e
CRC32 563DC210
ssdeep 48:bkfpwN4Vd37px75pqEWW+sJshz1guLqyUQthL003n7MvXbpO4:oeq7H5pz+5tCC7P7Mr
Yara None matched
VirusTotal Search for analysis
Name 4b28b46981bbb78c_649.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\649.WNCRYT
Size 251.0B
Type ASCII text
MD5 2c4c45c450fea6ba0421281f1cf55a2a
SHA1 5249e31611a670eaeef105ab4ad2e5f14b355cae
SHA256 4b28b46981bbb78cbd2b22060e2dd018c66fcff1cee52755425ad4900a90d6c3
CRC32 1826B15F
ssdeep 6:SlSyEtJLlpuoo6dmoe/GriP/FLo3W3v6rZoe/T+3vrig6HK:4EnLzu8Ae+nFmW3v6rxS3v+lq
Yara None matched
VirusTotal Search for analysis
Name 554444941e4ef36e_193.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\193.WNCRYT
Size 7.3KB
Type JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 640x480, frames 3
MD5 101be77d74523661afda5d519f616405
SHA1 7ccfccccd00211caef29116b0c2e2e1db9ca3686
SHA256 554444941e4ef36ef598bf3b9174091c5c7cef6746285088e0e084a6779ffb77
CRC32 AC92669D
ssdeep 96:EshOGl0l66sMeljC5BmsZLzf94iRirrLEj4E5PM:EW3ls66IEmstzai4rrLg4EVM
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 69c1c111071db7a4_281.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\281.WNCRYT
Size 4.3KB
Type C source, ASCII text, with CRLF line terminators
MD5 ab12822e5804439731c9bb0656e2fc7c
SHA1 fa5836f6f1bc3e1f7bc5bcea33e7f99916967c9f
SHA256 69c1c111071db7a4d7463d8700f0926651cc24fd8d3d66d1ca14a372356c8404
CRC32 7B604960
ssdeep 96:3FkoHeKx3nZbtBGIMmG766cfzFcE6hrKv:xZbHG9cLFAk
Yara None matched
VirusTotal Search for analysis
Name b633e58cd5b32398_usertile17.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 9afccefdd79314b5812017d7803a531c
SHA1 ad82364a2699b002b8d4ef0fb5a9771988923d94
SHA256 b633e58cd5b3239855b73f78b592283f30e0ce891c0b0373dc73e20b997e6929
CRC32 6C993280
ssdeep 1536:EjmmNj7cEpy6/eiPtVeC4qLf2MU1vJKadGS:EjYEAyPneCh+j
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 15f3679014eee1d6_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyscreeze-0.1.26-py2.7.egg-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 c3168282ece57124945e17651d450c8b
SHA1 6b0be0a69f15e1cef662e9e3b180a29787a3c2a0
SHA256 15f3679014eee1d6ed0476f824e76f52536018c72c9acf6e51f6339604ddc29f
CRC32 2130D671
ssdeep 6:bkE7sTeQXtFawrnGwIyoapY4CFweztXJvmsckmQeLwnhli:bkE7yDXt9rnIyoa+4wXXJvsJd
Yara None matched
VirusTotal Search for analysis
Name a7247ac66453663d_181.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\181.WNCRYT
Size 2.2KB
Type JPEG image data, JFIF standard 1.00, aspect ratio, density 0x0, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 128x128, frames 3
MD5 9fcd9ac9e8adaf7ab32b464cf13e506b
SHA1 ec10f032bb10570feed6f0c71c6c26e895b0f60c
SHA256 a7247ac66453663d3d24c66eda246a95b05f7b23194bc29f47167c492ee4c922
CRC32 73FE341B
ssdeep 48:1gIuESA6ypnaFrwATo6xaeFVQs5ytkLrcFAkLNoYRO2:KzEJpnaFrwATo6xpFP5BgeYNw2
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 5cd72812b9b4a54a_191.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\191.WNCRYT
Size 1.9KB
Type JPEG image data, JFIF standard 1.01, resolution (DPI), density 75x75, segment length 16, comment: "AppleMark", baseline, precision 8, 96x96, frames 3
MD5 45fdfb8895b2e7885c6fe534393187f3
SHA1 500dd7ce7fa7dfa3e9d9caa26df6699811dcd7b1
SHA256 5cd72812b9b4a54a937aa6411c6dd955dbc885140d53000ec432af42497c73cc
CRC32 69290869
ssdeep 48:SA5a3IuESA3rkSi1Jfd431erx1yIwparmAlF:SA5mzElkSL34SIWarmk
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name dcc2521ffa853e01_thumbcache_256.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows\explorer\thumbcache_256.db.wncry
Size 6.0MB
Processes 2632 (WannaCry.exe)
Type data
MD5 6af9929f04044b74ce80b1be30211672
SHA1 12493837f0020d630835217263acda054c25047f
SHA256 dcc2521ffa853e0133277a09097566f001e764ea67d2f64b60e962caa686267d
CRC32 52B6897F
ssdeep 196608:Q8K0Y8RbVQkBXkpVFJcPSsB/+1a6TpS1JD:RKBQbx2pVFWKQ/+1jSLD
Yara None matched
VirusTotal Search for analysis
Name 00ec801325958168_hu.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\hu.msg.wncry
Size 1.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 36eff76d1b628bbe04c7472a5c55b1db
SHA1 b26b1c75f52fe194aad340de3a2bcbdb7b890dbb
SHA256 00ec8013259581685f51c7733125a9872bda9760dce27a65fc0ae6ee3f6db468
CRC32 DD8F102F
ssdeep 48:bkQjBsF3r7HwulP6Tv9dluZyN8Ceaq8NCqdz:oag5lSTvfluZyN8CeaqiCqdz
Yara None matched
VirusTotal Search for analysis
Name f253547e1186bfa7_bg.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\bg.msg.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2ab6d8552356f0471472889573e0e922
SHA1 b2a720d4e154b2629b0bfb6f8ee0c93e87a3ea58
SHA256 f253547e1186bfa7aaf84359024a0f29ae6cbe04a02c40575c3e4bc6f669b818
CRC32 2BC98EED
ssdeep 48:bkIUBtufiti0sQh91k/r00LBYvm8uuwp04RUlMz52bLZxDefgjl+B7gKWj:oIWtu6Ow1OYsBYvm+wp04qCMxkgj2m
Yara None matched
VirusTotal Search for analysis
Name bf7193633a5de037_4.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\4.WNCRYT
Size 602.4KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 b53928822f1562819a44fa3592290885
SHA1 65c52b8646a2470429cf2b388dd18506de998e4b
SHA256 bf7193633a5de03714ea7b1376104e5b3b0453471769053557b06dfdd6d3c748
CRC32 9708E595
ssdeep 12288:WnAAn7LaROzVOVz/j3AbBsP2jNmnAAn7LaROzVOVz/j3AbBsP2jNmnAAn7LaR/:WnA8LHZE/jUmnA8LHZE/jUmnA8L0
Yara None matched
VirusTotal Search for analysis
Name f7c1df5e971f4d32_342.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\342.WNCRYT
Size 16.0KB
Type SQLite 3.x database, last written using SQLite version 3021000
MD5 5efbdaa65a57fbb52f7e2edf584c1dcc
SHA1 ffdb68f2d477a346a2788926db18ce742c5c9600
SHA256 f7c1df5e971f4d32fdbc2be5940058a07e3db77b84f2a4294755d1c7a95f8d4a
CRC32 131EB874
ssdeep 12:TLCIwaBg9LBgVDBgQjiZBgKuFtuQkMbmgcVAzO5kMCgGUg5O+:TLBdBgtBgJBgQjiZS53uQFE27MCgGZs+
Yara None matched
VirusTotal Search for analysis
Name 23c1c4970de2c514_msg_24.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_24.txt.wncry
Size 456.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 d85a474a3c37c01d393379acea43bf5e
SHA1 95853722d4488bf3d2abf26c4bf5436975ed6bb7
SHA256 23c1c4970de2c514c1a06d9ade58c43fa478b32f54064026ce843d408714ca54
CRC32 F57E10A9
ssdeep 12:bkEKZPkpVcY2IVPLaazqGh/I/oLp9i8guIEoSxcNJCaF:bk3Zspa9IVPLahGzpA8/oIcNJCo
Yara None matched
VirusTotal Search for analysis
Name a2d3dc479ec0123b_earth.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\demos\images\earth.gif.wncry
Size 50.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e94c10fd711150117a9436a8276a1456
SHA1 b57ef7dca15acedae9c60260c5f734d53ab199dd
SHA256 a2d3dc479ec0123b6da854626002622025de8eeff6165126321fc75a207e2b5b
CRC32 EB9F4713
ssdeep 768:F1QW/cu2ogLCeao4RUHpYn74tntBwHOGdHWVsEjRX21OpJAbMb0Hq0bdryIQ:Yuho4RMBtntgd2zlXY0JB0KKXQ
Yara None matched
VirusTotal Search for analysis
Name a20c337bb1a4f1a9_11.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\11.WNCRYT
Size 152.3KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 8a83a6c4801cb2d08b2d8f96f7f194ea
SHA1 837fcb92a90124a37bd4d38242436266cad5470d
SHA256 a20c337bb1a4f1a91d59ef4ca97910ebafa2a624cca258f6f6e68a3d3ce69fb1
CRC32 F8448D87
ssdeep 3072:4T3A6UoAFF10ZFI8TFdIplAo4oPf/wH06xN+P7Oz0l:UQBnFFoF5TqlEOf/PSMPqI
Yara None matched
VirusTotal Search for analysis
Name 2b73533f47a99ffe_415.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\415.WNCRYT
Size 68.7KB
Type GIF image data, version 89a, 30 x 30
MD5 398abb308eebc355da70bce907b22e29
SHA1 cffb77b8a1724b8f81d98c6d6ad0071d10162252
SHA256 2b73533f47a99ffea9cc405ffafa9c4c53623f62487aebfba415945120b22040
CRC32 FF018142
ssdeep 768:g5TXOSBAqNIPmA8NcjCWdM0VFMJEwavTeElfWupav5TXg7wV+irIPny9MTVQHydi:g5KSmiIPmAhZWiMsDfWug7DmqM6HybkF
Yara None matched
VirusTotal Search for analysis
Name bbf8a21491c3fe9b_74.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\74.WNCRYT
Size 1.1KB
Type UTF-8 Unicode text, with CRLF line terminators
MD5 15b78d88df3d856fe092a4827e2e8478
SHA1 5bb8b4bce4a5ed7d232a979dd6188bcca6d9b8aa
SHA256 bbf8a21491c3fe9baf5495b2a5743dffa3547e2db79b75abaf38a712efb72678
CRC32 91B70F96
ssdeep 24:tFIJD5Uft4dUAPJxd0bH8Gl5NFW4szQF+/LOiqM33N6+F6ktYZ:tFI9540JxdvGXu4aPKiqMtLgkWZ
Yara None matched
VirusTotal Search for analysis
Name a50ddf6e874cfd1f_229.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\229.WNCRYT
Size 5.1KB
Type C source, ASCII text, with CRLF line terminators
MD5 ac76d8e98c4419356787ef0f0a70955c
SHA1 175723d7c66a603285ce3329ce3fecf57d59d542
SHA256 a50ddf6e874cfd1fd226080bf31e4636a2f5fad806a4116cbd68edb612932515
CRC32 42F85AB7
ssdeep 96:VEBmrypdVchQpNwcvqZ9WZBMxreupqH0Acutp3Yn4MOjZqaT6aTi4Ejizr:VEcrwVchQHxqZ9mB2r/4VuYrT
Yara None matched
VirusTotal Search for analysis
Name 596ac02204c845aa_627.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\627.WNCRYT
Size 305.0B
Type ASCII text
MD5 a0bb5a5cc6c37c12cb24523198b82f1c
SHA1 b7a6b4bfb6533cc33a0a0f5037e55a55958c4dfc
SHA256 596ac02204c845aa74451fc527645549f2a3318cb63051fcacb2bf948fd77351
CRC32 41B71577
ssdeep 6:SlSyEtJLlpuoo6dmoCr3FD/LoCsX3vtfNrFLoCsX3v6YNn5oCs+3v3FnN9:4EnLzu863FD/U3vtNm3v6yt3v3FnN9
Yara None matched
VirusTotal Search for analysis
Name 5f25c6ca2194c000_508.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\508.WNCRYT
Size 476.0B
Type MIME entity, ASCII text, with CRLF line terminators
MD5 39c486493de2a8a4f0f39d7b6deeed35
SHA1 d471d623747121ba1e1556ddb4ff1a0468c5b1e3
SHA256 5f25c6ca2194c00035cc41d36ff90c4eeca69383f409d7b53af59d41ca2c3d0d
CRC32 655E5EDD
ssdeep 12:3XmyFxxGEYUp8MG886AQcVgQearowgQYf1IcgQrIBgQrj:3XmWxoErbGiuVtrowiacyBNj
Yara None matched
VirusTotal Search for analysis
Name 0b338e65d97c9597_ar_in.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ar_in.msg.wncry
Size 552.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b37ff3419dc8e9f0798a18b43af924a2
SHA1 8c87151c550b5fc7e4a3d6d18bd1c7b0dbccae18
SHA256 0b338e65d97c95971b6ac9dfe578696a3874ed83429973a552ee15018d3d2862
CRC32 3E6EA3FB
ssdeep 12:bkE+ncJNoDSjcgtpeuiCQ/OsvYbAhGvi0GIKP1/hn:bkZcMDS1peFQFHQI6p
Yara None matched
VirusTotal Search for analysis
Name 9d1d8665689af7a2_es_pa.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_pa.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 1fc230ebae4ee458dcf2a9f6f8802fe9
SHA1 415ac3d27fe5209c38180f2d7b8d4aedb28bf462
SHA256 9d1d8665689af7a2cc12480487e203774472cb6a0689d830b4eaab6e72d09877
CRC32 6869BDF0
ssdeep 12:bkEp/PE5Ai9UDn4cn4Zc7WzFGlwUAzlW3jCsjyVfP:bkS/PUAsUkcn4qowilLAyVfP
Yara None matched
VirusTotal Search for analysis
Name 5db3e3d271f214b6_30.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\30.WNCRYT
Size 687.0KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 6f0ac83d17e8920ba2d2657fe17c9eae
SHA1 1c2532df55d7b0a14a1feaf8a41eda9c74154c49
SHA256 5db3e3d271f214b618de1c86fc13e6b91ed874f1b17114ca756e60b6a0f44b79
CRC32 B6A73FEA
ssdeep 12288:2D8PPz9kV6U6pd854D8PPz9kV6U6pd854D8PPz9kV6U6a:WRB6pjRB6pjRB6a
Yara None matched
VirusTotal Search for analysis
Name 389b4b4dc1f6c7d8_tixgray.cs.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\pref\tixgray.cs.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c9719a26b1a9615b6b91667d98e8b585
SHA1 d6bfc79315c59c8ccdcad4f3cc0a645c6e3ceb79
SHA256 389b4b4dc1f6c7d832f47859135263946a73eb3e9110ef5e3b323bd0373a1aca
CRC32 77DD47AE
ssdeep 24:bk0EMm+fTXNmbGhqvTXWr+N/tvJXXs5YFPL5KV3uofUhONThpoRX6yqn5ZSKxPcl:bkZcCGsX/tRsU5Kc5O7pWX6pnHB1w
Yara None matched
VirusTotal Search for analysis
Name bee57236bbd426a5_pluck-pcm16.wav.wncry
Submit file
Filepath c:\python27\lib\test\audiodata\pluck-pcm16.wav.wncry
Size 13.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f93ccdb88a3a2b9c14396671631cfdff
SHA1 59dd4d8f0b34b7ad8e22d7957d323ae25108e8f5
SHA256 bee57236bbd426a5d6a19664a9993d6a7ff81a2e1fc662dc25cfad07e7fb68be
CRC32 B119E53C
ssdeep 384:yzLgtzvVg1Ey8NA6HdCr8DvA+llweiVD+KRVGgA:yHIztXy8O6H0wI/ek+KRV/A
Yara None matched
VirusTotal Search for analysis
Name 92cc16e48749309c_usertile25.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 fe29c1ee16f47fb221043be3d4dbb0e8
SHA1 b72afb8427282e57282e1183f22ac66410a2c499
SHA256 92cc16e48749309c04c82f18ac01a6bf8388f360f64f5a1419e9751ceacefa8c
CRC32 EFAA529B
ssdeep 768:1xOFxzoVSLXgFbD6Ye6MeqCiVklX446OadQeEgy:DgzZXg9+Ye6MNKB
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name d8489f8c16318e52_m_filipino.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_filipino.wnry
Size 36.7KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 08b9e69b57e4c9b966664f8e1c27ab09
SHA1 2da1025bbbfb3cd308070765fc0893a48e5a85fa
SHA256 d8489f8c16318e524b45de8b35d7e2c3cd8ed4821c136f12f5ef3c9fc3321324
CRC32 F9689D6D
ssdeep 384:Sw3BHSj2cLeT+sPzy3EFHjHdi2MG2AGsi6p07i/eo75Y3kmA31dv61QyR:Sw3BHSWjHdGG2Axa7iGZrS14N
Yara None matched
VirusTotal Search for analysis
Name 817b30f52e5884fd_60.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\60.WNCRYT
Size 47.3KB
Type Non-ISO extended-ASCII text, with CRLF line terminators
MD5 43d632d72e4ac82a7a7479aee773d51a
SHA1 7763aa51e382c8665d9492785bcd3b5ae667a9a8
SHA256 817b30f52e5884fdbe9e2b94fcdefde819e451c98f62e52db3f556cb4db2a429
CRC32 649AD3B0
ssdeep 768:WDLb4DQEfxD1kB+Mniwt3h8vnVFjQkTcKLhaHDu:+E5i4MHtu7nkju
Yara None matched
VirusTotal Search for analysis
Name 93408b58dc2f67c2_19.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\19.WNCRYT
Size 366.9KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 8739302de6585af6cc9ce457c54699d9
SHA1 38ddd8ea4410847d18b366ddd00c20a2c7a49951
SHA256 93408b58dc2f67c221ad6725a047dd59911e12dd4df9d9f56a840bde5ef23801
CRC32 87EC1A96
ssdeep 6144:As3wNfVASo2gsh7aeXVn+Mg8AFnQzCkDevIHGliMB1s/uNMJBs3wNfVASo2gsh7N:AsWIah7aewUCGevT/1s/YMJBsWIah7ao
Yara None matched
VirusTotal Search for analysis
Name 6689c52f5f53ac1c_584.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\584.WNCRYT
Size 304.0B
Type ASCII text
MD5 6f4fc332d22adafd32884241365ab78f
SHA1 5c42aae22989c25586ca89cf32ba265dba368ce3
SHA256 6689c52f5f53ac1ce2f8bb8eb4f700c77b2a805354ca147ce29c53c088310fa5
CRC32 F72EA94E
ssdeep 6:1qQQ0Q9z4GW7GWuRR7GWMEZJ17GWvsomN8AFe9Z78hk8uKQckfMheQ+Z:1A0Q1FQomN8AFe0hdQckfM07
Yara None matched
VirusTotal Search for analysis
Name 569d33c1af0c931e_304.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\304.WNCRYT
Size 9.4KB
Type ASCII text, with CRLF line terminators
MD5 0136d1064a910765da865f0fcc757a60
SHA1 599281a0319a9f441db69968a4dbda16f4979f87
SHA256 569d33c1af0c931e2169eed0c86aeb456c1c3f6dd56d271ed3da28d74e4d74ac
CRC32 E8313774
ssdeep 192:HooJDLQI0nhweRm3h2ZZaykqB/rsvuNUJMM2IB20L9Nc8V0w:HUI0nXmx+ZaykqtsvFJMSB20L9Nc8Ow
Yara None matched
VirusTotal Search for analysis
Name afa4ea944cbdec85_733.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\733.WNCRYT
Size 166.0B
Type PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
MD5 232ce72808b60cbe0f4fa788a76523df
SHA1 721a9c98c835d2cd734153bbe07833c6637ecd68
SHA256 afa4ea944cbdec8543242e627ef46d5bfd3766dcac664e7e50cdeef2b352740c
CRC32 C6971404
ssdeep 3:yionv//thPl3xWrA4RthwkBDsTBZttd//HmnFz1P/ZjXlUTqyCIc30ItK1p:6v/lhPKM4nDsptF/HOP/ZjXlUeyCo/p
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 76453fec72c59fd8_148.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\148.WNCRYT
Size 4.5KB
Type ASCII text
MD5 7045e373d8e5a7d379af004c5616313b
SHA1 16d7b17fbf71234989bf356655d6d43c271a020f
SHA256 76453fec72c59fd85648036b5b9fc983d7279cec5818295e0451cf83cf7d264f
CRC32 905DE364
ssdeep 96:GwCzxSy0Kt9C81m/HSzVqUaJf9q/x5a/mETsN:G31RCx/4vZM+EA
Yara None matched
VirusTotal Search for analysis
Name 9bbb11b31601335a_746.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\746.WNCRYT
Size 79.0B
Type Perl script text executable
MD5 5923d47d439c8bdf94af818225a48ed2
SHA1 b1170276337e8060275317e4b5f2a128fd489139
SHA256 9bbb11b31601335a92f516db0d15ff461154b92b7afa1573cc2f0014fa8a92ee
CRC32 17E72EDA
ssdeep 3:TKQWaHM7rWbrX0MxfplPsEdXzN+ov7Zn:HWaHsrwr/B1sK0y7Z
Yara None matched
VirusTotal Search for analysis
Name 823af00f4e44613e_668.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\668.WNCRYT
Size 251.0B
Type ASCII text
MD5 a65040748621b18b1f88072883891280
SHA1 4d0ed6668a99bac9b273b0fa8bc74eb6bb9ddfc8
SHA256 823af00f4e44613e929d32770edb214132b6e210e872751624824da5f0b78448
CRC32 72048B44
ssdeep 6:SlSyEtJLlpuoo6dmoQbtvvNLoQLE3v6aZoQbto+3vR6HK:4EnLzu8CbtvvNBLE3v6avbtF3voq
Yara None matched
VirusTotal Search for analysis
Name 355c833eef164e17_test_doctest2.txt.wncry
Submit file
Filepath c:\python27\lib\test\test_doctest2.txt.wncry
Size 696.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 667b9e39146c6d672590efa7fd590d8b
SHA1 f5dbbea62bc00030af2ab5144abb8d0482de4e68
SHA256 355c833eef164e17e1cffda9115fc9dc086e434f9497feebe61d069b1af87f4b
CRC32 05B8EC67
ssdeep 12:bkE6ir/FTFdrxN221feMsTKkgWADIDZ3VOluvkdN/LmQKMfAtP4YaOXXwViGcBEy:bkvAdtETcWAD6cdJLmQKMsQ1SXwoCY1
Yara None matched
VirusTotal Search for analysis
Name b25f3e0ec29b96ed_583.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\583.WNCRYT
Size 115.0B
Type ASCII text, with CRLF line terminators
MD5 224843e5a360f82f9b4a1361458e119e
SHA1 97c16865217cb68a64795ac3ec9316873434efdc
SHA256 b25f3e0ec29b96eddff3a53afd9453d5175a8f23c7e98ac8572f2a91d1ea15b2
CRC32 B93E3BE6
ssdeep 3:x2SAuMLCgOzrc0AuMLCgOaRjv2qw3XsRmBwAqLOIOJjF7A:ESAuK8rc0AuKPRjlw38RmyzZR
Yara None matched
VirusTotal Search for analysis
Name e3c70e2b06859c26_euc_jisx0213-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\euc_jisx0213-utf8.txt.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d253edae7d1b378dd89716d7553e2a53
SHA1 8721d6001dabc24393842602ea3473d78d00cd2e
SHA256 e3c70e2b06859c26aa81cfe942e7a547bf830174b7756afa8d5ea64c6efbcf14
CRC32 25F2AC1A
ssdeep 24:bk9wTumb2zcY7uTT1yBJAUNOY/aTqnxDr8DEnCyf8HLRtC4+gxdgWKv+ruka5sFv:bkopbA7uThyzrN5yTqnhoUWKvAa5r0RR
Yara None matched
VirusTotal Search for analysis
Name 89d6eb246f44796c_272.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\272.WNCRYT
Size 7.4KB
Type C source, ASCII text, with CRLF line terminators
MD5 df036cbb5f62bae1d74e2080df7d581c
SHA1 b903d02b719607922beb68bceecc8d99e2975203
SHA256 89d6eb246f44796c6c8b1e1faa24f34917cb99a2579b29369d073998683f59ec
CRC32 CDF434E8
ssdeep 192:l79skb4IzIrqbSKGRcdD24lt4Idz/LmRmrVRlinAQ:nsQ4IzapCnLmRmxinp
Yara None matched
VirusTotal Search for analysis
Name 2ad1cfc8f47eccd4_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyautogui-0.9.50-py2.7.egg-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 652f132b8d4acb0cb5cac9368e8c4e9f
SHA1 08983d56cb3b9a8c6914a49778b5a51589702390
SHA256 2ad1cfc8f47eccd4f16682bc0d6ee18d93ac5e37744aa4b29ee1565b17ec25a3
CRC32 17528FB4
ssdeep 6:bkEsDEISxHjj5qd6DpYACWYnqMIBa2Si7yoVrRElMJO7puSWn:bkEsDn4HP8LBqrrSYyoVFEKUtupn
Yara None matched
VirusTotal Search for analysis
Name 76e1195ac14fc760_talos-2019-0758.pem.wncry
Submit file
Filepath c:\python27\lib\test\talos-2019-0758.pem.wncry
Size 1.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 aa4ede824045e648bffcab8eaad2e865
SHA1 a4d3feaeb099fabffe6686046c3cb2ccebf7e8ac
SHA256 76e1195ac14fc760e7d54af5c81718e4beccbbde323da6a5b2bc5d0b252a7c96
CRC32 FC0293B1
ssdeep 48:bkemOJmcvoAW3ZMJhoOV25SIJ2fnV2AqivTU3fmHjO8:oe5umJaORu2fnV2AqivTyfmDH
Yara None matched
VirusTotal Search for analysis
Name b7811e45818366b3_keycert4.pem.wncry
Submit file
Filepath c:\python27\lib\test\keycert4.pem.wncry
Size 9.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 46ac4417c0a7ca25a1acd39de77e94c0
SHA1 298355e7d7c2504c42235739662319dfb56c5264
SHA256 b7811e45818366b3fa9386a9be8c93f8eb2ce31bf9c2bf796e5cc8a54798ea30
CRC32 FF0BC041
ssdeep 192:wbqwBFt6UPZ1+WgHwtk1w/YD46EpqyKaYBjpWEZs5883xU:vWt71et1w/F64qyKagEEFExU
Yara None matched
VirusTotal Search for analysis
Name 9054465f6906564c_598.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\598.WNCRYT
Size 25.0B
Type Non-ISO extended-ASCII text, with CRLF line terminators
MD5 1cd67ea1cf8497d33ded31b2e92b3f68
SHA1 5cd2b59769b9e95d401642643c97abbd2dcafcae
SHA256 9054465f6906564c2368092db9766282e598940381df8b2b35f18a1ce85719fa
CRC32 C0D1C0B2
ssdeep 3:mmdtCtn:fYn
Yara None matched
VirusTotal Search for analysis
Name 02932052fafe97e6_m_russian.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_russian.wnry
Size 46.0KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 452615db2336d60af7e2057481e4cab5
SHA1 442e31f6556b3d7de6eb85fbac3d2957b7f5eac6
SHA256 02932052fafe97e6acaaf9f391738a3a826f5434b1a013abbfa7a6c1ade1e078
CRC32 3AF47007
ssdeep 384:SheftipUENLFsPzy3EFHjHdg2qG2aUGs0K6lyZqmfGGHRblldORZeo75Y3kmA31L:Shef3jHdeG2lGsDOcZxbP7ZrS14K
Yara None matched
VirusTotal Search for analysis
Name e13cc9b13aa5074d_m_greek.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_greek.wnry
Size 47.9KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 fb4e8718fea95bb7479727fde80cb424
SHA1 1088c7653cba385fe994e9ae34a6595898f20aeb
SHA256 e13cc9b13aa5074dc45d50379eceb17ee39a0c2531ab617d93800fe236758ca9
CRC32 5A5826D8
ssdeep 384:SheftipUENLFsPzy3EFHjHdc2oG2WWDFFG5BwKeo75Y3kmA31dv61QyM:Shef3jHdoG2NHG5BwLZrS14Q
Yara None matched
VirusTotal Search for analysis
Name 50f098031344abed_installed-files.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyperclip-1.8.0-py2.7.egg-info\installed-files.txt.wncry
Size 456.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 6bdc773513684a27cdaba8adff9de644
SHA1 2207beb6f45b49c2c0f31901e1eb26c1badbc4a4
SHA256 50f098031344abed4d6d2f827e8e7c92c8d861b50d75d79c6b185a1274e9b2ed
CRC32 444E6C68
ssdeep 12:bkEWDIpYN+XtcCXR9KI85ngv6xlIo74iu6kE0fcjlg6jeTam:bkq3tz9KIkngSxSuFIfcl/jqj
Yara None matched
VirusTotal Search for analysis
Name bf46de0161bdec11_msg_21.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_21.txt.wncry
Size 680.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 ec21b13dcaa4520be85fb8dc84b5f8fd
SHA1 1c5cb41842a7faf15c5411bff1812db45f6a70d9
SHA256 bf46de0161bdec11e0225820d2c4cecc26ae2aef5c99d87e20205f51ba8b821c
CRC32 9E0F94FF
ssdeep 12:bkEjhtDIr/q7dIhfsoKhV41QTvG41JzpALnA8oKOSpv1mjiypUV4y5Tn9BUGFk:bk0htDIruah0pheYvG4r4A8Lfpv0/US7
Yara None matched
VirusTotal Search for analysis
Name 989c779abdf2df74_64.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\64.WNCRYT
Size 7.1KB
Type TeX document, ASCII text, with CRLF line terminators
MD5 9cc396423468f8e94d8df3f314593dc9
SHA1 29f4127ab1eebd1908214827bbeee7c60758a489
SHA256 989c779abdf2df7438e3ef9327d33a23e2adcb694a6476ed1307480d5259243e
CRC32 C10728EC
ssdeep 192:TSURXAxeDRGodyoTt4/JSjapdMh6bIb72P:TrwxeDXdyoW/JSjapFcf2P
Yara None matched
VirusTotal Search for analysis
Name 6507d80071c8a8c2_ko_kr.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ko_kr.msg.wncry
Size 632.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e33017d46603f8cd00996e186603e4a8
SHA1 9b32d46dc5665b59f9cdf4d77d8a7b162d619c36
SHA256 6507d80071c8a8c26603f292281d6ae0be04f851952513578dfc9aabe317e369
CRC32 FC0BE7B2
ssdeep 12:bkEPmHjqTzMPGI2c0IRsC0KhVf6txE8qL/qdsksa+3RaCakAp5:bkVi9jKll6vE8iq2XcTkAp5
Yara None matched
VirusTotal Search for analysis
Name 4654730e3f4dfe76_592.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\592.WNCRYT
Size 86.0B
Type ASCII text, with CRLF line terminators
MD5 07facafb1572bbde899f2e06c57eb07c
SHA1 b4deffd441595353f8ab88125789396fd9ad347d
SHA256 4654730e3f4dfe7628f80c442d841508703fff616773249d9a31f40d93fd7887
CRC32 D64B9E8F
ssdeep 3:+JzcWsFWO6K5oyWCoOfna6+Ce:wkB5lDq69e
Yara None matched
VirusTotal Search for analysis
Name 64f8d39f77df660d_772.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\772.WNCRYT
Size 668.0B
Type ISO-8859 text, with CRLF line terminators
MD5 0be15ade25e06fcc5d07d3e1b752d3b6
SHA1 a1687896383f5bd609da38870efe03505bece983
SHA256 64f8d39f77df660d61a37f71cb464ad0ba0c7ee9fe5f4ab64fd13edb2c079f03
CRC32 99750821
ssdeep 12:jT47jDEWiZT8sbUsoIA4OpVg4WQws+dNnfFzOFh+ydmabaUwSGRl:g3YpZbbo3DrbWHLjnhOFh+ytvwbRl
Yara None matched
VirusTotal Search for analysis
Name 58f27e4011c54c53_442.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\442.WNCRYT
Size 4.5KB
Type GIF image data, version 89a, 140 x 93
MD5 8d6fea22706f8accfd21a9552c94f570
SHA1 a37dc2f469ae04d99b34e4f972041964c599a293
SHA256 58f27e4011c54c53a005d1aec60ef34e3f2e440b07504566a0637dadbcc9e518
CRC32 C0B9E278
ssdeep 96:kfNpVS/tIzSGB/FAC5PglwOOdyKSLkaDKP4TX4HPTydwiMwtlSHOipSaRJ:sjLjB/FAUPtwkAykX4vTNiMwtlSEKJ
Yara None matched
VirusTotal Search for analysis
Name 7656ded0908ace82_pt_br.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\pt_br.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a8cbd1d3f6e688f9e7753e89f2c88ce7
SHA1 2f191c9d8c4c39f099383bc23c5f581a5e5f809c
SHA256 7656ded0908ace82f79ef98f28c781308554e68c894232843f2ce8ddd3602549
CRC32 52CC6F40
ssdeep 12:bkEMv21OsojSsONfRcH4ugK03hWIR9X9S3bKR20HR/NB5I:bkogsojS3zc7gK+ljpHDBW
Yara None matched
VirusTotal Search for analysis
Name 27cf9b982d8b56af_575.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\575.WNCRYT
Size 295.0B
Type ASCII text
MD5 a4b17657c3ba3d87da48d31082e4717a
SHA1 dcae8c2f74f8930f9f67d438b8635efd550f3d40
SHA256 27cf9b982d8b56af3f6d4dc71280a4cde846259e4f7a262e4a9c2213f51d0bf1
CRC32 0C5F8FCB
ssdeep 6:nE0Q7tkLWGkLWuRoRkLWMEZJMRkLWvsomN8AFe9Z78hkbWVL8w18aVEBIcQ3BkmV:nE0Q7+Uv2RZomN8AFe0heWVwwaayIcQR
Yara None matched
VirusTotal Search for analysis
Name fb853902f525bcd5_pystrcmp.h.wncry
Submit file
Filepath c:\python27\include\pystrcmp.h.wncry
Size 776.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 9474f07eeaded3245192d5a018d66040
SHA1 53933bda47ca3d80fc0826a0999745806d6d8557
SHA256 fb853902f525bcd5ed2d08b3c2419796de706904a9cdd36657502a1f56505b9d
CRC32 95249AE4
ssdeep 12:bkEP+NNvtjbeOGLWFS1UAk/Oeok+r8It13XoKxRClYAr+zefkOG9d:bkw+NjzcWFS1UAk//o5TNxRQxizefwP
Yara None matched
VirusTotal Search for analysis
Name c8bf773f931702fe_257.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\257.WNCRYT
Size 4.9KB
Type C source, ASCII text, with CRLF line terminators
MD5 1621caf11b02a3c97b6b2685b5444f12
SHA1 b26207935e55cbd3d406f56a45794e314a87df1b
SHA256 c8bf773f931702fe9e32a8e7f59f0b2877e195f711b5ab76a24754e893117614
CRC32 5BD0DAF8
ssdeep 96:fz+KEO9GHwKk9MLVBJBhE8kQL8QWcvgdQkWl5Xd/wYzd8swzBrJeOtsx:b+e8WMxE8kQLUcv93NIYRj4tm
Yara None matched
VirusTotal Search for analysis
Name a87818ad0754087f_el.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\el.msg.wncry
Size 8.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 effbb9c1a440c06e0fb9b811d85c3dd6
SHA1 c3cea0d567720a8f931022fa3d48809fbcbaddec
SHA256 a87818ad0754087faa970859a0b5b8509dcd433583799ee45a03aa64b0caed99
CRC32 B2D549C8
ssdeep 192:kpWWTTbD2ghmzbXaHZu4p11mDd8s0YfTzx7f2lPM2FBLNvq:TW3bDSXaZnp11U0YfT170HFbq
Yara None matched
VirusTotal Search for analysis
Name dd851bce6cf0f5f6_503.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\503.WNCRYT
Size 658.0B
Type C source, ASCII text, with CRLF line terminators
MD5 4b3b0f43a4f7983dceb9fe86c98d46b8
SHA1 6a3250205e03c7394158b4e467d5ac939733c546
SHA256 dd851bce6cf0f5f6029a35a47cfc6bce3baaf7e28f233428bdd01db4f5557a88
CRC32 38CD6450
ssdeep 12:BJTwhOQanpcnlVHntwiDUpaiiqKIBIlUcqK:DDQ7VNwiDfBqK6MxqK
Yara None matched
VirusTotal Search for analysis
Name 7ff0cb06c85aadc1_238.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\238.WNCRYT
Size 2.5KB
Type C source, ASCII text, with CRLF line terminators
MD5 f4f2141f85df666c95799a85799f211c
SHA1 297e0d6ffbe8f212fe79a6327ce25790c6a1fb53
SHA256 7ff0cb06c85aadc1ca075c12a0b2521c3776415708c0a2b0359f21f7b1f1000c
CRC32 B7D33513
ssdeep 48:ZkUFQawBF2JS5SuZafSu7iS8SEmaovsmcpz:ZlAFFcLau7RTBXtsz
Yara None matched
VirusTotal Search for analysis
Name 066b799a6540c5e8_63.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\63.WNCRYT
Size 5.5KB
Type Python script, ASCII text executable, with CRLF line terminators
MD5 f27556dba17a52b5a8fa3297076c567e
SHA1 4d061e50196d2e8f728e7b2117abdc3f5011eeaa
SHA256 066b799a6540c5e8e003a196eaf6d88d0a5a069ab0dae613af6aee112c1b0670
CRC32 68EEBFEB
ssdeep 96:ByHJ3pm3ZELrHjcHwZRl+1SCaLeTgHIllKuXNoCihygi95iaiIRAii1vtss7MVrj:A37HHjcHIXC4eTgHYlKwirUXRm1vtssS
Yara None matched
VirusTotal Search for analysis
Name 5d5c293fb264d2de_be.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\be.msg.wncry
Size 2.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7305698e253d12a53fc016ef5f98aaf1
SHA1 b5fb22d89b01c6f898517b37dca245cd6de3f470
SHA256 5d5c293fb264d2defd7124019b45d2c9954bc81ff1eade3a1a64621c324b918d
CRC32 2083D506
ssdeep 48:bktjoFNO5pUAHcuQ3zn4gtkQmdOLERJvrOTsGIwfQ7tI8VVeasPnk9lN99g40N+T:ot0aUFuuz4OL2rD37fPsPk9DTZrm7mZD
Yara None matched
VirusTotal Search for analysis
Name 8a1b629477e0b3af_71.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\71.WNCRYT
Size 3.4KB
Type ASCII text, with CRLF line terminators
MD5 cfb61e31123fd203c9458991dd74b314
SHA1 6a8fa7bc866a9ad4c2ddd438b2c3c3f6af140e51
SHA256 8a1b629477e0b3af488f29684e245f5762c7bd86dfced24dfcf8b12bdbd269c0
CRC32 9BD49384
ssdeep 48:Su48Y1BQ1mXwFbzK05bifpLCpnggUmFGb1qv9qYafh8rrGRDBa7H:Su48Y1wmAFKg8pQnhU69rafh8AO
Yara None matched
VirusTotal Search for analysis
Name 686b335b044e16f6_es_sv.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_sv.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 519d4b1ab2de53e6ba720e5d0a3872e1
SHA1 18df7eaddbeba6ab91c3268db78fadd8f5bcd5ec
SHA256 686b335b044e16f62118c449bb622fb8702d91350a9f7e71309956b37cacee06
CRC32 D4CA95BA
ssdeep 12:bkEqwlGnmBqrDL0rkPyiqEb+KZ3fUgrNwCyV0h2MCa8ocyHCJMIK:bk9QGnDHL+kPqEKje2Csva8ozIK
Yara None matched
VirusTotal Search for analysis
Name 59fe744de6c2636d_433.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\433.WNCRYT
Size 7.0KB
Type PNG image data, 420 x 100, 8-bit/color RGBA, non-interlaced
MD5 a7099e08e14f10d8f47a0cd7b8bc003b
SHA1 6e1ad712e4dca6fe8b14921edf8d644b277a6edc
SHA256 59fe744de6c2636df554075ffb1c28aa3f8fd75830434e28c1f85b19eb9d566b
CRC32 0E2034C1
ssdeep 192:rSuXC+KvLz7DPz35YXQoKVQCc3agPVKj12DUm:eaKvf7DL3+fK2fTPVi18R
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name a509acd2e5f29e59_ru_ua.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ru_ua.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 603b06bf3c947422ceb71563c2f25dea
SHA1 53026e9b1041e083640845e18b21d792250ab81a
SHA256 a509acd2e5f29e5994c7e4321afc7938fc09b87c4679a66323b01cfdf6080c77
CRC32 740E1716
ssdeep 12:bkEq+cPo5YJqHCR0dsxMvB+/D0arbAM+pAp6+:bk7Po5yqiR0nvB8jbhO+
Yara None matched
VirusTotal Search for analysis
Name 0d9e6c9ac9b57936_mirroring_common.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\mirroring_common.js.wncry
Size 241.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 0c040f11df18537834c97fbe61c2afb1
SHA1 fa2fc03bd1a69e140f14243ab83e0c847a6fd583
SHA256 0d9e6c9ac9b579367566f77d93da60a5935603231093355616816c03c2c8a43a
CRC32 6E099BF5
ssdeep 3072:AJDbWzK+rF8HayQ5HZrCLedtGNUcOBkwXsbvgRlfxjGVn12Plpcu18jdEgndl7xv:MvWzzwu4byXsbuxs1apPvkDh2+ao
Yara None matched
VirusTotal Search for analysis
Name a3c20d651051cc9d_nmsibqicnh.txt.wncry
Submit file
Filepath c:\users\test22\documents\nmsibqicnh.txt.wncry
Size 470.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 854e92f71482d54d6704496c2bafab14
SHA1 cb0ec68f28f47981336b485a0e5a64ab66288d21
SHA256 a3c20d651051cc9df2b05fd01248541fc097cfeb2cdb390249a1a1c6650deb69
CRC32 F5819FC0
ssdeep 12288:vbW4uFll+tv+mpaFEytI0AYQFk4+1csm23EaTr:TW4Mll+J+mAPI1Zb0g23xr
Yara None matched
VirusTotal Search for analysis
Name c7fc3be23b2ac145_512.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\512.WNCRYT
Size 678.0B
Type MIME entity, ASCII text, with CRLF line terminators
MD5 1909edbc78b2939b3d6ccc40b4fc57f4
SHA1 d391302d62b97479f73febdae8737501fc0c19f6
SHA256 c7fc3be23b2ac145d61da72a5db41fbc561d19d43ef00710781155bd96da4c6f
CRC32 C62933DD
ssdeep 12:3XmyFxxGEYUp8MG886AQcVgQearowgQYf1IcgQFSCgAQrIUAQrIWXgQearowgQrj:3XmWxoErbGiuVtrowiacrSCgSUSWXtrf
Yara None matched
VirusTotal Search for analysis
Name 1af437eff9a80ee9_floatobject.h.wncry
Submit file
Filepath c:\python27\include\floatobject.h.wncry
Size 5.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 baf84636fba042712582562593b79f94
SHA1 9e1f6375598532dc5abeac213d9a79a52f9f8ead
SHA256 1af437eff9a80ee943d6e390d01696b3d65296ef8635ae168cca8b293b7c047a
CRC32 564820C4
ssdeep 96:o+CcVoN6p2cwSxRtHcUUIgobmKJzfdbuDRK7YMt/sfg2R6OdyKw3+8xpJW7lnOdh:6t6YKRt8UUCb/dbwKZ/soQ6OTwO8xpJV
Yara None matched
VirusTotal Search for analysis
Name 874f275ec77fdd8f_chromecast_logo_grey.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\cast_setup\chromecast_logo_grey.png.wncry
Size 7.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 37a2501f424093f7481cb53fb54e8023
SHA1 1863b0e3c243b6229e69c1c01d9a08ec23e228c9
SHA256 874f275ec77fdd8f87cbaa074a3a3495b02c1b0732d071bb7191c97399ecce97
CRC32 695387CF
ssdeep 96:oUvpmHh5RHCVTntXMLi0GdsMgj4bBZcbNM+YlUWscOlSAIZgUc9rpTcSZ1DnpSXx:XxmLbdhxj4bBMOlUHlSALp7f1M1eMW2
Yara None matched
VirusTotal Search for analysis
Name a73217bccf6a6ea6_marshal.h.wncry
Submit file
Filepath c:\python27\include\marshal.h.wncry
Size 1.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e20c62e7cf4aa097992318df2475659f
SHA1 6ab4bb1598654f281af71b4097a136ff4e76ff5f
SHA256 a73217bccf6a6ea6e31972ccb2a594e3f5b08616e20c3496fa4c27733c25af7d
CRC32 F3DB508C
ssdeep 24:bkXQnNd408Bd9S+XpZlL6weOwZ7tfwpP/JjJQQNyukdoDIoF7:bkXQnNq0adU+XptetZ7tfCZJrAu4oca
Yara None matched
VirusTotal Search for analysis
Name 7099681ebd66c38f_entry_points.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pip-19.2.3.dist-info\entry_points.txt.wncry
Size 392.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 663d56fdeba2e75c04654ab5a8511a57
SHA1 4ffc8b53715d60bcd998d254864aea649850453a
SHA256 7099681ebd66c38fce505d70a14c964eeac0a693d31aad32c7943464013e8d48
CRC32 AAFDBB2B
ssdeep 12:bkExX0ZMBvkERUdGSn1vbPph0DeLRnQTugpbvZUymr4Pl/ML:bkcX0CkERvYPph0ggpLZKeML
Yara None matched
VirusTotal Search for analysis
Name ad4453e0a7ebc04d_listobject.h.wncry
Submit file
Filepath c:\python27\include\listobject.h.wncry
Size 2.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3431b9447e77fec4ff66f9eb706c2357
SHA1 46e8742c4e106f179bb660306852490bc454eddb
SHA256 ad4453e0a7ebc04d34ed1cd6218b041de5efc17b35b24fd3a38d95675fd9b293
CRC32 F2FDFB19
ssdeep 48:bkNyKGako+1BiqaNo04S06eYL3f7mhZvL1LrFQEpZX2oXtwlcTR:oQKGan+1KUS06ek3f7mhZDJ+Eb2oXile
Yara None matched
VirusTotal Search for analysis
Name 4a0073b134e09cdf_180.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\180.WNCRYT
Size 4.1KB
Type JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1], baseline, precision 8, 250x283, frames 3
MD5 2c469d94d98375af2821d4a0ffe93f0f
SHA1 b290b573666ee77d49f1498c0548a5129f35a62f
SHA256 4a0073b134e09cdff6a083e01501626a391d4d86962b7b00012df50b46373def
CRC32 F454A851
ssdeep 96:1LhYE4lypP3+c8kAgVcKVnt5sso/xSr4p:1dYHlX0AkcKVt5U0sp
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 1443906e7d151dc9_xtgoutelmxzuthf.rtf.wncry
Submit file
Filepath c:\users\test22\documents\xtgoutelmxzuthf.rtf.wncry
Size 542.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 166610a967b222550dd714d18fc55699
SHA1 efb043d8dbb0af7fc9e250730f4fcf1a2946ef6d
SHA256 1443906e7d151dc90cb6e522bb085037e8dd678147d2129447316a9169e32354
CRC32 DD52A8DC
ssdeep 12288:R0UUorgXW93qkv0Aign/akM9W5YZnTPUPbSikU:RkorgwrsATn9d5uYPp
Yara None matched
VirusTotal Search for analysis
Name e64178e339c8e10e_m_slovak.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_slovak.wnry
Size 40.4KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 c911aba4ab1da6c28cf86338ab2ab6cc
SHA1 fee0fd58b8efe76077620d8abc7500dbfef7c5b0
SHA256 e64178e339c8e10eac17a236a67b892d0447eb67b1dcd149763dad6fd9f72729
CRC32 F4114D33
ssdeep 384:SheftipUENLFsPzy3EFHjHd4Yb2YG2gNZ8a8zV/8j8U8l8x838Z8Q808m8d8T8hw:Shef3jHdZvG23AZrS14f
Yara None matched
VirusTotal Search for analysis
Name 4d22967ba72384fd_73.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\73.WNCRYT
Size 2.6KB
Type ASCII text, with CRLF line terminators
MD5 b17376a5c8d22dd701ca008e6c7816aa
SHA1 6dd91e5fde67b8f923328b18934574a9ffe525c8
SHA256 4d22967ba72384fd7d1e06d58acd7ca26f66ca9092541c721245be753290b18e
CRC32 791CC0F1
ssdeep 48:hCfAXWSJNMr0wbmjX+uijOpNRgUrYDLckD3Ua5:f3Ir0wbEpiaGUcDLckbF5
Yara
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
VirusTotal Search for analysis
Name de25f8fefde5ac98_thumbcache_32.db.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\current\appdata\local\microsoft\windows\explorer\thumbcache_32.db.wncry
Size 1.0MB
Processes 2632 (WannaCry.exe)
Type data
MD5 f6c400cafce3b5e59b3eafe0e9d60400
SHA1 7bb469594ac7814d81e14aac4672cbb58bfdbd90
SHA256 de25f8fefde5ac9840787f1ef2f33624cb34a0d9876221624dbe690366e8831f
CRC32 1BE40701
ssdeep 24576:2MFNm37724+utyz0E4aCEXHJ2DBbIr7NsTc7AUHumSXM:xrGi4hj+QBb+N2c7Aeum8M
Yara None matched
VirusTotal Search for analysis
Name c70d78c5b09a823f_main.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\main.js.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 8293c211ab85962078b1683a78238994
SHA1 159026d52d3afb71c4e13007a59beee290a6f902
SHA256 c70d78c5b09a823f5dab5eab1ac6315a6097d295e48cd6dc20dced93c54dd27d
CRC32 8892A929
ssdeep 6:bkEtN36qEVUrbURCoBz/qh05VUMulBy2SdmL/1MqNpqBpl32/XA97IMOX7awtXBL:bkEfIVujolXPUMCy2Sdm5M4ABplm/k7S
Yara None matched
VirusTotal Search for analysis
Name 0c7b9ee51db4a460_314.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\314.WNCRYT
Size 13.1KB
Type RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, stereo 11025 Hz
MD5 263f463cc93d29413dd1955d560cf70b
SHA1 bc7feb88523009e733c53627ae2aa67bf461b700
SHA256 0c7b9ee51db4a46087da7530ade979f38e5de7a2e068b5a58cc9cc543aa8e394
CRC32 2F666182
ssdeep 384:vEpAW7koAXlsDzNjmdNLdi2odoZ0MTfzBU9f:vESoseDzAdNLdipsTfN2
Yara None matched
VirusTotal Search for analysis
Name 438de9ad201a7c13_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\128.png.wncry
Size 5.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b61e1762c931bd3430e16101b2708181
SHA1 8d0e0d5ddb99cbece9283a45d073366e0d1adbaa
SHA256 438de9ad201a7c13032bb8efb02e8508af6c8771c6051d194e850509f36e10b6
CRC32 FAF840F5
ssdeep 96:o7WEPyrRAipKNYOxt2Jle7eAFC5lLMpdgh/u3kMf9XIol5WwZYpxEqMVWqG0:ElyaMiRxYEKvApdUqPJIEWcmEFt
Yara None matched
VirusTotal Search for analysis
Name 5e785f42126bc4fb_plus.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\plus.gif.wncry
Size 344.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 aa2980d5a02b7cf073537fc330449ddc
SHA1 f0e7c05420bca1d264bdef4fd2dde9a4f1e9c2cc
SHA256 5e785f42126bc4fbcb15b075717ded2f320da2e3b0f0e47d8dc08918a5466ceb
CRC32 03FF6474
ssdeep 6:bkEEDECqb7wq6OMTDJtZ24OMKg8XDGbu0zzuE8cQb/mMe9Hli0/r5KJnPVq5aB47:bkEKEzHSjTDjMa37buKzuEqb/mzlld/J
Yara None matched
VirusTotal Search for analysis
Name 46c6b35f985b1d32_530.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\530.WNCRYT
Size 140.0B
Type news or mail, ASCII text, with CRLF line terminators
MD5 00c166fc52bada08ac8c3f7680373286
SHA1 25157a9057d9b75aedf49ad38d200f4003c7129f
SHA256 46c6b35f985b1d32c4a1618dfa1f48af2d657445b4a214155ff610ee01a894bc
CRC32 70AB027D
ssdeep 3:m6yMfwL1y3H4GGWsMYvlHL7SlyPknWxeHY4MiLN3A9v:BYLCkDvlXSlZnIO/Mie9v
Yara None matched
VirusTotal Search for analysis
Name 3e765c14199a5421_296.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\296.WNCRYT
Size 5.0KB
Type ASCII text, with CRLF line terminators
MD5 b8d3dac6930bbc31f2dd00c0a4c25564
SHA1 d52c8c770911d927f0556811ae665e7b568ea5a2
SHA256 3e765c14199a5421dbd2a2f54ccf6c6edb098ccfe55d004bd813e1a63865136b
CRC32 6CCEC8CA
ssdeep 96:LrSmg1HpOJQCYQPEgdTM6ZwkhzGhrDDHtSaRg2dYlWpJqmuPQx6cdKl9ZUD/PHg8:HS11UogllwkZGtDVRPbJqmuPQxbu9ZUd
Yara None matched
VirusTotal Search for analysis
Name c939693ac847b797_code.h.wncry
Submit file
Filepath c:\python27\include\code.h.wncry
Size 4.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 06825130a48dc681bf91574f5de0331b
SHA1 0ac75347c0213b0d0a420c010aa09338d705a188
SHA256 c939693ac847b79778d89e28de23a55025f85f7a459e1ed8d9ac6edd21bc82b3
CRC32 AC9FD02F
ssdeep 96:oLpL+oB0BA7MikLCypfOa7BmZMoE0OSQWowGHdwe0h8BbvobOJ/i/Zt:SpKoBVYdL/pD7BmZLOpWBKch86bugt
Yara None matched
VirusTotal Search for analysis
Name 5fa739e2cfb70583_sand_paper.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\sand_paper.jpg.wncry
Size 15.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6f7eaf1c3e3605eb6a4e5677de4bf951
SHA1 c2f291274f91ad5f0facdf7a5dd6afbd17ceb7e1
SHA256 5fa739e2cfb705830380f3a09694a9ac467ac48dbf3a2e7f8fdc686965cd36bb
CRC32 7AA57ADE
ssdeep 384:1cRK72aT6LbW+8rUevvv7RLv3XN5AFbWUZ/p/jTKO70bXkL6:1cLaOL36Ucrid/aQ0wO
Yara None matched
VirusTotal Search for analysis
Name 9a59e2abf1840156_543.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\543.WNCRYT
Size 125.0B
Type GIF image data, version 89a, 16 x 13
MD5 e178fbfa06781ff6c0e5a7bfb59a18d2
SHA1 5554e899fa35dd04a33960751350d693bfe8b7d6
SHA256 9a59e2abf1840156e9db8f85a38822fd56ab79a139eb95ec86f1fba1bb87326b
CRC32 D2F8078B
ssdeep 3:CxwJF11ltl1Exl7xlvpdtlNqHJpPRCZncUq5EoByun/En:511l+DhqppPRWdwBcn
Yara None matched
VirusTotal Search for analysis
Name 2981965bd23a93a0_621.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\621.WNCRYT
Size 989.0B
Type ASCII text
MD5 3a3b4d3b137e7270105dc7b359a2e5c2
SHA1 2089b3948f11ef8ce4bd3d57167715ade65875e9
SHA256 2981965bd23a93a09eb5b4a334acb15d00645d645c596a5ecadb88bfa0b6a908
CRC32 6B7C1436
ssdeep 12:4EnLzu8wcm2NkKcmtH3WhvdfjESBToOqepFHvFgdF69dixmem1OMVjeza6O6c:4azu8DtkN3bbJ75pF9gG3U2e+gc
Yara None matched
VirusTotal Search for analysis
Name 13311653af62a8c0_253.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\253.WNCRYT
Size 3.3KB
Type C source, ASCII text, with CRLF line terminators
MD5 bdc9459077ea035032066564600fab0e
SHA1 48f4eeed2bb0cf7cc98862a698d4f198435faf17
SHA256 13311653af62a8c08b781660abae9f7a9610a0653cc98504e0bb0472d4d16875
CRC32 A5D0B6FE
ssdeep 48:+FRtM1sQz0H2nz+iSey69luib4O+2kYYkpnUfjPTItifxP1l1bUuqiEglOnd:ERtYNZOLIuI+2
Yara None matched
VirusTotal Search for analysis
Name 8f1b1db638c12057_brndlog.txt.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\internet explorer\brndlog.txt.wncry
Size 6.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1820e67542a96df5a55a847af1023afb
SHA1 de3bcbdda31335142d31c1deac4cd9269ffeed48
SHA256 8f1b1db638c1205711bbfa50d4787c79227a3357ec68df6e62adac29adb1c77d
CRC32 D4B7B995
ssdeep 96:omxGSCvTcozn2xeXcbzaHofNHy6D/O+AePSq5Zidl2DfgjtyxzJJaLnJd05zw:ySCbDNX2+sHPDW+DaAZi72s0OLJd0u
Yara None matched
VirusTotal Search for analysis
Name 3fc1cd312497bf7c_it_ch.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\it_ch.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a337227087c2df753c3d6187457fe229
SHA1 3775f6db4fdb4e0e757da96bfcc9e243754cbfeb
SHA256 3fc1cd312497bf7c551efbc7f667c3cee7bbd54aad9906c5da7b882186779846
CRC32 3CDFC6AB
ssdeep 12:bkE5nKkh1lJp4OTqAB/2T1tLhuSvv9LLH5GNoNvvp/PvkTb+Rn:bk6X16OFSzvlHok2aR
Yara None matched
VirusTotal Search for analysis
Name a848a3e80b939c04_m.vbs
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\m.vbs
Size 221.0B
Type ASCII text, with CRLF line terminators
MD5 4b7bcb48540207151cd7d632b299214a
SHA1 631518d083f8b27aa82128a2ed0aa1e936eb699b
SHA256 a848a3e80b939c042b17fc2d4e61fedf7d3cae5811de76ecf5e73b4a1b32ca87
CRC32 1F1D313B
ssdeep 6:e+hvbmQpcLJ23fYgJSoPmQpcLJ23fYSK2Fv:e+hDOLMh7OLMeM
Yara None matched
VirusTotal Search for analysis
Name 95747b4f7a1901bf_msg_40.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_40.txt.wncry
Size 488.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 3f4a178270fff085a4d9992c7c0cadf4
SHA1 747742503049d9fdac067e4e8bd2620392627295
SHA256 95747b4f7a1901bfa56836f11c5641e58077f4e3e4040656fd138af84712d196
CRC32 66B8E8AE
ssdeep 12:bkEVqZQD+c4R+yMp1nKo8a+04Q3xvYq19rBqPJ82GCZ4kmwn:bkwqZXV+y1o8fQhvYsrBh2GcfVn
Yara None matched
VirusTotal Search for analysis
Name a58bbb162a72c36d_282.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\282.WNCRYT
Size 3.1KB
Type C source, ASCII text, with CRLF line terminators
MD5 2e6ea512653dedbb8f1f828b0d387838
SHA1 30846f3bf5353c304483cd17fff3cedd7958a3f5
SHA256 a58bbb162a72c36dd48d3c77f8f43621ca99315b29802692506b8f96da12ff6f
CRC32 BE86D430
ssdeep 48:O9YXlb+arCqphmrGZ0x6+f5exvlrOfDww1QyXQq6yrbwPqD8I4gl:Pb+arLgexvkgG3V8I4Q
Yara None matched
VirusTotal Search for analysis
Name b104ec263d647352_185test.db.wncry
Submit file
Filepath c:\python27\lib\test\185test.db.wncry
Size 16.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 83592ce6258ae1832ddde1a4b9e6a44f
SHA1 ecffe8fdf687231d1ce4007aa03fac96568e9ae6
SHA256 b104ec263d647352aa5463604c8499db1e90444457d710f5de595e9f1258bd84
CRC32 0085F9EB
ssdeep 384:JlBFgJlz4/vJMd1nQpjVA6K6Ber+cAbBsDEwQBE802xNMpLUpybG4x+6fdcieD:J/Fgn4/v01nc5K68EVKh2xYAybG4xvf+
Yara None matched
VirusTotal Search for analysis
Name c2da473e55d8317b_330.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\330.WNCRYT
Size 6.2KB
Type GIF image data, version 87a, 320 x 200
MD5 4d10e3a9b9c5cc5ab490962afa9bfe6c
SHA1 59609b8a8f221d3fc1cb58d3bf5c7e58104e3fdb
SHA256 c2da473e55d8317bd1f983638adb729bff1461de590d76f99d8b3430c71e0f6e
CRC32 CD64DC51
ssdeep 192:EeSDPfecM7mHVhEje/tL6qaOdROJ3NZq7wtZ2aGIFD:rGfPV+iL6qa5c7wm4D
Yara None matched
VirusTotal Search for analysis
Name ade3a48859df14f0_526.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\526.WNCRYT
Size 215.0B
Type news or mail, ASCII text, with CRLF line terminators
MD5 03c3c1405774037c6508897c34740c1e
SHA1 a8b50f0cd670da7ba6a4dbb09dad4afd15edd3f8
SHA256 ade3a48859df14f0b7751283a04c1d8cc1c7376c50a0edf11bdd0092744e4434
CRC32 D1D18819
ssdeep 3:m6yx9XWMKEkeIeAtISin/BQyQ+5IeAtRATmlL7Qvqovov1q+5IeAtRATmlL7QvpU:AXmMQ67JygQ8Kqvq7wgQ8KqvGVj
Yara None matched
VirusTotal Search for analysis
Name 51764351ec85ddda_41.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\41.WNCRYT
Size 37.7KB
Type ASCII text, with CRLF line terminators
MD5 a7f260eb0ba84e4d42d95da047349cc6
SHA1 59e86b5b28370b55d19bb0dedafdb8990b3238b1
SHA256 51764351ec85dddada0e539de3c510a2c52864e53867bbc4fec0b5452acc2adb
CRC32 4B9C1CCE
ssdeep 768:w7TXCIJDmXPkVDXzfESsixKioGRmIcxHsABzqZlyGzZhdbzwEduFz5ZJSZGHo5z+:wXCIJQPkVDzDsio+mIcyoz9Gzxbznyz7
Yara None matched
VirusTotal Search for analysis
Name 6ea9f8468c76aa51_197.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\197.WNCRYT
Size 627.9KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=3], baseline, precision 8, 1920x1200, frames 3
MD5 da288dceaafd7c97f1b09c594eac7868
SHA1 b433a6157cc21fc3258495928cd0ef4b487f99d3
SHA256 6ea9f8468c76aa511a5b3cfc36fb212b86e7abd377f147042d2f25572bf206a2
CRC32 ABDD3D1A
ssdeep 12288:BnmIVaIGcSfCEwrDj0FhIrPGuZbspaaWYGo9mfZo0K3tmUx/FAy+aaG7:XWSrD5PDZb7oWo0KB/Ay+aZ7
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 8109a7a5dac3f7d9_295.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\295.WNCRYT
Size 16.0KB
Type Berkeley DB 1.85 (Hash, version 2, big-endian)
MD5 0162c799087900a645c96aa71bd27096
SHA1 5b1eefb783e6b44b071687905f01500b8ff3f40b
SHA256 8109a7a5dac3f7d92e8570f835b1c4c9352782916ab472caf654236241147166
CRC32 35C9027B
ssdeep 3:Lt/1Mvllllplfltt/lE9lllnldllwsGltdl/l8/qqg/LtbYT/ksnlkgNa0//NYen:5Sv/L9cvVlwnXy/3gjRYTssnmn01tR
Yara None matched
VirusTotal Search for analysis
Name f4c43b9e6dabd985_00000000.eky
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\00000000.eky
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d7118aab0b9152adf3dc2ff31fe26bc4
SHA1 7d8a30b55bef50553e65f8102ac6dd7710dd22f8
SHA256 f4c43b9e6dabd9851f039a620a8d5fa7c5d80d44d314576f0f2ff2a70576d586
CRC32 02109BD5
ssdeep 24:WKAvcx9Vdk+J6TsDNT6GsuCgCaFY6+otaFiCGwTMhxYwWCk3JbUM:WKAvc1dTJIsDNT6GsurLFY6+xide3GM
Yara None matched
VirusTotal Search for analysis
Name b51797577809d01c_entities_u.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\editplus\entities_u.txt.wncry
Size 2.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 0fd2cc00efb59855904eadbc0232d405
SHA1 f0637ee733733ee7e575a41af157be70f5b86813
SHA256 b51797577809d01c2fdcca264e338b483a62cd15d03851dc548d0c71ce1d2911
CRC32 243093F2
ssdeep 48:bkIFK0//SksLm3LYyb2oK7fNF2pM8WkdqKivRBW1mprRZic0DmuFDjbd+yCSw:oIw0//Sl1TJk0KYR+z5jboyy
Yara None matched
VirusTotal Search for analysis
Name 58be53d5012b3f45_libeay32.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\TaskData\Tor\libeay32.dll
Size 3.0MB
Processes 1452 (explorer.exe) 152 (@WanaDecryptor@.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 6ed47014c3bb259874d673fb3eaedc85
SHA1 c9b29ba7e8a97729c46143cc59332d7a7e9c1ad8
SHA256 58be53d5012b3f45c1ca6f4897bece4773efbe1ccbf0be460061c183ee14ca19
CRC32 F8747FDE
ssdeep 98304:W5FYc9YouOquJVqrR1LlZRUT83DlJrqd+kq:WrjYouOquJgrlZ283xFqdq
Yara
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 4f32e1518be3270f_129.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\129.WNCRYT
Size 1.1KB
Type ASCII text
MD5 496d9183e2907199056ca236438498e1
SHA1 d9c3bb4aebd9bfd942593694e796a8c2fb9217b8
SHA256 4f32e1518be3270f4db80136fac0031c385dd3ce133faa534f141cf459c6113a
CRC32 88036A29
ssdeep 24:4azu8JLmAQVm/xTsS9CfxTlijQkcjKxFvivn:46hVQc/psJxT8kyhkn
Yara None matched
VirusTotal Search for analysis
Name 09dad3bff208e4d2_exit1.png.wncry
Submit file
Filepath c:\python27\click\click\click_image\exit1.png.wncry
Size 904.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0c79011aa52f432c22fc2048f4c06337
SHA1 3039f3d6f0aef0d49f484ef81aa8a741cc374a7b
SHA256 09dad3bff208e4d2a648f202b4f3fc85c60e847c287d4fa99986cad21057958e
CRC32 3C3288B8
ssdeep 24:bkR1JrVLGktd5pnxctNgupGjiMygMOIoWx:bkRDVLpnjXaLx
Yara None matched
VirusTotal Search for analysis
Name 7bc48ad359298d96_277.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\277.WNCRYT
Size 21.1KB
Type C source, ASCII text, with CRLF line terminators
MD5 3cb3acfff0de84afa7faeae611efb3c2
SHA1 8a89754ca41091f4e35db2d09e33fb8e36fdc146
SHA256 7bc48ad359298d962c14f091bdd89004a69b01387722f96411a2bd8ad3e44939
CRC32 5ECAB433
ssdeep 384:R/PUm3DLYsJRkF6a1VFKlRFKSt9MvzVh8b1kXx:R/PUm3D5J8VFKISb1y
Yara None matched
VirusTotal Search for analysis
Name 8dae0f8ffb908150_196.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\196.WNCRYT
Size 2.1KB
Type Little-endian UTF-16 Unicode text, with CRLF line terminators
MD5 813727f81b72f42cd1d9e65ab8a528e0
SHA1 3b1b0cb967465433c5a40c03116164d38780a415
SHA256 8dae0f8ffb9081500f665573e536f426237e8b9ea3cca29db446381b536ecafe
CRC32 1CB5ED03
ssdeep 48:GA2lj8f0m0+4pNcTpvWoBXUjAIBxSAmYMMMLronQt:lHf0mIQOoBXUkIBxSBYMnHonK
Yara None matched
VirusTotal Search for analysis
Name c10a183c31acc75a_139.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\139.WNCRYT
Size 6.6KB
Type ASCII text
MD5 46b5eee2e4ebd6f602728fda684bd428
SHA1 952cbb8c1aa3c13b3dca7e09186a0f6491744811
SHA256 c10a183c31acc75a3005c161f823bee5d17ecef3cfc024e0094b18d045658d09
CRC32 94DA3619
ssdeep 192:NDRWCV+fMcXoteIORoa53akmRO+X8Bt+YnvEO1:1V+74tXah53akmRPO1
Yara None matched
VirusTotal Search for analysis
Name b22228a1038b64c7_installed-files.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyscreeze-0.1.26-py2.7.egg-info\installed-files.txt.wncry
Size 408.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 297f42270ba54f70b9a2b88dee1d82a0
SHA1 0f1f8c18b164cb575755fce9a14f0ddc68285c5f
SHA256 b22228a1038b64c72d7def63a20339ecc6e4f743bd52593cddf78db0647cb588
CRC32 B49E64FF
ssdeep 6:bkEG1cu6w4tWW9cjUgLyG+eY0xmyWgtWX2bSk36Lo8iMxEk8oK1jp:bkEG1/wWKcJ2N0x9WGL3mokg
Yara None matched
VirusTotal Search for analysis
Name 0f24e66aacb94dcc_pyarena.h.wncry
Submit file
Filepath c:\python27\include\pyarena.h.wncry
Size 3.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 834c578c9a04525123e4e1b461103c51
SHA1 7d43ba040fa4e14427813db5bf564388c6dd9881
SHA256 0f24e66aacb94dcc1be0141bf3bcc7e7d003dec231a3887330f4250cb30c1488
CRC32 2C968205
ssdeep 48:bkIK7twhJrKr9Fgz+tb4823x4OdTPvPd2y87zTGTvf8QKR/CEEKZRnDxDXpKFib:oIK7tw490EbeB4OdTPd2yKzI35fcnDxn
Yara None matched
VirusTotal Search for analysis
Name 9dde341957aa40a4_usertile22.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 7f11dc0cd9a1fd3976b832cfacd86a94
SHA1 fb48152c39232f0688f9af0726a9aff2a118ef85
SHA256 9dde341957aa40a44a8860293780530dcdcb0e6b659ebbec7991c2e1c659ed8b
CRC32 70CF063A
ssdeep 768:ZrGdPHxIXzTkAv07yZ66hWfN8zEQ4CIAEgTt8rKVE9QfSl:Zy0zTFvYyZ548zEQ4dAFTlVE9x
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 579c95e7906492ab_pl.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\pl.msg.wncry
Size 4.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ec642ddcbbe411f6355771a79e4708b4
SHA1 b8861a32db2f86f380130992f3b7cd60e9345869
SHA256 579c95e7906492ab6324149de4e245182b3daaec33021eeb2d1e1657633292cf
CRC32 9628EBF6
ssdeep 96:oMwYxzyF4z3isM+E141hFHQ17Yq7+2nD23x0a0CsMrw:mYxzyF4LMKzw1B7+KGx05H
Yara None matched
VirusTotal Search for analysis
Name 45369c1c8853ee34_153.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\153.WNCRYT
Size 6.9KB
Type ASCII text
MD5 202dc42c5da0f0aca88b1b4c30e5381b
SHA1 9a7cc7afbdf37c7937589e7f212abc6e3f260d55
SHA256 45369c1c8853ee34c5b65c742c6ac3e03e1399e64c0958b5e4e4a927e8d30310
CRC32 E6A8C92B
ssdeep 96:NUEBGhT4YsVL3L7Pkhx2xSrw02lOzFAnxS/j49cD/qRjGSQvN8Nfo5hgV9aoTRZ/:grAPJGF8mq+WRKOGcRmRu
Yara None matched
VirusTotal Search for analysis
Name 297f8bec523aac9f_es_ar.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_ar.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 d51b6c51ce18639e48598d4ac8ee50e9
SHA1 4ff38a1f342d2219337acaa3d84431bfeba72fda
SHA256 297f8bec523aac9ffb68fe49c82a892abb9d6871a1689815da80cb72d7f25001
CRC32 C4DB7FFA
ssdeep 12:bkEmNknZSEAEke2RPEznW29DkxZ9qlQoekCK+cqQgnB+P3zm+x:bkiElWzNDk/9q9scfG8vzV
Yara None matched
VirusTotal Search for analysis
Name 35adbbb21115b1b1_es_cr.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_cr.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 221f3ea8bd37ef8219e0b25bab904afd
SHA1 07592bd83d0b321a916e6f77f50cb1740da61f24
SHA256 35adbbb21115b1b10f6fb13dd68e4a018a1b1e0d412fc55004d2381ad1b010d2
CRC32 AC02D98C
ssdeep 12:bkEDrpAL64OeTpNBFeAmIX1UiIfgC2ITKlgwa9DMpUzNZAjicc:bk8AL64HbF6SI4uKPoMpQdt
Yara None matched
VirusTotal Search for analysis
Name 6c592a7b68342271_pgen.h.wncry
Submit file
Filepath c:\python27\include\pgen.h.wncry
Size 552.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 09379af6dd326801433d11933ff0d0c2
SHA1 e97ab3d2b5832afb17a9db455fe39488880d1c7e
SHA256 6c592a7b6834227129831dc603430287655caa909698b0742a10af61b6874e17
CRC32 FBD90CD0
ssdeep 12:bkETcOHjQIiPEE+/oSxuNoGj1RpZGJbviF3ljhTZpSUPJCkX70:bkVOjQ7PE4b60Wd83ljF+MRr0
Yara None matched
VirusTotal Search for analysis
Name 25c8298ebb00deaf_thumbcache_idx.db.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\current\appdata\local\microsoft\windows\explorer\thumbcache_idx.db.wncry
Size 3.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fe64d9c27ae37dc189d267b0e595c50a
SHA1 d20cdf71dc880596ee99be4558c477fa7ddad7c1
SHA256 25c8298ebb00deaf75cd3fcd7b271206141a422a6ed8c0fde582c12f075bc2ab
CRC32 8EB6FCEC
ssdeep 96:o7Lrve9D/4CqWnqWs8Yc8wP19p4t/YnOu8W9L2geZC:y/S4Cq/Ws8YcL743q8ZC
Yara None matched
VirusTotal Search for analysis
Name dcca041e74d5ba28_icon_16.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\icon_16.png.wncry
Size 840.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 eecfd60c24ee4de1d7c558230f56ce1a
SHA1 5c4e4601dd3c07915532fe01df169085ac15ff44
SHA256 dcca041e74d5ba28b02853dbf54cf4f18bea12cadce1699e19e9e44f5f1117b6
CRC32 3912F442
ssdeep 24:bknxmvFULW62D78cEb3shqTAwLr/uyIoYZav+w:bkAvFUyob8hqEwGhoYZLw
Yara None matched
VirusTotal Search for analysis
Name 8aba5eb2b64cbfa5_gb18030-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\gb18030-utf8.txt.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5b315f75fa04ca3153cb439de72cf793
SHA1 244329906ab53e58d38cfe43cca15a644f59f167
SHA256 8aba5eb2b64cbfa58f2dc16c6a1cf5a00afa9edee29444dff449162a14a6cce6
CRC32 BEC97BC1
ssdeep 24:bkrALX9PfEYgqcHegf9XD2RElIuiHSJ7Xz3zV6Hs8zBKiDTH7ufbW5bOT9B/FIv8:bkkLtBgtl2RElIbH+7X7Od9jDvuKOTPF
Yara None matched
VirusTotal Search for analysis
Name 9e14d8f7f54be953_106.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\106.WNCRYT
Size 1.1KB
Type ASCII text
MD5 46fd3df765f366c60b91fa0c4de147de
SHA1 5e006d1aca7bbdac9b8a65efb26fafc03c6e9fde
SHA256 9e14d8f7f54be953983f198c8d59f38842c5f73419a5e81be6460b3623e7307a
CRC32 1705A5C7
ssdeep 24:4azu84VBVgqoLpYDThoLZDT25KNWg1gqNvEKvOAl:46nNYPSLZP2ZVqJTO+
Yara None matched
VirusTotal Search for analysis
Name 2674ab36aee073fa_readme.cpp.wncry
Submit file
Filepath c:\users\test22\documents\readme.cpp.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b35a759356900cd6e657c47b1c908f07
SHA1 74a2a1218947dd26b46fa73d023c174f697954ae
SHA256 2674ab36aee073fa91287719e338fdc61939b7f6a77f9dc9e8fc970155211b0d
CRC32 579E8FA6
ssdeep 6:bkEKzzC64Xccy3rrktgTrOSFLSXKIKR1xzRtsNbb1uLktcRn:bkEKzurBerrktB0SazFRib1uLkAn
Yara None matched
VirusTotal Search for analysis
Name 20e16a4eb99cb6be_pythread.h.wncry
Submit file
Filepath c:\python27\include\pythread.h.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2b752dca83d55094b3d757cc865a1a03
SHA1 bd40389b59afe5bcb2d1784263ea7225f0f3733f
SHA256 20e16a4eb99cb6bec5767d9645e4d080461ed43ecd1d43aa26f1c85056ac9422
CRC32 BC6831D8
ssdeep 24:bklq/WbCnki1r9lrMqZjm4+EPPs7v1+07QANl3XPrqVE+WGqqzDj63a4H+:bkw/+Cnk25lrrZjm41idQANNPvPqzfbf
Yara None matched
VirusTotal Search for analysis
Name 49f2c739e7d9745c_m_italian.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_italian.wnry
Size 36.0KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 30a200f78498990095b36f574b6e8690
SHA1 c4b1b3c087bd12b063e98bca464cd05f3f7b7882
SHA256 49f2c739e7d9745c0834dc817a71bf6676ccc24a4c28dcddf8844093aab3df07
CRC32 7913256A
ssdeep 384:SheftipUENLFsPzy3EFHjHdR2AG2c/EnByeo75Y3kmA31dv61Qy9:Shef3jHdJG2cQZrS14R
Yara None matched
VirusTotal Search for analysis
Name 0f404764d07a6ae2_334.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\334.WNCRYT
Size 10.7KB
Type GIF image data, version 89a, 354 x 520
MD5 45d9b00c4cf82cc53723b00d876b5e7e
SHA1 ddd10e798af209efce022e97448e5ee11ceb5621
SHA256 0f404764d07a6ae2ef9e1e0e8eaac278b7d488d61cf1c084146f2f33b485f2ed
CRC32 AFA203B5
ssdeep 192:d+nY6zludc/We/yXy9JHBUoIMSapQdrGlapzmyNMK1vbXkgMmgFW/KxIq3NhZe:YnY6p4c/OCHyowaGUaCcMK1vbXNwFW/l
Yara None matched
VirusTotal Search for analysis
Name 138c240382304f35_333.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\333.WNCRYT
Size 1.6KB
Type GIF image data, version 89a, 43 x 64
MD5 b226cc3da70aab2ebb8dffd0c953933d
SHA1 ea52219a37a140fd98aea66ea54685dd8158d9b1
SHA256 138c240382304f350383b02ed56c69103a9431c0544eb1ec5dcd7dec7a555dd9
CRC32 47ED8FDC
ssdeep 48:PF/mIXn3l7+ejbL/4xsgq4sNC6JYp6s/pmp76F:/1nHL404raM/op2
Yara None matched
VirusTotal Search for analysis
Name 9a75d212ad7c0db6_tm01793058[[fn=가을]].dotx.wncry
Submit file
Size 56.7KB
Type data
MD5 d7e376ee1d4b0152c17d7787b01d9627
SHA1 456e38dd7d032317be0ca1c0c870640700d698bb
SHA256 9a75d212ad7c0db639cf8edc5e208c308d03a836c3ae1805f88caa34f5e3d2a9
CRC32 5DDF8675
ssdeep 1536:y9VnK6DiDf2sLbqQpmtIWJEftI266z5ENQYYBS8Z:y9pg2sLbqERWJEFIr6lj1
Yara None matched
VirusTotal Search for analysis
Name e538f8f4934ca6e1_341.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\341.WNCRYT
Size 5.3KB
Type GIF image data, version 89a, 100 x 100
MD5 048afe69735f6974d2ca7384b879820c
SHA1 267a9520c4390221dce50177e789a4ebd590f484
SHA256 e538f8f4934ca6e1ce29416d292171f28e67da6c72ed9d236ba42f37445ea41e
CRC32 4316D8DA
ssdeep 96:+EqG96vSGfyJZ26G6U1LI7nTD2enhjc+2VBnOqcUERVIim:+46KcyJI6G6uU7/LhjlkhQR7m
Yara None matched
VirusTotal Search for analysis
Name 149538ecbbbd6b61_326.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\326.WNCRYT
Size 1.0KB
Type ASCII text
MD5 6e3ee31ff13a2318c369fefa56bcc59d
SHA1 4aa92045c8903456cd0d60f02c6c98375b53b140
SHA256 149538ecbbbd6b6179d4657946b71ebf8e7b15e5b9bc4ba2af68399536cb6bef
CRC32 840BAC9E
ssdeep 24:392cN47i2zlGnjWGGAXayXspXFjXFdgdsHmjkOjerdyGo7:NN47iclGjWGGAh8pB1+mHA9eRyGo7
Yara None matched
VirusTotal Search for analysis
Name d4f4f4eaf4a8f356_topbar_floating_button_close.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\images\topbar_floating_button_close.png.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 bf19d36014a10fbd361b76b547bd6394
SHA1 2f143615ccac85fda353b90c25cccb3af090ad77
SHA256 d4f4f4eaf4a8f3563341697240c8a8b2c9d99d75394a72e9381b996ef19c7ad6
CRC32 E46DC488
ssdeep 12:bkEgGny29sPSvx1MhDlmgs6qEz87DLcDGVCAgX8y:bkRy19sPS51M3m56cXLAGVYXB
Yara None matched
VirusTotal Search for analysis
Name 18f8457f73600db7_warning.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\warning.gif.wncry
Size 472.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a7b59f1db259c866977096b31b10d62e
SHA1 e225c0b180f1bcf9b2fe78c09ecdbb1246bdee4e
SHA256 18f8457f73600db71287965e12f269f454f670f1d3b177a2319e34801263b0d2
CRC32 3D972983
ssdeep 6:bkES8YHTNxJMuiHyXYPG/LUGTWJpnBj6q16CMXQAgjnrN/v/Eg+ivYxBCb73lXdC:bkESdT1GyYawGTWndMXKjdvhRYK9ts+G
Yara None matched
VirusTotal Search for analysis
Name a25a6b4b030cff6e_450.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\450.WNCRYT
Size 3.8MB
Type Microsoft OOXML
MD5 53a6a39fe5bca8b62a70e4bb76b58dc0
SHA1 0b8ed75abc2201c3261189d6ab6e2a05115a9682
SHA256 a25a6b4b030cff6e803ab17ff33a7e4313270a66977dfc270409ea84910f5b18
CRC32 2DA4DAF9
ssdeep 98304:HVcwFm3wFP2YXwFP2Y3VcwFmEBy8JuXOqKuT5NEFBjOPhSxk2uK:HGwF20P2YX0P2Y3GwF5BZJuXvK+nEfjt
Yara
  • zip_file_format - ZIP file format
  • docx - Word 2007 file format detection
VirusTotal Search for analysis
Name 95e23938f9142803_572.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\572.WNCRYT
Size 10.0B
Type ASCII text
MD5 83ef0dd9006f3338d7000e3bbb67f39a
SHA1 b3ef37bc0084b263d51a6481f1a8abc5417bf51a
SHA256 95e23938f91428039a425f404ec9b7820bbe0c0ff7dc31fbeb10bf9cb18f1fe2
CRC32 5D79E319
ssdeep 3:be2n:q2
Yara None matched
VirusTotal Search for analysis
Name 8523e393e3d8b29e_license.txt.wncry
Submit file
Filepath c:\python27\license.txt.wncry
Size 38.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 47832a6495aa4ee8cb2d214c12e294ad
SHA1 bc97de926a89d82c1d3de4b0cb3e7f5ca14a42f6
SHA256 8523e393e3d8b29e06da38609decc05bc6d6dda7f4e62305e6da3b185bd1c55e
CRC32 4664CBC8
ssdeep 768:5u2bgkdFK5uGAm3JnBrA5BpXaAsz1A+efj0MdG36y:5nbZEJdB6BpqAszKNfj009y
Yara None matched
VirusTotal Search for analysis
Name 611fe4feb0fb3a8d_152.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\152.WNCRYT
Size 3.9KB
Type ASCII text
MD5 1f04930642b3f4a9f16f11cc674b56a7
SHA1 1af829dd0a4175af35ded50f530b4285f7a174fb
SHA256 611fe4feb0fb3a8d7bada328b6af65c5be9704df334bccd55b5e736eaa0a898f
CRC32 DF2AB0CD
ssdeep 48:YmBmHHCnBbrvRjfgxtilIUkQIPlYwCC4x+hrmK1VZi:YmAncxVMtiXkPl2xomUQ
Yara None matched
VirusTotal Search for analysis
Name 4975de46079e6c17_ar.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ar.msg.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 25508a169ddc719634dbde2066b4b342
SHA1 db38eba5a0628ad37e43d0be90a5a8f99c0668d4
SHA256 4975de46079e6c17bd599ac6449dc09a3bd47f817e2eba29c3307255f7fcd7a5
CRC32 98B8EE1D
ssdeep 48:bkKhJ+krirBb+KRHbTuPnOnOnPYxhAMcZY/9C8OaZs1OBSHKJvJ7Y/NU:oI+AiNb+e+PnOnOnPYxhvcao81+1O0Hm
Yara None matched
VirusTotal Search for analysis
Name d05948d75c06669a_681.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\681.WNCRYT
Size 259.0B
Type ASCII text
MD5 8261689a45fb754158b10b044bdc4965
SHA1 6ffc9b16a0600d9bc457322f1316bc175309c6ca
SHA256 d05948d75c06669addb9708bc5fb48e6b651d4e62ef1b327ef8a3f605fd5271c
CRC32 D3508037
ssdeep 6:SlSyEtJLlpuoo6dmoChFflD/LoChF+3v6xH5oCh++3vflm6PYv:4EnLzu8IPflD/ne3v6Tl3vflm6q
Yara None matched
VirusTotal Search for analysis
Name 3e92d288b6a8be74_721.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\721.WNCRYT
Size 160.0B
Type PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
MD5 c5b9024592b3e317ca10b288a3e63fbf
SHA1 bf6e848fb4152ddd264843e1528f04699bc36701
SHA256 3e92d288b6a8be741ae271f476dc0a2d925d7bd0e312d10b314133d5c73c24d6
CRC32 410B87EC
ssdeep 3:yionv//thPl9vt3lGsLDLcmk624J4nm49vHADYl4vn/0bUvpvfK6AtxtH/bp:6v/lhP/LDLcmz2jm49fADYli/0bUxK6U
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name c194ad1b9d36b3ea_sbyekmdwyn.docm.wncry
Submit file
Filepath c:\users\test22\documents\sbyekmdwyn.docm.wncry
Size 687.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 55206a2c019a18f11caf9f3a1458c906
SHA1 72e19dce3820bd35542ef3fd49cfaf62be2eb16e
SHA256 c194ad1b9d36b3eaeb0a24a7882c4bcced2870493d97c994389204834baf71cf
CRC32 C2F925D4
ssdeep 12288:fu1FUAiSBxTde2gcbfKgUs4CF83xD9WQXpck9U559guDYoKDgQahbw:fuHBx5eQ7Kgj4CmSQXtWSoKnx
Yara None matched
VirusTotal Search for analysis
Name 91cca8972e255b13_432.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\432.WNCRYT
Size 137.6KB
Type ASCII text, with very long lines
MD5 a758e946d735f56f1ab372fbab63ed8c
SHA1 1b77f290b2149ba6a3e6dbfdd820af3f24420036
SHA256 91cca8972e255b13f383abf8df3153a9ac33b990b5022f42c206dc3da90f729a
CRC32 ABAC7A19
ssdeep 3072:GmBE7IJXI+JCKo4JXs4N0GFqrOsq2wDI0Sy5g:pbJXIRWcu0GFqrOsq2wDI0Sy5g
Yara None matched
VirusTotal Search for analysis
Name 2610667d43cc765b_msg_37.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_37.txt.wncry
Size 520.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 5104bec2b4c6f94b6e0c4ceb024486c9
SHA1 d16e4e1b984c129b8e8dfed29229078661e20a64
SHA256 2610667d43cc765b389fef83086863da2db77a10149e415e5d5ba34f7e04d188
CRC32 D56E65E0
ssdeep 12:bkEr5bsJ7xNSndWUtrtbN5cSdT2crNrctDQ8GVeo1U7a8KPsPKlG:bkubsJNNNEbNKoFcm8EADKPsPKQ
Yara None matched
VirusTotal Search for analysis
Name 86998e0c8e3b4bad_15.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\15.WNCRYT
Size 898.8KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 1e807734b12b90a036a18d86bea9ad02
SHA1 da988ac25239b7e7a6d60fbe73a2881c477de893
SHA256 86998e0c8e3b4bad82f04b765168f42141c2fe64780af590ab25b8cd79faa3c2
CRC32 8C757416
ssdeep 24576:lUcKCCek1FElKUcKCCek1FElKUcKCCek1FElKUcKCC1:Kcw1i1cw1i1cw1i1cs
Yara None matched
VirusTotal Search for analysis
Name 0618d6fc5a05288b_usertile16.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 d342c2b5f3d16dc992db22cb737ad617
SHA1 615a98744fb22809454b706174597a4d6b6d128b
SHA256 0618d6fc5a05288bb126eb258fccfe7697e194022a57206671a172a39bc5e486
CRC32 40CE8FB5
ssdeep 768:pBe2w4gygwGeTXlwKkSX5e2AcjxGJ8lrQOoZVzpswGuKXBSeJFankmO0p:p1XgiaHSX5myGJWQ9ppslPZ7Q
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 957d58061a42ca34_libevent_extra-2-0-5.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\TaskData\Tor\libevent_extra-2-0-5.dll
Size 401.7KB
Processes 152 (@WanaDecryptor@.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 6d6602388ab232ca9e8633462e683739
SHA1 41072cc983568d8feeb3e18c4b74440e9d44019a
SHA256 957d58061a42ca343064ec5fb0397950f52aedf0594a18867d1339d5fbb12e7e
CRC32 5B503C1B
ssdeep 3072:oLQzG3CaDYuKCsZW9p2M8suCOSNKOM0LE5BtBsxvQkVgA2+FOYtLEgZEVPSm0aQY:oWHMACLoYaQ2bj+b0pJ
Yara
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name cf14a3b7dedbffdb_shadesofblue.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\shadesofblue.jpg.wncry
Size 4.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 31278a1b1bb87b4918c9c1051f6be784
SHA1 d2bc483396a96a2db595db6999ade038d3a379ca
SHA256 cf14a3b7dedbffdb21959e6aa9fb9bdf1874ae064ef16f666c41f2499b466bd9
CRC32 A3252412
ssdeep 96:oEaBsoFHITplZgMq3Ia9WhIAYdSomHhKTjwkysMMF0tSnezhH+Hk+2Xvbl0W31:YqoIZVmWhIAY7jwkysMhtztWD2Xv5v
Yara None matched
VirusTotal Search for analysis
Name 9937f1f840a067a5_fileobject.h.wncry
Submit file
Filepath c:\python27\include\fileobject.h.wncry
Size 3.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4b7c1d5f4f830154c01e2450a222514c
SHA1 68241c51d45ffdfc783475828dde8b25a2026894
SHA256 9937f1f840a067a5c2ef4544005986506ca963dd8efa61090051ea88abcfa323
CRC32 7190814D
ssdeep 96:ozHimZG6eUa/mHpj3UNrJUvY8GaXRXdR/2SnxzsetvOkVHwm:YnXa/4pQNrO/GaXtrpxzsgmkVHX
Yara None matched
VirusTotal Search for analysis
Name 7c98d566a13fd599_541.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\541.WNCRYT
Size 120.0B
Type GIF image data, version 89a, 15 x 13
MD5 56c144caa9a420c26a47106a53c9d530
SHA1 bd3c46df953ab712c847d12d03bc3f6bac4fa0b3
SHA256 7c98d566a13fd599d1c11a375f387fef69b6c595c4f18c5d88c188a860be0e55
CRC32 E1021D7B
ssdeep 3:CCHaRRhtldzJ3VQHDtVuI5BIvkCdoIRzen:1HaRRhtJ2jttgwIRy
Yara None matched
VirusTotal Search for analysis
Name eab04bd5714fbd2e_347.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\347.WNCRYT
Size 3.2KB
Type data
MD5 ba9b220724249d3cfc73cf7e98a4ee56
SHA1 3d3238cb843d11ae4f9d6d000ceaf4e3c06ea039
SHA256 eab04bd5714fbd2eb200189b11331ff2c29a330b3c209006eddabf552a43b7d0
CRC32 26AC409A
ssdeep 12:ujtkQUS+Qg3kEgsAsThgANLlCR/RkPthOMYhBEhnaVIRh5tfw/AwxSH/QhiY1Nlv:ujaQvG1g3tU1erEdxR/ttNQZVX/
Yara None matched
VirusTotal Search for analysis
Name 306ed87bc1145fa6_setobject.h.wncry
Submit file
Filepath c:\python27\include\setobject.h.wncry
Size 3.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8b57398bebd95be1e945eafb786baf87
SHA1 e25fad2b1fdee4d84512eef044d6c85232e43044
SHA256 306ed87bc1145fa6a8f21daf48674ff7a825e3fe6db5c5d5aa42cc08f1df9c0a
CRC32 D183E6C4
ssdeep 96:orkv0lrMwEg/mDJ66SgoOXqsIwg4jkkU0K+CB3IBDz:X0fExJbZoO6sxg44OK+CKN
Yara None matched
VirusTotal Search for analysis
Name 77957d6fed6c7aea_236.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\236.WNCRYT
Size 2.0KB
Type C source, ASCII text, with CRLF line terminators
MD5 877c6f377081f19d94ee60e7dbaa24f0
SHA1 02f83e1f9733354c726b799d608c31fedc65b1c6
SHA256 77957d6fed6c7aeaddb0c84af8614aada32c9312275cfb6addd37814f1699624
CRC32 6EAEF831
ssdeep 24:Gf1NwCCEA69uZB/VzXYqs3LUJ/tKa89tPhBB4gCPZc1jPyeW1zSx/Pt/L4kopRM:Wwu9uB/uqSUezv2hc1+rpQj
Yara None matched
VirusTotal Search for analysis
Name 6767115fff2da05f_108.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\108.WNCRYT
Size 1.2KB
Type ASCII text
MD5 6695839f1c4d2a92552cb1647fd14da5
SHA1 04cb1976846a78ea9593cb3706c9d61173ce030c
SHA256 6767115fff2da05f49a28bad78853fac6fc716186b985474d6d30764e1727c40
CRC32 8A1A5A0F
ssdeep 24:4azu8qVXVDWpXMVmDz1ZVcWVzbQ1/xZ9b3eYXvhv3eT3:462hVW5JDz1ZVUbpfV83
Yara None matched
VirusTotal Search for analysis
Name ff86372ce43519d6_171.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\171.WNCRYT
Size 548.1KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=8, datetime=2009:03:12 13:48:32], baseline, precision 8, 1024x768, frames 3
MD5 8969288f4245120e7c3870287cce0ff3
SHA1 1b4605b0e20ceccf91aa278d10e81fad64e24e27
SHA256 ff86372ce43519d675b8d8d29c98e9ccbe905d400ba057c8544fa001fa4d8e73
CRC32 5CB7A2A3
ssdeep 12288:tCk+WvjNNND+0MEKgv0i4qTAlK5tRebl4usL+++YGXh7ZBbL9xdc8TN6fC:Ak/vjf9+0igp4W55TeId+/vpB6K
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name acde808e15731123_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\128.png.wncry
Size 5.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2af83e99b3c8a96ab846bc824af7c312
SHA1 a41027d142868f5173db40f7c4e56f89aaca8102
SHA256 acde808e15731123aa632f0da019f86661e40f3b64b02b5b6c83f5c669cb6a91
CRC32 AE91B9D6
ssdeep 96:oK8SHH09NUNOIlmNpBNurDCw9qYSUvqq06WeB0sKgnIxSPrdE3yWjLO:WgU9iEIl8VurDx9qnwqq0lgIxO2NjLO
Yara None matched
VirusTotal Search for analysis
Name cbf972f4e8152570_470.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\470.WNCRYT
Size 404.0B
Type PNG image data, 36 x 20, 8-bit/color RGB, non-interlaced
MD5 0f30933db193a9852f46f0331f0e0ae1
SHA1 5e0243368f97a8bd6c749442f3fbcbc641bc1aec
SHA256 cbf972f4e815257076b2e751b6fbc18bad303d22b0a68ae8cd9ffddb151d1f39
CRC32 712940D1
ssdeep 12:6v/7W/NtVdBSk6bxD9mDD3YMnEEDBQ7W5N:tt756Li3dEE+7W5N
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 937bf53595308fff_tm01840907[[fn=수식]].dotx.wncry
Submit file
Size 39.8KB
Type data
MD5 9be6cc7117c21446a34f41e693dd01ca
SHA1 c70f44e305039d714418ecb2e356ce7c4ba1ff14
SHA256 937bf53595308fff4ef713fce2bd8f19835713f9482020db8da84f28dbd6585a
CRC32 C8B83A86
ssdeep 768:t4phyNV6BHzbjxWSmioKfRtD/Vym29vookgaa9OjjKrRGpii3nSOi4Uo6:t6hWV6BTbcStzpthyVg4t9GJ3nS86
Yara None matched
VirusTotal Search for analysis
Name 5daedffabbb37cae_sitesecurityservicestate.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\profiles\qxo5wa6x.default-release\sitesecurityservicestate.txt.wncry
Size 1.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 faa3a758f0df36b5071d3e6c340f1f1f
SHA1 ab317968b02486b642d4902c2016b904aa3e9522
SHA256 5daedffabbb37cae5a975e21c24d5f2d05aa131c28fd6f98e5aeaa77478ec20d
CRC32 E0EE1CA3
ssdeep 24:bkrdVLJXz5rRPojdzdGdmTylaiv4H05qMGLf:bkJNJ9rCjdzte8iv4HMvGLf
Yara None matched
VirusTotal Search for analysis
Name f24ddcc7ce24fd7b_es_bo.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_bo.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 91679c358169a5b1690493c603fe0b7d
SHA1 526aa0ff355aff2a0b01278cee0fd2766b2fe449
SHA256 f24ddcc7ce24fd7bd3efff2d1002881f48dd69dac21048c312290b6802974af6
CRC32 050FE2FC
ssdeep 12:bkErBP1f1z1QeQPKi37wjxLfGe2XZLwGT0rn:bkiaXY1f/iw7
Yara None matched
VirusTotal Search for analysis
Name db81643ba1fd115e_671.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\671.WNCRYT
Size 251.0B
Type ASCII text
MD5 a285817aaabd5203706d5f2a34158c03
SHA1 18fd0178051581c9f019604499bf91b16712cc91
SHA256 db81643ba1fd115e9d547943a889a56dfc0c81b63f21b1edc1955c6884c1b2f5
CRC32 17E0EB5B
ssdeep 6:SlSyEtJLlpuoo6dmo0kGvNLo0F/W3v6aZo0kT+3vR6HK:4EnLzu8NGvNS3v6aQK3voq
Yara None matched
VirusTotal Search for analysis
Name 32a0285463efd8fc_topbar_floating_button_pressed.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\topbar_floating_button_pressed.png.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 ec44ef96e0d967059d9b5695c7bcdd3b
SHA1 889aafcfd8d2656afc9a88ab91926be3844925f6
SHA256 32a0285463efd8fcb0739d5e754b9153585ac5648a012707c3ca9405a25293ed
CRC32 A451D617
ssdeep 12:bkEm8qaBn0Bg6kRw494Llsgz8kmp7Ivezp:bkCdnEgd594JOkmp0vezp
Yara None matched
VirusTotal Search for analysis
Name e653f38b0c83d543_511.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\511.WNCRYT
Size 149.0B
Type message/rfc822, ASCII text, with CRLF line terminators
MD5 91eeeb6f0c11af865888682b7baff8c0
SHA1 85fa4bb2f29b9d8a60ba75144d92229f70bd7a35
SHA256 e653f38b0c83d543839248107ada56fd989b8a9473a9113829d5d3d25fa9d78b
CRC32 CA05620A
ssdeep 3:/eIeAtIaPWXXy3XWMKEhGmF+LfAhNwu8AGEJIBGCNw1yAFVwfTRrnv:/eQ6oQXoXmyF0vLGv1yoopv
Yara None matched
VirusTotal Search for analysis
Name b99f54ddffce83dd_shift_jis.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\shift_jis.txt.wncry
Size 1.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d87c920d9208fb967c842b930a172682
SHA1 1bc3b004cd9fdff890002a011473b22fda3ed9be
SHA256 b99f54ddffce83dde959a252ff476a496a0a04de65778d8b6881ed68259f3981
CRC32 836F713E
ssdeep 24:bkfy9PYCylUbU0zyYMax7wpiadoFxgO95HOtCAcCYjf6:bkaGMU0zXB7wHd6xN95tAcCU6
Yara None matched
VirusTotal Search for analysis
Name 40adeb0de5bfeefb_cxmlmlmlmjidcp.doc.wncry
Submit file
Filepath c:\users\test22\documents\cxmlmlmlmjidcp.doc.wncry
Size 976.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7c63716c6a3857d894b216158ae536eb
SHA1 32dae53af0dad1f5c0f3ce114a4878efad62ed85
SHA256 40adeb0de5bfeefbecfae4bc635173fc8ce9eb8a49f304dc545954d60bb9a8ed
CRC32 86314A92
ssdeep 24576:wKSUeVi0ERxcyTrcoxHUwWVO0eEqz8SpWqSrHlVWIGLiPeUX1+Eoc3b:wKSRERxDrpvWcnz8FLlATmPH1+Ir
Yara None matched
VirusTotal Search for analysis
Name d35a4422466b1e62_523.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\523.WNCRYT
Size 405.0B
Type news or mail, ASCII text, with CRLF line terminators
MD5 080a9e03cb42f78e3d4d6c0008960f38
SHA1 fa438609f5a86776f6036e7ce23e3c805e2b8b65
SHA256 d35a4422466b1e62b37425a540c73589435990e56e64619f5b775e19b09a3c80
CRC32 5CBC7AAA
ssdeep 12:AXmMQfbgQJCSQyoyJxmwgQJCSQyoyJxEj:AXmpbbnj9bnjKj
Yara None matched
VirusTotal Search for analysis
Name 56aa5bb4dd668441_490.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\490.WNCRYT
Size 738.0B
Type C source, ASCII text, with CRLF line terminators
MD5 849476df6a1411c6c0669fa1c161b362
SHA1 e3602eee273e028d894a57a27288a5b7d0684460
SHA256 56aa5bb4dd66844181c64bdfa548e5948ecc0cda80f694d9203caf73a086d352
CRC32 8AC42C85
ssdeep 12:wL2aF+rdUUC1LfhKluUI0ZKlunKnU8TZPWxv1afxr1anUxxc1anUxxc1anUxx5cf:whFwUUYLfOuU7ZUunB8lPWzUTxUxwxf2
Yara None matched
VirusTotal Search for analysis
Name af323876c04dde95_earthris.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\demos\images\earthris.gif.wncry
Size 6.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c97271095948114a15a3cb1fa54da692
SHA1 9ec93cb812d12e14694ef427796354a25caaab78
SHA256 af323876c04dde9534a50aa0da9a38ccc4ab2be2de5c0f5ea9c04e53a6cb2a36
CRC32 B65EC696
ssdeep 192:tv2hx4iD/z7/v8t7ee7lrDYJvPbvdkfxbnogab8zn:V3izfG7F7lrDSnblkdogpzn
Yara None matched
VirusTotal Search for analysis
Name 4701aa92535f8cff_requires.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyautogui-0.9.50-py2.7.egg-info\requires.txt.wncry
Size 552.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e02aa21bb22481df44fc8fb594f283b1
SHA1 93981ab09444c7861299587f716d590339b7d8b6
SHA256 4701aa92535f8cff334a63265e8740aa54b4947063e444fafae7084719291f96
CRC32 DC0662A7
ssdeep 12:bkE3cF64fB4KpBEdv7cn4/igMaGZa90KD3N3xvw3Tyf+G9zJBueX:bkVF/p4eSk4/iBa583Gf+YqeX
Yara None matched
VirusTotal Search for analysis
Name 30145b640d1c9667_dictobject.h.wncry
Submit file
Filepath c:\python27\include\dictobject.h.wncry
Size 7.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3f2e33e6c326dbc0f42ca53c54f20037
SHA1 223cead2ebb21d0c87864dae73a1d92b65a72e9f
SHA256 30145b640d1c9667542b3d2e317ab2ad2eda0ba86a85a20a35f1046f90db7705
CRC32 B76F09DB
ssdeep 192:WYD2fPUezeTJAw+zkNNf6GtCXbz05D63E:32E4Y3akvKXc5u3E
Yara None matched
VirusTotal Search for analysis
Name 245a493cc7764886_150.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\150.WNCRYT
Size 6.9KB
Type ASCII text
MD5 072e12f026647b15649adb045847a5c2
SHA1 1840b96a80ac1506b0510679eab56fd799e7dce1
SHA256 245a493cc77648861f3629286bda153e2b6bf0e2499bb321fa7b18951f05bb7c
CRC32 923665FF
ssdeep 96:/TTnlMN3O70KFuQbL/Zs4g0GcNhHOx/bRHsa1EHL3YRYt:SRh3ILhsKQuLjt
Yara None matched
VirusTotal Search for analysis
Name b72121e03cd7ab66_msg_39.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_39.txt.wncry
Size 2.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a01f3ba7c662e8482cdbccd9ddf26e09
SHA1 fa1f03016b3e284606b60559c4e6b1f9e2049193
SHA256 b72121e03cd7ab66fbbca3f641b0d85cab5f2a4d40e38e08a5a44b0532b0bfdd
CRC32 BC156EEE
ssdeep 48:bkSMXPcYIWxXKU62F8LJSS+t4URCMQIe5K0U3OeG86sJ2gQm3FT1bxIBH1StXB:oSMXPvd6bLJbWPe59uursdxIL6XB
Yara None matched
VirusTotal Search for analysis
Name 519ad66009a6c127_m_polish.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_polish.wnry
Size 39.0KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 e79d7f2833a9c2e2553c7fe04a1b63f4
SHA1 3d9f56d2381b8fe16042aa7c4feb1b33f2baebff
SHA256 519ad66009a6c127400c6c09e079903223bd82ecc18ad71b8e5cd79f5f9c053e
CRC32 498DDD81
ssdeep 384:SheftipUENLFsPzy3EFHjHdD2SG2gA8w8OJ6868jy8/8w8m8T848f8y858l8j8yv:Shef3jHdxG2KhuZrS14G
Yara None matched
VirusTotal Search for analysis
Name d3d05c5d0e1b74eb_longintrepr.h.wncry
Submit file
Filepath c:\python27\include\longintrepr.h.wncry
Size 4.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1c9b38e625c75a6fd32e163ade2721c3
SHA1 9140d1cb5fa76adb51c7a376a24f120153320a00
SHA256 d3d05c5d0e1b74eb3ba98ede602e0cf3a0ffeac34fdfa5c8b78ee2d6272cd80d
CRC32 C56463B5
ssdeep 96:oQ1YbFqZ0OEUxv6jhtvrf3CFQs+/xWfgU6yLpF5joxbqu3MTshwFwRMvzDL:pYb0LE8Qzr3CFQsM6gU6GBjoxbqPwsbv
Yara None matched
VirusTotal Search for analysis
Name 54629940ae1aae2f_open1.png.wncry
Submit file
Filepath c:\python27\click\click_image\open1.png.wncry
Size 664.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 2b2823f9697ccf27918c070d8d43e92f
SHA1 361c64212544eb1cdbf44fa409ee81320eb16858
SHA256 54629940ae1aae2f77ab53f34f237e4abe17b8ec112f1fe323c0341ed915904a
CRC32 D75C8637
ssdeep 12:bkEwctegVZIJ8KNjvoTvD0wFT/S1V0+OaRUDLXeh2L5irKwex0qHOhOR:bktEeJJ8MvIDVFe1VwaRU/XDErKwexd
Yara None matched
VirusTotal Search for analysis
Name 3871aac7203311cd_pwrdlogo75.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\images\pwrdlogo75.gif.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d932040bc59811d65fce0c1b75665bab
SHA1 5c5228c3f76060453290bf4c4c86eeb1a5f633ac
SHA256 3871aac7203311cdfeff9e121072088104ace5b14c8396892fc28fbcf97aeda4
CRC32 2FCABD43
ssdeep 24:bkbwUmmfSw3kGM1twn24SCYxVJqxnrzCoTkznpf44YZsjkrgAYSa8y2lNEg6:bktkd1twnSCa2xUpfIjrFYSa8yCNEg6
Yara None matched
VirusTotal Search for analysis
Name 757b77a9f136fb1e_thumbcache_1024.db.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\current\appdata\local\microsoft\windows\explorer\thumbcache_1024.db.wncry
Size 312.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 3137a4e527a70b79bd63bb46eb1eaeac
SHA1 e73ce85af8bc6bc87ac9e2e0dc2b5765e8687b38
SHA256 757b77a9f136fb1ecb7fb8acea515961b89ea028bb8cc7fa599b4f7c8dde4f48
CRC32 BFAF8E5A
ssdeep 6:bkE7+m14ZBof60U2vibQRhVmfVQelns726GiWUaD4iDOn:bkE7+9/t6RhYfnX6291k
Yara None matched
VirusTotal Search for analysis
Name 15a3977f0d2c6a8e_540.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\540.WNCRYT
Size 177.0B
Type DOS batch file, ASCII text, with CRLF line terminators
MD5 5dd3dc514db4843357ae370da738fe8b
SHA1 213caac32e64bd3c2c194ec5260bc5d028b822b6
SHA256 15a3977f0d2c6a8e87db2ef7050ea10afb3a88b064bf5ef95439924e42464114
CRC32 4E7BE175
ssdeep 3:mKDDE32REXRFshHqVxEmF1BMLmtARCAaCRs3tbBqW+jgoFM3su15qKcAmCspBOK7:hQbQdaBKCAUIob4L8oFSVmrBGTQbAgR
Yara None matched
VirusTotal Search for analysis
Name b091dcc25b281afa_eo.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\eo.msg.wncry
Size 4.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 818b8f5afe9dc1c5184f6a79730db0f1
SHA1 f28f97c0932474121fc067080c78a33d20cf2583
SHA256 b091dcc25b281afacf657ab58d5adff02d1ea2601dfb3579bad1e8362dc84663
CRC32 8D3D22F4
ssdeep 96:owHvpyB4LuIiLHWSLZqIDPwAnTiXsFzp2sxokp7rboYkzejKs:Jpy2uT2cFNlFzpvxDp7rbYKf
Yara None matched
VirusTotal Search for analysis
Name acf3d3b653147ddf_mt.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\mt.msg.wncry
Size 984.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b586cfad7829ad618f0d35a7a9d6da17
SHA1 5878a4a1204ba8d57a08ffeecddb7c54d617a7a5
SHA256 acf3d3b653147ddf0f3d5ac92a6ac9df36d9ff142398742441c5cdde9635d7e8
CRC32 388E9202
ssdeep 24:bk7D0U7/gQd644uZM7YNIh43t+QFBi7FRKYk1h4n:bkcQS7YNP9nFBsFwh4
Yara None matched
VirusTotal Search for analysis
Name aff0708cd6709d9d_jsgirplhspm.txt.wncry
Submit file
Filepath c:\users\test22\documents\jsgirplhspm.txt.wncry
Size 152.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2da98b42512fb464a81ffd69a17bcfa7
SHA1 2d5f87602892920d94b7975891dc90d245564b10
SHA256 aff0708cd6709d9dd84b9bf53aa2528729f9e57aa44e0e6edc97cbe67f94ccad
CRC32 1038B3C2
ssdeep 3072:gc95W4B1Y3OgxXKte3tSS1hHPDTHJFthmT5c6i0wdS:p97kOgxat4NhHflhmTG6odS
Yara None matched
VirusTotal Search for analysis
Name e1379f1116f679ae_dependency_links.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyrect-0.1.4-py2.7.egg-info\dependency_links.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 3c2f2ae3469d19ad59547390fa5bdbff
SHA1 59f284da61689be5714ca0897b22078a1743c020
SHA256 e1379f1116f679aef706fa4c3bd837d0ecd7b7e4f9b97b761bac34d657d3510c
CRC32 2E5AEFA6
ssdeep 6:bkEpuLgd0ll9nshkWnbm82mGbpi5M2qF1880FrUcS+Sl/sW3:bkEpuLn9sI82Zli4709UcShtsW3
Yara None matched
VirusTotal Search for analysis
Name d891dff013381400_590.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\590.WNCRYT
Size 313.0B
Type ASCII text, with CRLF line terminators
MD5 70c6bd9d997f8a9a4c0faa5a8f4dddac
SHA1 5ceb44598445589fc40a9196a1382b431b3ca28b
SHA256 d891dff0133814001d2cb295f0b5218b66df0d6f7b0db0df5495f686d37878cd
CRC32 0388D8CA
ssdeep 6:hum8cKD8dSENcw2TNO0B+AF7A4r1jrQ1jcdjnKMMy:humTSENcnTTBt73L3
Yara None matched
VirusTotal Search for analysis
Name 4886be530a6e8a10_392.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\392.WNCRYT
Size 16.0KB
Type data
MD5 1f06305fa3d9c2218a5d0fd93be7c600
SHA1 313638a34f732290a5596ccd87448e18b27f0d8c
SHA256 4886be530a6e8a10de8e34f532d6c41d6ecec309b2af75b2c210033a53589e47
CRC32 730E4908
ssdeep 24:vq54sc//0E6igTsi5QkU//M8yKIDka5I8M//:y54sc6igTs//M8a5I8M
Yara None matched
VirusTotal Search for analysis
Name d8718d6043f45b42_kok_in.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\kok_in.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 c61c5e44bfd0ae8cc458e3dad59090b7
SHA1 ad78d0d16a24e25c65a3e1e40fa403154e6c960e
SHA256 d8718d6043f45b42574168fa6b0d199d521d31bc7c62fe836f4555567c5d7872
CRC32 94B793CA
ssdeep 12:bkE8cHP+CgTC+9RSWnBmtr/3t5BEhumldXTIgwS2S+2VVgR:bknq1gCCPmt3STIVSuiM
Yara None matched
VirusTotal Search for analysis
Name f10ab4fb6785ea44_607.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\607.WNCRYT
Size 330.0B
Type ISO-8859 text, with CRLF line terminators
MD5 944c309dca6b5c5e74edd96759067037
SHA1 3a03c998d9fd8f9d9bf9465e4d5d6587666bd81d
SHA256 f10ab4fb6785ea44f746c18f3565145461bfe74f5d1720f8d88b4cc8d5cad0af
CRC32 E8DCC853
ssdeep 6:trT6VR7jCosyK3WkvKwjcwSN+IcK5utmvhaQek9onH/TgPQhyaiBKGoa:tnkR7R4bjnwzq7nHcjajGoa
Yara None matched
VirusTotal Search for analysis
Name 23e5e738aad10fb8_m_indonesian.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_indonesian.wnry
Size 36.3KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 3788f91c694dfc48e12417ce93356b0f
SHA1 eb3b87f7f654b604daf3484da9e02ca6c4ea98b7
SHA256 23e5e738aad10fb8ef89aa0285269aff728070080158fd3e7792fe9ed47c51f4
CRC32 16A6A478
ssdeep 384:Sw3BHSj2cLeT+sPzy3EFHjHdY2oG2pq32eo75Y3kmA31dv61Qys:Sw3BHSWjHdUG2pq3nZrS14I
Yara None matched
VirusTotal Search for analysis
Name 7e5bdd023b6cf21e_172.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\172.WNCRYT
Size 759.6KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, datetime=2009:03:12 13:48:35], baseline, precision 8, 1024x768, frames 3
MD5 9d377b10ce778c4938b3c7e2c63a229a
SHA1 df7be9dc4f467187783aca68c7ce98e4df2172d0
SHA256 7e5bdd023b6cf21efe42a8ec90bc1993fc853980d4b564688e5ac2d28c64223c
CRC32 DBFCE5CD
ssdeep 12288:nZjLqkqjwM90ABrRzWAnL23FKNrIoHv3QwKrF/spqr7FnnBBmW5s03eS5Za5R9tE:pmxjwMCSRL23FKNl36h/j9nBkW50mA9u
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name ba79d15200c574ae_py_curses.h.wncry
Submit file
Filepath c:\python27\include\py_curses.h.wncry
Size 4.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fb8ae22a65c53a97d234440b725f502c
SHA1 fb6a69fd800d282c3cb76a3dbe85c68b45c791ff
SHA256 ba79d15200c574aeffa837f93561b8b17eb7ffeff02b411e444688ba2c275ace
CRC32 1C8FA4B8
ssdeep 96:oUKBe9Hmpzzuv0k0tdPOfCOJunENWDScklCJl7HKmNUHaPj:vye9HmpXuv0BtdPmJuWSkMDqQ5j
Yara None matched
VirusTotal Search for analysis
Name 34894323ff69b693_usertile41.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 486424faf3534cd712b8eb5357e977c7
SHA1 fd8df270e38f50680b23c337386106c27895688c
SHA256 34894323ff69b69313364214ba6b9b503517dd0e8940b6176cf65bfa64392e6d
CRC32 6E523FDB
ssdeep 1536:G42l2zYxUdScRaBCXoBvHczPO23SyjdErE:G4M9DaPXKv8z2wzjdErE
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 2a4f1edac2b18b18_en_ie.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_ie.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 920ca5877954d6f809db60a9c12bbde3
SHA1 4f255139aeb184d0f8eca5cacb336f04a726519e
SHA256 2a4f1edac2b18b18db7eb5773c769eadb4e88ad9b6b69463ec0d7e5311b8a8c4
CRC32 3E0D3DAB
ssdeep 12:bkEdilawRP61Wrifjap/ptXx6uh/NJnEu/fO76Jrlvaz9n:bk+2PGfjatl6uJou/xlvc9n
Yara None matched
VirusTotal Search for analysis
Name 6caafeff3c68b716_436.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\436.WNCRYT
Size 168.8KB
Type data
MD5 aa53bfd6b6604a70194dd7473821f405
SHA1 2c6afb8206aabb81b536503fa7d937fe44ef7391
SHA256 6caafeff3c68b71662ffa63716de2366c7bd98f8273eed43fba65366533ff4e9
CRC32 4B26453F
ssdeep 12:Po6ZYrfffffffffffffffffffffffffffffffffffffffffffffffffffffffffU:Q6aGw64o0rlO
Yara None matched
VirusTotal Search for analysis
Name eb17a8344e4df101_nl.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\demos\nl.msg.wncry
Size 6.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1a2c4c8fcaece4f535813137cd78c284
SHA1 adcfa9a5a994c186fa9b4cec23f3b7be3e0d031b
SHA256 eb17a8344e4df1012f7b8a4f5e2858b189ece2e94384501678913d5570d29b13
CRC32 66B43039
ssdeep 96:oSIoNDnbt0CJ8oWXMn6/jp3dH3rAkUBejmQwnaI+XwCxhfwrgXzNF8VjCwD:RIwbqC42Sj37ANHWgCDYgDNF6j/D
Yara None matched
VirusTotal Search for analysis
Name 2c95bef914da6c50_m_dutch.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_dutch.wnry
Size 36.1KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 7a8d499407c6a647c03c4471a67eaad7
SHA1 d573b6ac8e7e04a05cbbd6b7f6a9842f371d343b
SHA256 2c95bef914da6c50d7bdedec601e589fbb4fda24c4863a7260f4f72bd025799c
CRC32 EE90AEFC
ssdeep 384:Sw3BHSj2cLeT+sPzy3EFHjHdp2oG2/CzhReo75Y3kmA31dv61Qyz:Sw3BHSWjHdBG2/UhsZrS14f
Yara None matched
VirusTotal Search for analysis
Name 319296ecd18ddcfa_302.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\302.WNCRYT
Size 4.0KB
Type ASCII text, with CRLF line terminators
MD5 b7a1b79ee0aa71ff5c2704e112482771
SHA1 4695cedee75846b343188b9cdfff6b443766df32
SHA256 319296ecd18ddcfa1ac858cd0604c1a22ef1b39951806d93ae04906917481b1c
CRC32 F07E06FD
ssdeep 96:LrkRsrz6I/lqzr+UEOuNRTKjpAUHpHt2dKEoyn8iahE0naDZC:HksPI+UVujIHy9n8X3naDZC
Yara None matched
VirusTotal Search for analysis
Name eaa7684d6defff34_plusnode.gif.wncry
Submit file
Filepath c:\python27\lib\idlelib\icons\plusnode.gif.wncry
Size 360.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 3959b96b22f7df5452f9a9dd8fa5a4f8
SHA1 8574616b8830d903c0739e937a2cc4baacf7fbfb
SHA256 eaa7684d6defff34538a7ffcd34ce5e7bae74091a97ec635a697108836b2c279
CRC32 02E0E233
ssdeep 6:bkEe298qMdDeg9AkyIK3ZvNyl0Cv116MUqcMN6jdZx6FxQsfAG1OewPUeu6jEqmt:bkEe2O3dDeoTyIKF9+1nUqcMN6jdzcZl
Yara None matched
VirusTotal Search for analysis
Name 3a224ed65eb1cca4_license.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\profiles\qxo5wa6x.default-release\gmp-widevinecdm\4.10.2449.0\license.txt.wncry
Size 760.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 906def6ff518fe33f8998fc4adecf61f
SHA1 947aff8ea5a5170a90379ec75b830414ab549fe8
SHA256 3a224ed65eb1cca4e89def3509a47e6db93fd72860a7abc1dce410720e9346e4
CRC32 9B5668A8
ssdeep 12:bkEJRkVXRX+9iEcxzUdtatcSecFbbUxAIbN1W6BQY2TtCsFCEWOuh2v3ja7N6u1A:bkuet8i1xzU2tcFcFbwxjbX9BQYq0sFd
Yara None matched
VirusTotal Search for analysis
Name 5d62ac5998a74bef_installed-files.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pytweening-1.0.3-py2.7.egg-info\installed-files.txt.wncry
Size 408.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 8704cac83ac1e400f265984c2713ea29
SHA1 0ee64b6ae95936fb9cf0f931def4dcb7bbf7a53d
SHA256 5d62ac5998a74befcf084b90c821241f6b2cbef7bab201247b772bcd852c55ce
CRC32 B9448738
ssdeep 6:bkEn2+bVfNfc9mWxYusy+c1Q2kleD8/59MLX4JkOra+OFYR0hIMeIIGMBkE76mtK:bkEn2+pceOG2qILtpFziIIpBkX7
Yara None matched
VirusTotal Search for analysis
Name 05c399022a54c881_craw_window.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\craw_window.js.wncry
Size 259.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 463770788ffe8fe281c338a2364d6de0
SHA1 fc7504329cf0a9a65fd8b24c2e15daf68a3adf80
SHA256 05c399022a54c881dcd9d6a26db13388d6c7e684a73fe65cff72086a9007b955
CRC32 45A3CE0B
ssdeep 6144:psIMW3pqm+8PUe9YP/evNoE76gJx0sAXTEUpnq:psHsqNfe9LvNZhJysA7hq
Yara None matched
VirusTotal Search for analysis
Name 6119a9887692fb85_354.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\354.WNCRYT
Size 8.0KB
Type data
MD5 8b7a6fc84edbb9b9c2164f3227a8c945
SHA1 9ab615853fa8c7b08a012187a733dc39585ac297
SHA256 6119a9887692fb85eabc996f065b03c6d19bafc23f00a4794242e72b13120bd0
CRC32 6A364D6D
ssdeep 192:3k2xaaUyse71abxl0fatpNnxa/2WvVJBZHp5isu/dY/tBNLqu5Xw2v:3k2x3slgatpNnxZGplu1Yte2bv
Yara None matched
VirusTotal Search for analysis
Name ae6d9357118aecc3_502.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\502.WNCRYT
Size 957.0B
Type C source, ASCII text, with CRLF line terminators
MD5 2313e2456f8c17621c369ce31c07f4f3
SHA1 80081a6a2a6cfab929347d25dab4a28a11d86052
SHA256 ae6d9357118aecc38f5b77adda255628890eae4b1d5e7f535393e7a53107ed76
CRC32 92543456
ssdeep 24:JYSglHeay+SxM/Uyj20kAmnqfK5/AqdN6qcc9L6gWUy:SlHek0M1j2nA2qfK5Bd3Jy
Yara None matched
VirusTotal Search for analysis
Name 47c3b6b4a4fac03f_585.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\585.WNCRYT
Size 11.0B
Type ASCII text
MD5 c4a791a0b9771d5de97c92f851aaeadb
SHA1 d7cbff571fe66d621e8c1ce5a3279587fe189a98
SHA256 47c3b6b4a4fac03f6c436928978cd899c9ea50e7e003d30cb2cc1fdd3f73448a
CRC32 FD983947
ssdeep 3:bLMLCv:vKs
Yara None matched
VirusTotal Search for analysis
Name 7433425e3adeebdd_chrome_shutdown_ms.txt.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\chrome_shutdown_ms.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a82f739a13247b68eff090bb0bfce6a1
SHA1 509385dcb062953e1bd8ef4f653bdf45563bdfcb
SHA256 7433425e3adeebdda849e374fda26d0c787bb16e941a810dff7f21b4361db1f2
CRC32 DFE6CAB6
ssdeep 6:bkEBiCwESYz2lyVadnBaYS07nCS+6h26iNLwWTqVYFQJc+Fh:bkEBhwy2lyVYnMqWSphU2V1l
Yara None matched
VirusTotal Search for analysis
Name 03cef87e586e38b8_482.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\482.WNCRYT
Size 955.0B
Type C source, ASCII text, with CRLF line terminators
MD5 de03d9f919df2a39e8dc72a12d267cce
SHA1 d374c95d663f141f24efc4566058308bd07adb31
SHA256 03cef87e586e38b8532cd39a0902863c2b372c79eae75ed7bbea027e21cf901b
CRC32 CE01D292
ssdeep 12:trF+rIk9Stzj6Jp0n2xLRfngiLLnAtzfngaZtmnumZN:trFhk9IzGJp7RRhMtzZZtXmZN
Yara None matched
VirusTotal Search for analysis
Name 952303585658d59b_160.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\160.WNCRYT
Size 1.3KB
Type SoftQuad troff Context intermediate
MD5 5bbe771289a5650bb4c40ccc0608e12e
SHA1 5c1e4a94c785f41d824e7fc5bfc605e3cdf47c42
SHA256 952303585658d59b9782c0cac8a9d9c5b99dca60d775526fc9052c4e83e6ae34
CRC32 C64E71C1
ssdeep 24:96arNJHYHPyPP3j6Jq1k9QHvsUrt8Ok44Sv4KCo30vfTr3WHavXYQ418Wy:YahJw6PvjR8QHvs6IJM4KT30vrrmHavd
Yara None matched
VirusTotal Search for analysis
Name 552aa0f82f37c960_m_korean.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_korean.wnry
Size 89.4KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 6735cb43fe44832b061eeb3f5956b099
SHA1 d636daf64d524f81367ea92fdafa3726c909bee1
SHA256 552aa0f82f37c9601114974228d4fc54f7434fe3ae7a276ef1ae98a0f608f1d0
CRC32 00B0A712
ssdeep 768:Shef3jHdUG2NQcbxfSVZiG9jvi3//ZVrMQr7pEKCHSI2DsY78piTDtTa6BxzBwdY:SheiaDq
Yara None matched
VirusTotal Search for analysis
Name b0c2252a53340d41_usertile35.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 c8d351bf2848d70bacc8c54aebe5ce0a
SHA1 f3e4789442f2bf6f76a03d2462bcdc26e9efc78e
SHA256 b0c2252a53340d411dab77569089953661edf4bbb0e87c2b4b7ab792adc9818f
CRC32 7EB68602
ssdeep 768:RzOZSrfCWMgNXcnWrAsp2xOpriqtbS079GQ6Cfcox3PFyun5po8Zffe:RJbfMOXcnWr12xu55BUQvfh3PFLc8m
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 68dd677eec437309_493.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\493.WNCRYT
Size 979.0B
Type C source, ASCII text, with CRLF line terminators
MD5 40c41e2285d956e867ada5d16b50e969
SHA1 042de7c9a3ae708226fd8c76b9bfecf10343c3c3
SHA256 68dd677eec4373098f36b5814b1f0be9f4cf7d0069cb83b9b3faa3c107bd99df
CRC32 E5FEC46E
ssdeep 24:OU6jxu+sZTpQrAjRRTuMclJA5XrL1BURJ+9:S3sZTGExGJmL1S8
Yara None matched
VirusTotal Search for analysis
Name 61a902909739197b_gb18030.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\gb18030.txt.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 76622ee76f6df98143d4c33ab0ec7855
SHA1 7344675cefe2e862e0ca76eed0c30cb04857d734
SHA256 61a902909739197bdab4dd40972a014f4404223ec7580347af3e05f4e7b4777b
CRC32 FC902C1B
ssdeep 24:bkBgQ4ztwT8Ygt24ZH0X07cWrBKVfC62K:bkB14z6Fg44ZH0hW1KVTl
Yara None matched
VirusTotal Search for analysis
Name be62cee27df1199f_441.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\441.WNCRYT
Size 12.6KB
Type data
MD5 93b659722d728ef02520b5a1a375835d
SHA1 2136da4612ab8d11c5ed8ac164b4a05b68520f14
SHA256 be62cee27df1199fb79988ec1fbafc58fdbb7ca223e608b696395ee6378d3e62
CRC32 1B62D83C
ssdeep 96:W0Jphj6MTCt5vZyH+NFKm05xSuvM2cNmh4e1cjc/QZXya3+0AZMorTPFcSEx/D8W:5Ja9Bzym0hFcN27WYAZuR9ebxUi
Yara None matched
VirusTotal Search for analysis
Name bd9f4b3aedf4f81f_m_portuguese.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_portuguese.wnry
Size 37.0KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 fa948f7d8dfb21ceddd6794f2d56b44f
SHA1 ca915fbe020caa88dd776d89632d7866f660fc7a
SHA256 bd9f4b3aedf4f81f37ec0a028aabcb0e9a900e6b4de04e9271c8db81432e2a66
CRC32 A49E7C1A
ssdeep 384:SheftipUENLFsPzy3EFHjHdy2QG2xgk5eo75Y3kmA31dv61QyV:Shef3jHdCG2EZrS14p
Yara None matched
VirusTotal Search for analysis
Name 8365077564eb2920_453.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\453.WNCRYT
Size 56.4KB
Type Microsoft Word 2007+
MD5 d769b29414cf63b3824fd63aa203687a
SHA1 ff882d9b399799b6c774424cfbf7a19af357dd00
SHA256 8365077564eb2920893b7e0907cf4d197f8cf87d789c0d2666d3bc6a464fd223
CRC32 45340478
ssdeep 768:s5Uz+6NXAFd/ZJgMu49UgnU6ldz0iGUBShEllKottEZ:C4N4/ZJgIUOR0ih04oya
Yara
  • zip_file_format - ZIP file format
  • docx - Word 2007 file format detection
VirusTotal Search for analysis
Name 2535a956d292899a_50.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\50.WNCRYT
Size 1.9KB
Type ASCII text, with CRLF line terminators
MD5 73c2152336e3aeab8a5e175806a6d1b6
SHA1 6faa86d9ade1e677e28ff58427db54651e829b5b
SHA256 2535a956d292899a4541d1f654487ed5ebd85f870e0409eae17631c7864adb95
CRC32 4C05F236
ssdeep 24:w2mAIfboF6gZyAqCR6DyOASKQZnVAzChLLLrZzDtpiUYvcZrM9VgZyDn:GAI85ZzZPSKQZnmuZldpvWcW9uZk
Yara None matched
VirusTotal Search for analysis
Name 5b502a7eec391535_readme.bmp.wncry
Submit file
Filepath c:\users\test22\pictures\readme.bmp.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 4e615111bb79b1d780256238049d47e3
SHA1 9a123c59caf51709dc55ce90f278af5dd57873b3
SHA256 5b502a7eec391535eb2dd4b39d03b36c57b59244ff1fa761e50da1beeff62de8
CRC32 76FAE75D
ssdeep 6:bkETJaGWHYmlUMaEjlrE7TzNSD/Spz31hECIWzquHZOV:bkETEvYmCMhITzMDaFgL8R5E
Yara None matched
VirusTotal Search for analysis
Name 54dc21771c3c1a95_81.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\81.WNCRYT
Size 1.1KB
Type ASCII text, with CRLF line terminators
MD5 1f9d99a43692a15f008b14fe014e4a66
SHA1 071323a62a243939ad2cdec8efec2b39412a2c82
SHA256 54dc21771c3c1a9550a248586580c08a6a49d445874556e2e50aaf5ead10c9fd
CRC32 B3F6207A
ssdeep 24:X35Yvn1/3OVFD9DTGnDMsDPhuC727Ly5LHTcJeQg:X3q4FD9PGDMyhuC72yn
Yara None matched
VirusTotal Search for analysis
Name d5e0e8694ddc0548_b.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\b.wnry
Size 1.4MB
Processes 2632 (WannaCry.exe)
Type PC bitmap, Windows 3.x format, 800 x 600 x 24
MD5 c17170262312f3be7027bc2ca825bf0c
SHA1 f19eceda82973239a1fdc5826bce7691e5dcb4fb
SHA256 d5e0e8694ddc0548d8e6b87c83d50f4ab85c1debadb106d6a6a794c3e746f4fa
CRC32 676D21FE
ssdeep 384:zYzuP4tiuOub2WuzvqOFgjexqO5XgYWTIWv/+:sbL+
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name e79bef586dc48aa6_garden.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\garden.jpg.wncry
Size 23.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 9878a4285fdf3c07be26436f8ae638e6
SHA1 5bb28c400a63c444d0fa703cabd905a6cf9f3c2f
SHA256 e79bef586dc48aa641446298dc50366c04e4ac37fe36cf8f4f82bf02eff73c37
CRC32 15AE2C27
ssdeep 384:Xi7mSt21Okz1MZM8medpV+TZDOTER2rJe6bxQyThKOeboDwJXBBLoNvuFEMUInCX:S2OkzGZXme1MZD52w6hThuZpBBLoNv4M
Yara None matched
VirusTotal Search for analysis
Name a07aec7bc6205744_logomed.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\images\logomed.gif.wncry
Size 4.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7d375ac8cd24e8b816a35956e315a4ef
SHA1 5963203d0f0b11086fb7cbf4adb1df2795be86c4
SHA256 a07aec7bc6205744c65cd614d244e89aa16ab80c5879afc2684d75009b778e60
CRC32 0CDF0F8B
ssdeep 96:os3LoB5PDDbk9FPCfqR6hhq3FLMG8OAvwyvSW8z3R1tob:QPDDA9FPFR6hkFLjeDSWoB0b
Yara None matched
VirusTotal Search for analysis
Name 973dade5897208ac_usertile33.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 f8b0196d4c0afa0e8e014ccff735cd82
SHA1 b80b339cc8ea6a3d5f960c5646ce8d3a32b4c401
SHA256 973dade5897208ac53e79d90c3e69997dcec89085800f00c231ec9dbff7a2038
CRC32 AD313D96
ssdeep 768:K9SlVif+StPW5oLZzLj8XuOAdV6BdSXQUM7/4KWIMaC+nfuH5g13/Kn81PDt:KyV0pW5eD8eOoV6LUM75zMx7C/s89t
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name fe63994a603371a7_eventpage_bin_prod.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\eventpage_bin_prod.js.wncry
Size 69.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 723c7101ce5ba68bd06c85073b229ee6
SHA1 7453bedc5107e8112f94ac8fa6b5112e74318cb4
SHA256 fe63994a603371a7c62b783112f443724bc50d9d1c4208e3d3530e9a4ed9ae0a
CRC32 7DC7A504
ssdeep 1536:59JM4lfPRIV70/rGWmjfggKQjB7Nt23TnbcDZYjbjIverfkY:59JJa3jLtvSnIZibjIGkY
Yara None matched
VirusTotal Search for analysis
Name fc0fdb93ef0f796b_bisque.cs.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\pref\bisque.cs.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 43a4b062498bb22ccb5d766c2a709378
SHA1 de5afb5bcd1c46581463bedaf0903771a28d550f
SHA256 fc0fdb93ef0f796b687039ff367bc3a594baecb9dbb4982d7e39d5aedbf3a560
CRC32 5F197843
ssdeep 24:bkM7zE2Q0rwf6vffeO9P6H761ab/A4LNtL4Wjtpncn9kYuk6Ebs:bkQVQxSvew47oab/ZNK6ncn9kYuubs
Yara None matched
VirusTotal Search for analysis
Name 66a102294aa68a73_411.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\411.WNCRYT
Size 4.3KB
Type ASCII text, with very long lines
MD5 1f64214cf8028c4dc434ddcec9cbfb68
SHA1 21b7c28af08a4bf167223b2bb153b34f3752eafc
SHA256 66a102294aa68a73016c5f0143b1960ea059b9ab09205ad4e599ea2298ca527d
CRC32 15F667C2
ssdeep 96:2nMjbPyrDyFNNvdnOVoc++7Y+90+t/LX02KmUEu/u9P7D:oGqrDKNNpM7Y+/tr02vUEueP7D
Yara None matched
VirusTotal Search for analysis
Name f25c8a503a37db7b_r5t3hke5.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\r5t3hke5.txt.wncry
Size 600.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b98cf23ca8c788b0dce0cbc35057d723
SHA1 bca2429f6fa74a6ac73b5bcfdbe94a3a8cd7f41d
SHA256 f25c8a503a37db7bccf33d97fdb601ce03ec66c340865e154f29e2d1f528ac7d
CRC32 7604605C
ssdeep 12:bkEbs3PayUaKk1Oy5sB3TfcH15xf04EQ2v3+lVq7A1FpdRpnksLEKjCX:bkYs3PjrKOgTAFBEj+lQ7AfjksLEx
Yara None matched
VirusTotal Search for analysis
Name 31cda21e35efe9d8_pluck-pcm8.wav.wncry
Submit file
Filepath c:\python27\lib\test\audiodata\pluck-pcm8.wav.wncry
Size 6.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 63dd551df0532b8cacc867e3d7f3598b
SHA1 e25be3a79089dff00be09bf2d4ba528a66259c56
SHA256 31cda21e35efe9d8565e9c232ade578ffd50ad8d6e6e7495245272cb350ca71a
CRC32 9647EF5F
ssdeep 192:VFhIfKM9u9y4Nd4XWsrRTa8ZWLVMPDy7zBwrP:XufKM9uI2d2rFWLVMLyvBwD
Yara None matched
VirusTotal Search for analysis
Name bb2197e6417204ac_722.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\722.WNCRYT
Size 95.0B
Type ASCII text
MD5 63939c583eaf1d8803fd40cf3c6dee0d
SHA1 0fb42a8629292967c7b45a8752ac97b303841704
SHA256 bb2197e6417204ac00effec48df66f60398adaa777c49393edb8b3a6e5d198b5
CRC32 8B8BB598
ssdeep 3:yLR9dBkADF2vRtP3uzXseRSQSi6YrQIHev:yL7YmgmIeIQt6YrNHev
Yara None matched
VirusTotal Search for analysis
Name e3f843b1a363f61a_msg_25.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_25.txt.wncry
Size 5.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2db1b8a3ff93e0a214661b43fda69d70
SHA1 a63519188346df73ac1bea9571da98efe79d5adf
SHA256 e3f843b1a363f61adbc82d6bef55b96fb123fd96fe1110e88e769e2edd9c1cc0
CRC32 979BCC13
ssdeep 96:opt8EFSdo8X1ct35r4M3Aq9MY/DWhc9gdRNvKdzR7xG5alyGg8SrtX2jb:wN0o8FcHrF3Aqd6bSdzVUay8SpXob
Yara None matched
VirusTotal Search for analysis
Name ca58ff5baa9681d9_91.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\91.WNCRYT
Size 1.1KB
Type ASCII text
MD5 f012f45523aa0f8cfeacc44187ff1243
SHA1 b171d1554244d2a6ed8de17ac8000aa09d2fade9
SHA256 ca58ff5baa9681d9162e094e833470077b7555bb09eee8e8dd41881b108008a0
CRC32 698AF7C7
ssdeep 24:4azu8xVKE6V4/xPsS9CfXTBfijQT1GqAPwvsvT:461H6y/RsJXTNGqAuKT
Yara None matched
VirusTotal Search for analysis
Name c3aa37dfff969222_msg_10.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_10.txt.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3a2e5098a120fcefdb64dd38f7eafe19
SHA1 2b0a1a5fed6dbbbc3783e46d861368d99fafaea7
SHA256 c3aa37dfff969222ba074f1e66306f1816d33164635fa69b4fff4df3d04c4fb4
CRC32 975BCC6F
ssdeep 24:bkMNMIbSYs/ICiiAiLgBTsr+TodfhhMa9qitpPwni7Bzyo:bkMiXYs/KiAiLGFTGbMUXIoBzyo
Yara None matched
VirusTotal Search for analysis
Name 76837e0522d4e332_handprints.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\handprints.jpg.wncry
Size 4.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6b4907bd21915dcf9846479b1011e2bc
SHA1 2259500d3e1981395d52661a69c7db0b8e5a22fd
SHA256 76837e0522d4e3322b4d38f69d6954ff843bea94d6fb26db8404a949d5c3cdb4
CRC32 022ADE3D
ssdeep 96:oEAM3RV+w+DM8h5AErvgdjzUyIJ79AYEAMcWWgNiMBf:WW/+1DHrhIdcyIJbPpTMBf
Yara None matched
VirusTotal Search for analysis
Name 2af127b4e00f7303_762.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\762.WNCRYT
Size 479.0B
Type ASCII text
MD5 49ddb419d96dceb9069018535fb2e2fc
SHA1 62aa6fea895a8b68d468a015f6e6ab400d7a7ca6
SHA256 2af127b4e00f7303de8271996c0c681063e4dc7abdc7b2a8c3fe5932b9352539
CRC32 ACAB18EF
ssdeep 6:Ci1FD+DmsDZrkrDxBYRgELGNB+cIMLohXOl0t1iKR/UFioWd9+iAt4jZMeLhJoUe:CiCDtVEDsCDLeelyigqBjt4eK2fylL6
Yara None matched
VirusTotal Search for analysis
Name 03d48bb1e886732d_nl_be.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\nl_be.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 4f7f99007c4a87204752bc392133afc1
SHA1 5be2e655841cca10b3042b57107b944a7e7d9b2b
SHA256 03d48bb1e886732d6172498bc8ef0e92be32cc8fd9500218718bac8a3b1005d3
CRC32 1D46F1CE
ssdeep 12:bkEIjQh7cfVQvQNjdgIV+Y35/oV1wI3OwwSKyV1UJ2ZPOs+g:bkVj47uV+Q3gIt35QUHDSKyV1D5l+g
Yara None matched
VirusTotal Search for analysis
Name b4242029551626b1_501.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\501.WNCRYT
Size 728.0B
Type C source, ASCII text, with CRLF line terminators
MD5 4f3f6fb9de61f8f276bea6dcc8e61411
SHA1 6ed0143987d3af9952d9dbaba1fb9c904252e2c9
SHA256 b4242029551626b1e413c310c01e1e5c099321565ad50b36758d0716c66b8234
CRC32 C3BF0FC9
ssdeep 12:mRraJlTvzs84ox0yI1thhvrjrKkIRBJMeoKRBhE02L2ilSLFBb5A7KL2:VJNLs8tx0z1thhTjrH+BJNBy02L2ilme
Yara None matched
VirusTotal Search for analysis
Name 46048dd0176b13f2_535.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\535.WNCRYT
Size 333.0B
Type multipart/mixed; boundary="AAA", ASCII text, with CRLF line terminators
MD5 a1660c790ed8e2d885a2eb8bedd57a9c
SHA1 6eac46023391c2d3e995d73c9408e823cb32d48d
SHA256 46048dd0176b13f2310d61516b3a9202ed0b7b8f212458dd621d4bdcbb36941e
CRC32 172D96E7
ssdeep 6:/eQ67JLkbDwjW0AUVqeLnjFuyJV2GvoDUvtQ6oQXTegzKIDMQ67J7RM:/eQLw1GCn5uA7oYtQJCTegzKNQOM
Yara None matched
VirusTotal Search for analysis
Name db6df0b77a6441b8_patchlevel.h.wncry
Submit file
Filepath c:\python27\include\patchlevel.h.wncry
Size 1.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 64a61b23869a9a57a809a8c155f61283
SHA1 21f5770bab90ce4e86472cd9e5228fe0bcee5f89
SHA256 db6df0b77a6441b88d3e06f0093a8b3c86f716da25db37c6df27ea0ff9c9fcd4
CRC32 7C050FC7
ssdeep 48:bk571MUdDfMYMIhVtYMc3agDrxBEWqeeYUemF6jgE:oDjdjMYMYVyf9BbqIUtlE
Yara None matched
VirusTotal Search for analysis
Name f3b60a6e34667142_pretty_peacock.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\pretty_peacock.jpg.wncry
Size 5.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fb7d19df10bb7bde050148c016186266
SHA1 b6cd2306b7bce238b5097cb594998be735f7bacd
SHA256 f3b60a6e3466714201fbadb4aa27f646ae3110aeee9a3ce68643ba0ad942de17
CRC32 CE9727B8
ssdeep 96:oenJF6qPDZ65NMuieflXZ8V8iLcPcIA52CiWiDfxM91zALQiJHCgUH:7nJFVrZMN1fxSV8iuVAgQX1ke
Yara None matched
VirusTotal Search for analysis
Name 745e7999a17f2954_keycert2.pem.wncry
Submit file
Filepath c:\python27\lib\test\keycert2.pem.wncry
Size 4.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a4fcfab40f28160d09b74b13ce7bbd2b
SHA1 71f0c8e30d069bb1db9ca6c61e92cf7f5daa1b09
SHA256 745e7999a17f29545c0910fd5c77be64ba267d8d0a919c0fe1ce5e2391e1cc7a
CRC32 7FC3D2CD
ssdeep 96:oNPI6ZYfUvAl3mz8RtS4Ne5TH/kWT1/hNblIJv9reDE7OOYtO8QgY:unYcvs3mQ7SLH/kyMl9rVHYtNQgY
Yara None matched
VirusTotal Search for analysis
Name 5c5b0de42d55486e_overlay.png
Submit file
Filepath C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
Size 28.2KB
Type PNG image data, 1213 x 270, 8-bit/color RGBA, non-interlaced
MD5 1f93b502e78190a2f496c2d9558e069d
SHA1 6ae6249493d36682270c0d5e3eb3c472fdd2766e
SHA256 5c5b0de42d55486ed61dd3a6e96ab09f467bb38ae39fced97adc51ba07426c0e
CRC32 8FE1809E
ssdeep 768:oTtItqbNQtn4MXG4QMAehi3cY1AEErztGlDJSSNxXo:aSmc9XwMAeE371A9ntG7zzY
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 2826b55dc6fde66e_25.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\25.WNCRYT
Size 73.5KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 49cec597e4f6a637dfe9220ca13a395f
SHA1 ea94a917250a24645267ded580002efff5e3cb45
SHA256 2826b55dc6fde66e9b74c267dc0d01af90d1b5574564f4f2e6842cb656399136
CRC32 6DCD2BF2
ssdeep 1536:z3tcWsgxZG95zPOR11lMZqj2B+lgyTQ9l6rEHgEq0D3PJ:z3TxTXnMZq56X9S/zo3B
Yara None matched
VirusTotal Search for analysis
Name 3f33734b2d34cce8_m_croatian.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_croatian.wnry
Size 38.2KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 17194003fa70ce477326ce2f6deeb270
SHA1 e325988f68d327743926ea317abb9882f347fa73
SHA256 3f33734b2d34cce83936ce99c3494cd845f1d2c02d7f6da31d42dfc1ca15a171
CRC32 644F1C2E
ssdeep 384:SheftipUENLFsPzy3EFHjHdb2YG2+d18Scgn8c8/868H1F8E8/8Z3m8VdAm86a8n:Shef3jHd3G2n+p/mZrS14A
Yara None matched
VirusTotal Search for analysis
Name a2d25880c6430955_647.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\647.WNCRYT
Size 251.0B
Type ASCII text
MD5 aae4a89f6ab01044d6ba3511cbe6fe66
SHA1 639a94279453b0028995448fd2e221c1bde23cee
SHA256 a2d25880c64309552aaced082deed1ee006482a14cab97db524e9983ee84acfc
CRC32 7992B3BD
ssdeep 6:SlSyEtJLlpuoo6dmoIvriP/FLoP3v6rZoIo+3vrig6HK:4EnLzu8w+nF+3v6rP3v+lq
Yara None matched
VirusTotal Search for analysis
Name 5cd126b4f8c77bdf_libevent_core-2-0-5.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\TaskData\Tor\libevent_core-2-0-5.dll
Size 408.0KB
Processes 152 (@WanaDecryptor@.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 e5df3824f2fcad0c75fd601fcf37ee70
SHA1 902418a4c5f3684dba5e3246de8c4e21c92d674e
SHA256 5cd126b4f8c77bdf0c5c980761a9c84411586951122131f13b0640db83f792d8
CRC32 078232FF
ssdeep 6144:g8r2rQrFr0XGXnZ7rvzRsiWqnjmYl5oHIH9A:gtXGJnvmiggA
Yara
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 7a504e0ac8b9bed2_723.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\723.WNCRYT
Size 143.0B
Type PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
MD5 d8386138a5ad709a96b8e87a2f8abeeb
SHA1 aa4d2cdf5651eae1557ad82c2ae4dc7c3b562b6d
SHA256 7a504e0ac8b9bed28120cd088cca6da56569aca5000099f2db791a2dc4f0a859
CRC32 4F7280C1
ssdeep 3:yionv//thPl9vt3lh1JH9gpuLh75F7LUaM4elaqRoK6fsup:6v/lhPhdsuLZ24nSHusup
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name fec9aafbd19c3dac_usertile23.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 477256402c581beed8f9aef56cebfb0a
SHA1 af541187d2a0baaeb1329c6234c6007c5ef322f4
SHA256 fec9aafbd19c3dacbec0b2b1168d0720bdbc510b53919b628de736d15971139b
CRC32 A8211A58
ssdeep 768:6gObTRB6u2Je/2F6WEu1FEH/WN51ahb4VrtzdIDh7rES97Cn5WjGH:LObTRBOJ5F6cEHOvQh8TILrGH
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 5f3fd01af2714182_2.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2.WNCRYT
Size 719.0KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 09258ce6ca906d575afb3cf93ba5434b
SHA1 ddcc4af970206ba73124723764d0f2f66165d9e4
SHA256 5f3fd01af27141822d12cb8242c1193812b24cc5d40d2f1935a019cc561d3c34
CRC32 484B5BB3
ssdeep 12288:0HjbHPM418fCRDnQCZHjbHPM418fCRDnQCZHjbHPM418fCRDnS:ijbHPNxR3jbHPNxR3jbHPNxRm
Yara None matched
VirusTotal Search for analysis
Name 4667b82036e3d98d_kl_gl.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\kl_gl.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 f51ca81a8d2bdc876a592f691a0272d6
SHA1 b413d64eccdb0665b83fe1dfe82d062ceda75461
SHA256 4667b82036e3d98d88918122b77cc3ff9fdfec4803a257a1967a3dfc5ad1d0f0
CRC32 3082B297
ssdeep 12:bkEuyvqRDhWGpoXEUuvIEgWlhPjj7cVtWqLd+nDTAY:bkByvqJRpKEUuvIPRDWqLd+DTAY
Yara None matched
VirusTotal Search for analysis
Name 2f669b8eab66e175_memoryobject.h.wncry
Submit file
Filepath c:\python27\include\memoryobject.h.wncry
Size 3.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 60fba408b050923967f8a51f7dbd4009
SHA1 0e09cb1f3fce5ef3ab2a799f5d5fed6c3c4d2040
SHA256 2f669b8eab66e17555d76bb578f82086ad09bd156042a972fd31228a9341a3dc
CRC32 AACD04A2
ssdeep 96:oTVVKjLeSyBKWxaniSVUdgZQFHchOoOzD4aU:WBKCHNF9ojaU
Yara None matched
VirusTotal Search for analysis
Name eee0eda3a08e2397_311.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\311.WNCRYT
Size 2.5KB
Type ASCII text, with CRLF line terminators
MD5 2517e1c4ecd54e37bb6aa2c02bd63c5d
SHA1 b0971558552a7e9d503e99f6da2413a7f67e6c23
SHA256 eee0eda3a08e239798a90e0e42ccb8305ed9cd28e9c24a48777c484e389709b1
CRC32 BC4CBBB0
ssdeep 48:LrjKdKIPJhKPxGTfYxraAAUZYTMAzBIvo2I0tYVFaXWpw8YtPwpwXXvkfoZrdmm/:LrGdbPJhFfVS7Az41SPwHvkfoFdjMsKk
Yara None matched
VirusTotal Search for analysis
Name ba3de2052791d1d9_cast_app.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\cast_setup\cast_app.js.wncry
Size 137.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3afc9d59d6bc0cd1544a0e39a7323d1b
SHA1 7ee740940751f900e25d577875564b3f6be8012c
SHA256 ba3de2052791d1d90583b5e0aef1e32757454082468cbcdd9903f854c394dd68
CRC32 AB9781D8
ssdeep 3072:LbdoJm/+uUapLwbheMAt3oFdES0rN88JFD2svvpYR:Lbdem/Bpwde5ofF0R88JFasvvaR
Yara None matched
VirusTotal Search for analysis
Name 94c63462936a371c_440.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\440.WNCRYT
Size 3.0MB
Type data
MD5 812e01c4e0f875892464c7e7146e6266
SHA1 d4e9c32952a61a9134bbe9f0939f97daa2db0cab
SHA256 94c63462936a371c291cff880bb862de69f233093f0c2872a0b3a489aa7b8159
CRC32 F8D5BF3F
ssdeep 12288:PcP7CiRAq8Pomf1r1JYJhLdIth6uH3oGfmKWKrLEJ:o7CiRAB1r1C
Yara None matched
VirusTotal Search for analysis
Name 5bdc7389812adff5_eula.txt.wncry
Submit file
Filepath c:\util\processmonitor\eula.txt.wncry
Size 7.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fafb0a99a624f28ea799d223e1eda634
SHA1 3458fd72d8282f6972d5ddef2994ffe295e0e875
SHA256 5bdc7389812adff5849599d7e623c06263a491677df0d35fd295cbf5c042fa3b
CRC32 42B10A5E
ssdeep 192:R8glV/Um0eZMcbv5Sf+ldQPv4MBO7Reo20F2e5jfZjgwJP:R8gT8m0eZMcbvU+ldQPAwOR2ATZTp
Yara None matched
VirusTotal Search for analysis
Name ae38ad5452314b09_630.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\630.WNCRYT
Size 279.0B
Type ASCII text
MD5 07c16c81f1b59444508d0f475c2db175
SHA1 dedbdb2c9aca932c373c315fb6c5691dbedeb346
SHA256 ae38ad5452314b0946c5cb9d3c89cdfc2ad214e146eb683b8d0ce3fe84070fe1
CRC32 2829D3D5
ssdeep 6:SlSyEtJLlpuoo6dmoEbtvqH5oELE3vG5oELE3v6X5oEbto+3vnFDoAov:4EnLzu8ibtvqHBLE3v4LE3v6RbtF3v98
Yara None matched
VirusTotal Search for analysis
Name 20ec564c8ae43dfe_johab.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\johab.txt.wncry
Size 648.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 eced26583ab5c90b031cbed62284c0d3
SHA1 41ea9422651c9aac731fb51b63a501160d86d3e2
SHA256 20ec564c8ae43dfe0b39ab71f5f1f0266d8f5e10926519de20180b61a59ef33a
CRC32 9F4A468E
ssdeep 12:bkEpBfTVETpmq7Qw+cej/x4YL61hxsXc/joLViYauUzGYbOt2a+q5e2WnJ2rZZ/J:bkwhVE8G9i/TMxsX8jgcdDbOtmqA2ZXJ
Yara None matched
VirusTotal Search for analysis
Name deca44b62e877434_es_do.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_do.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 f534592a5f5eb87aa6a9d320f543085e
SHA1 4defe2b3ffa619d7924eda7e854893280d794355
SHA256 deca44b62e8774340319a8c0771105d1c512880f05f189367ade63978d1b04c3
CRC32 8800B11D
ssdeep 12:bkEbeOY1FJVZQS0vP9IxMK1f2PxbZeGgBxkg1YuSLqKRJSAD:bkOeLJ2vP9IxMWf2PPeJBxkKt+n
Yara None matched
VirusTotal Search for analysis
Name 7d657da5532ab3be_ru.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\ru.msg.wncry
Size 7.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f2a4a60e5750d89185cc3e93017921e0
SHA1 9e9905e07d8f7cce04a8f4b67e29889cad0e4b4c
SHA256 7d657da5532ab3be78c3ceda715285cb37055be1b6dceb2a9b145b2d24f380ff
CRC32 E619B6FD
ssdeep 192:KhuPoWP6IN9abbcjEb3EyqCyb4RClN9taqEaHK2Alm1fjD:Lok5N9ab4jEbRqTERClHcaqHS
Yara None matched
VirusTotal Search for analysis
Name 2f41195544e873e3_nb.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\nb.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 cb311384822a069b79c72485c5ddd5e9
SHA1 84fbca5aa0f4e4b755366fae41f5c89884341c8b
SHA256 2f41195544e873e30f50f6dd091a78d26122c16361f1790bc39fb462a8a70ffa
CRC32 FEDE676A
ssdeep 24:bkCBUbD2ZEV49SViweOMRLwxWhvXYxLY+5iJQK0d9Hr1Tbrbh6PUVgRdUk37MNFY:bkCB22ZEoSfMRLwEhvoxLY+UJQxdZrVo
Yara None matched
VirusTotal Search for analysis
Name b078a65c153f5e60_ga.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ga.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 68fb4c43e0e0e3a8936a64251cf0dfce
SHA1 8e0a468d17547bc7914fd1d1c203023400f58295
SHA256 b078a65c153f5e601fd244e219d44f9d36f14b256b2c2a9b69ba034a1901196e
CRC32 D3D47BC0
ssdeep 24:bk4/X6fmriXX5Pk2Mt2ajJCsOdCo0KyR/1fiBVy0hw68ZA/UTn:bk4/K+iHC2MYcCsOdCHpiBV1w68Zdn
Yara None matched
VirusTotal Search for analysis
Name f590cbc7c830731b_539.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\539.WNCRYT
Size 954.0B
Type GIF image data, version 87a, 150 x 35
MD5 d36af1ec9b66bb61a728702fd39ea0a4
SHA1 a0483b7947de6daec4a69864328662b3d70aab86
SHA256 f590cbc7c830731b68b55ca1b1ea11818b5afa3566537440a17017296578dae9
CRC32 8C9EA293
ssdeep 24:rEbB2ZcyvuV+Tmw3QCnsixNhJ5W+jXFi5:Yt2DvQw3Q0zN8+jA5
Yara None matched
VirusTotal Search for analysis
Name 08255f32eea017d3_613.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\613.WNCRYT
Size 502.0B
Type data
MD5 91ec3909d2074103da3fc3a5a71c8fed
SHA1 2fad35371f8340e9108103062b736cd6d6c63a0c
SHA256 08255f32eea017d306e286d9e6db090a05d26f0088719b122209819b6f73396d
CRC32 3C0BFB09
ssdeep 12:xf+O+JtaWxzZ6FO/OhBiGE/D3LxMAFF8VjjnPv:MFSG/RMAFAHPv
Yara None matched
VirusTotal Search for analysis
Name 360260360e2b4eac_bn.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\bn.msg.wncry
Size 2.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1d56ee74ed22b98aa0ae804ec29d32b2
SHA1 2d5a51606ef40389730389d10c6e1b8683dbdda1
SHA256 360260360e2b4eac7f692cebc0d33d078d3ab205165ef8112a91942188bd9e0c
CRC32 37E0337C
ssdeep 48:bk8lB1Ya0qtHlLvZeIf90Ab4TqRzpJyuUH2etT+RJfsjSoUgvL:o8lBh3wUPAqRJUt+RJEFRvL
Yara None matched
VirusTotal Search for analysis
Name d2dfe38e1b1f7425_index.txt.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\current\appdata\local\google\chrome\user data\default\service worker\cachestorage\b1152479bea6c46553d8c242ffa5edf2b0a050a7\index.txt.wncry
Size 408.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 d2244ba31c566d9f3bad2c11e9e204e2
SHA1 8fb557e2e1e473e09e9ef39567fd89db08b90e4a
SHA256 d2dfe38e1b1f74252709748cc4d1d8fc888787db0da5f23fa83125924ce5cf00
CRC32 F11F0A95
ssdeep 12:bkEnqGm/y+sGRZbg+/LLDSlH5B6kDUPcwOo+I+U:bkA9m/yORZrKjB7YE7C+U
Yara None matched
VirusTotal Search for analysis
Name 88bdaf4b25b684b0_688.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\688.WNCRYT
Size 411.0B
Type ASCII text
MD5 443e34e2e2bc7cb64a8ba52d99d6b4b6
SHA1 d323c03747fe68e9b73f7e5c1e10b168a40f2a2f
SHA256 88bdaf4b25b684b0320a2e11d3fe77dddd25e3b17141bd7ed1d63698c480e4ba
CRC32 47E7D3ED
ssdeep 12:4EnLzu8CjZWsn0sEjoD0sLvUFS3v6r5F3vMq:4azu84Z1nnEjoDnLvUFEvS5NvMq
Yara None matched
VirusTotal Search for analysis
Name 2072e48c98b480db_665.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\665.WNCRYT
Size 279.0B
Type ASCII text
MD5 04452d43da05a94414973f45cdd12869
SHA1 aeedcc2177b592a0025a1dbcffc0ef3634dbf562
SHA256 2072e48c98b480db5677188836485b4605d5a9d99870ac73b5bfe9dcc6db46f4
CRC32 D05F171C
ssdeep 6:SlSyEtJLlpuoo6dmobHAyg0obHAqo+3vG5obHAqo+3v6X5obHAy9+3vnFDoAov:4EnLzu8s33vj3v6r3v9dy
Yara None matched
VirusTotal Search for analysis
Name 92eaeef50181e689_es_pe.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_pe.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 6c35c0b7b514e8c840b3e2ad364e519e
SHA1 167bcee4785346c9332e397b65e2468d84ea4811
SHA256 92eaeef50181e6891a595fa527bbb00982b96c0087d865a8d459bf1666fcfeda
CRC32 3E502006
ssdeep 12:bkEIdCWfCPOUNrU6uHuR5TtuEAXVac80maGpIkjCYfH:bknCPOUm6uORNoEaac80CpIk2Yv
Yara None matched
VirusTotal Search for analysis
Name 46b1574daeec4009_psychedelic.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\psychedelic.jpg.wncry
Size 14.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 bc296abd3bfbb9ee7be29c9f5364550d
SHA1 8cd45b31a83ab9933f0bca25d2627deec4611432
SHA256 46b1574daeec4009f7da19c8f77ffd95f7ebf84d90f4010da737ad018fd6fe67
CRC32 FD7BE8E5
ssdeep 384:pYgQwXueqJU2JJu3QoGdoO52SZUrp5JrK:3QwelJUAtdtDYlK
Yara None matched
VirusTotal Search for analysis
Name 510d8eed3040b50a_113.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\113.WNCRYT
Size 1.2KB
Type ASCII text
MD5 73f0a9c360a90cb75c6da7ef87ef512f
SHA1 582eb224c9715c8336b4d1fce7ddec0d89f5ad71
SHA256 510d8eed3040b50afaf6a3c85bc98847f1b4d5d8a685c5ec06acc2491b890101
CRC32 83BAD781
ssdeep 24:4azu8FHYI4/+HYZoNPW43VvJZb3lSuRnixx/x5JfbiMQeTVYkG2CvRksvQ:46hHNHhu43VxZb3lSuRwxZ5VbiMQeTVL
Yara None matched
VirusTotal Search for analysis
Name 62866e95501c436b_338.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\338.WNCRYT
Size 2.9KB
Type GIF image data, version 89a, 113 x 175
MD5 da5fb10f4215e9a1f4b162257972f9f3
SHA1 8db7fb453b79b8f2b4e67ac30a4ba5b5bddebd3b
SHA256 62866e95501c436b329a15432355743c6efd64a37cfb65bcece465ab63ecf240
CRC32 66E5E46F
ssdeep 48:AmEwM8ioQoHJQBTThKVI7G78NLL120GFBBFXJRxlu+BmO/5lNqm7Eq:B57QoHJQt4II8BZ+jxluZO/5lNqm7Eq
Yara None matched
VirusTotal Search for analysis
Name 37fe00a5e10dc67d_state.tmp
Submit file
Filepath C:\Users\test22\AppData\Roaming\tor\state.tmp
Size 771.0B
Processes 2592 (taskhsvc.exe)
Type ASCII text, with CRLF line terminators
MD5 860738a7d2d87dd66701877dfc58811d
SHA1 c2b9d177a02a62101f98f0a094dffc3875849a7f
SHA256 37fe00a5e10dc67d93ae529a7f43176082f38cef1dbdcaea1ca036b4dd34e1b8
CRC32 CA84ECDA
ssdeep 12:bwxXY1Xr87HVBvwN6F1nFczN0JX1nF0YPtttcPe62kEwEbEzEV9Evw/R2Utv:bwRyQ7HVBfvcuJXvbCeY30Yu9Gw/R3d
Yara None matched
VirusTotal Search for analysis
Name b46855a99bf66a32_orangecircles.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\orangecircles.jpg.wncry
Size 6.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 62348e49a9c6695182f978d173a84e53
SHA1 0628af08e1810266bbc901e0094dbbf483bcd861
SHA256 b46855a99bf66a326980d768226ab8b3dadcd0bd95a11fc5370ccd144c611bf3
CRC32 B0D8DAFC
ssdeep 192:7ZYHlOYcJUfh1cTw/7e30Zyiy/32tC2O/vpX:8lOrJUfh1cTeemJsGO/vpX
Yara None matched
VirusTotal Search for analysis
Name 96f0bb18499679cd_289.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\289.WNCRYT
Size 52.3KB
Type C source, ASCII text, with CRLF line terminators
MD5 e2ddf4614af898761e5c9fe249977041
SHA1 6b205a76cde9a249d956d8e4795751ee95d91018
SHA256 96f0bb18499679cd0a09f87c797d77fcb765d64be24817378bcbd441c1a4c747
CRC32 3A0DF9ED
ssdeep 768:DxveT2aenwERF9AukVB8Kfxe/UlC92hsxxQGUAujg:Fm26ExApA4U6GUr8
Yara None matched
VirusTotal Search for analysis
Name 38286dbdb9a7919d_67.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\67.WNCRYT
Size 135.9KB
Type ASCII text, with CRLF line terminators
MD5 1bcd0c86642b4cc0bd329fc6f0db666b
SHA1 649d6074063f45a7718be7047a616f1d195cb633
SHA256 38286dbdb9a7919d3cfb1d4d8196da74dee5014f241af679e2e5633a0091ae14
CRC32 2FC8DF34
ssdeep 1536:OjSjSdA+evWsmSLHIvMSKLufkonr/jn/tUlLlVjg6jy5oWAAdD63E+rWivXdfHDB:Om301g6JmjB
Yara None matched
VirusTotal Search for analysis
Name 980e703dfb1eede7_662.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\662.WNCRYT
Size 279.0B
Type ASCII text
MD5 483652b6a3d8010c3cdb6cad0ad95e72
SHA1 8fcdb01d0729e9f1a0cac56f79edb79a37734af5
SHA256 980e703dfb1eede7de48c958f6b501ed4251f69cb0fbce0fca85555f5acf134a
CRC32 6681A4AA
ssdeep 6:SlSyEtJLlpuoo6dmoXqH5oIX3vG5oIX3v6X5og+3vnFDoAov:4EnLzu81qHd3v63v6Y3v9dy
Yara None matched
VirusTotal Search for analysis
Name 6b080288d2faba74_497.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\497.WNCRYT
Size 674.0B
Type C source, ASCII text, with CRLF line terminators
MD5 2e441936adcbd78ece3704dc68682266
SHA1 9ec34ed15d75c7f0b2b3bb2c598d51639f7c3be0
SHA256 6b080288d2faba743095d05328382e268f5315cee7a6b71d2aa336e8e305ce94
CRC32 662D485B
ssdeep 12:CwYNmrVceqXugPHH8EIS9ZdOK8vFRt+bREsDwYySNM5jwF9Rm64vKV7ql:dYN6cesDke6Rt+usDwYySNM5sF9QvQ7q
Yara None matched
VirusTotal Search for analysis
Name 5b14c88195a46083_567.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\567.WNCRYT
Size 12.0B
Type ASCII text
MD5 c03d218b189657c9403c05eabc13ef0e
SHA1 3b291777964b455432073a587105758ff08566b0
SHA256 5b14c88195a4608301d50404ed23bfbc22f9abeb122aee45bf4ac9d14ee95999
CRC32 8077FC18
ssdeep 3:a/L8c:4
Yara None matched
VirusTotal Search for analysis
Name eaed558d6439df7f_usertile24.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 35cbde129d22ad6080dc8fed0fd3e185
SHA1 e29871c61fe34d7159cf12daa543e1679f3ef63a
SHA256 eaed558d6439df7f6172277ad993c778b631aa73ffce8cd9619b525ff92a2265
CRC32 54775165
ssdeep 1536:znbqtqWbGhCAYVbAoSkeaRTC5w+4WcLsoewOQs3g:zWhiSb6krocLsozOxg
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 104940a1659b2081_761.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\761.WNCRYT
Size 752.0B
Type ASCII text
MD5 8dc6cae9cbe870bcc3c74516f3ca916b
SHA1 c9767ef852fee25e07a3530e824e707059ffc1b1
SHA256 104940a1659b208174a062a97689e68389f4a1e0a08258c8f0d8cdc3489b1181
CRC32 420940E4
ssdeep 12:MQiUc5ukocQiUc5ZXrHV4Uc5/RJBV4Uc5JyNZQiUc5RM54HV4Uc5G0HV4Uc5iqc8:MLfuELfZXrHOf/RJBOfcbLfNHOf9HOfp
Yara None matched
VirusTotal Search for analysis
Name a1b9ae3cd3cbe19d_ssl_key.passwd.pem.wncry
Submit file
Filepath c:\python27\lib\test\ssl_key.passwd.pem.wncry
Size 2.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fd48e5ed7235278846b571a09b352713
SHA1 fe79c3fe10702109dfbc9c193993bf95faab8cba
SHA256 a1b9ae3cd3cbe19d3adeb42d6d6f7e1ab8beafbd5b545df14e6c79510b669087
CRC32 DEAAC480
ssdeep 48:bkzFPX7QpC1BZSmGWw3xn8AKqigRxlj3x6IDij02ti2f2MLuYhKBFvp0f2TFs:ozF/7hZLoaFqiO3xlD/2t7OQbKBm2TK
Yara None matched
VirusTotal Search for analysis
Name b94d7ccbb381f9fa_iso2022_jp.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\iso2022_jp.txt.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 97e580f83c2d2b001eefaecfe13ab864
SHA1 2080899354ca6f1fadfa6255589c0f638230d4bf
SHA256 b94d7ccbb381f9fa060489d0af13583fba238529fd14ac6955932266323b4942
CRC32 39681449
ssdeep 24:bkYBcIhRDSczAlb4v3712zuuzYVkLq7LPTRDf/CHFJC7uu2dTfmH:bkYBjh5Sc80Ia7L7xDfaHPKx2dTuH
Yara None matched
VirusTotal Search for analysis
Name cc23a765fdd26279_abstract.h.wncry
Submit file
Filepath c:\python27\include\abstract.h.wncry
Size 45.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 9c2dec2986810aa771d6667662f8e74f
SHA1 97014048fc1bb6cc9fc07d46ec6bf82d8ee58aac
SHA256 cc23a765fdd26279f088d0c9a366e0801057104436d47162e1f3d362c02bf859
CRC32 BB0A2836
ssdeep 768:vZsj6QP+DLmHHcTZQPBeSmYZxGlizJbmDdtkWMlurnAd9swsG6YMbDOJCKA4KPiZ:Re6jpZKBeJxizJqdt5JAd9shGMXhPNPo
Yara None matched
VirusTotal Search for analysis
Name 27fe675aa568e7ad_bytesobject.h.wncry
Submit file
Filepath c:\python27\include\bytesobject.h.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e9aa4aec0187bc723b8fbad28c63ee40
SHA1 47880db322860b4e17cce6e06e94b61bfae530d8
SHA256 27fe675aa568e7ada727bd75f62b0920177170f1b74c3ed710be4367d9eae18b
CRC32 87F36484
ssdeep 24:bkhfOcsxxzx2OdK8pfdeTIXZKqSww1WqUYHQ971C7bBMF9W9wOrn58zv8qFoGGvb:bkUx2OdK8pfUIXjDP1C7bBMFk7rn58zg
Yara None matched
VirusTotal Search for analysis
Name 665784bf5a2b6813_usertile14.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 962093c737839e34489f80e492c4ebfe
SHA1 097a7e3bbdc5bd954666f87f7e505104c652e227
SHA256 665784bf5a2b6813e22449ec557faed6f2bba3925fd07ff6a27629f06bf5f9a1
CRC32 EA4D668A
ssdeep 768:7qYBRumkE1lsra67M8H4VcCJUlCUUEtCN8VMzA6:D7nkELsG6PH4HUCUftCNHzA6
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name ff46dfd4d7644e20_194.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\194.WNCRYT
Size 3.6KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 108x96, frames 3
MD5 23b1fbfd5e3bf49b4e2280953dfb95e3
SHA1 c8b3e932ea524da6e3c4defcfaf7031996aae8e4
SHA256 ff46dfd4d7644e209f7efe81a49986ac1aa843ca7965e251eb07f4e18a001040
CRC32 D79CF382
ssdeep 96:JoCvGA1MHt9VxZNUQ1h3S8Bg5uniZIa4a5XECS2zj:SVtRz3S8mQniZ9EHqj
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 74b54652a4cafe63_312.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\312.WNCRYT
Size 1.3KB
Type PEM certificate
MD5 fd3b4a968bd2273670cfe2e716236884
SHA1 346de7f1a890fe71c7c0786630e690b29d45b14b
SHA256 74b54652a4cafe634f9ff518d50dfc282380f1618649f27a9cc97c4b630b737c
CRC32 A3079794
ssdeep 24:LrUtoxX6KP1eVBJJ23expmceKW0oNV2PQn9HDQmUVVJ/Yli05Xbb+A:LrU6nPMVBr23exYco9V2uGRbGJ
Yara None matched
VirusTotal Search for analysis
Name 2ee356ffa2491a5a_672.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\672.WNCRYT
Size 244.0B
Type ASCII text
MD5 8666e24230aed4dc76db93be1ea07ff6
SHA1 7c688c8693c76aee07fb32637cd58e47a85760f3
SHA256 2ee356ffa2491a5a60bdf7d7febfac426824904738615a0c1d07aef6bda3b76f
CRC32 310C0CB4
ssdeep 6:SlSyEtJLlpuoo6dmoi5jLWNLoyJ+3vULoia+3vjLtA6:4EnLzu8m3WNJ+3v23v3t3
Yara None matched
VirusTotal Search for analysis
Name ef81b41ec69f67a3_136.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\136.WNCRYT
Size 3.3KB
Type ASCII text, with very long lines
MD5 9c33ffdd4c13d2357ab595ec3ba70f04
SHA1 a87f20f7a331defc33496ecda50d855c8396e040
SHA256 ef81b41ec69f67a394ece2b3983b67b3d0c8813624c2bfa1d8a8c15b21608ac9
CRC32 40A3BAF7
ssdeep 48:468jDI/Tw71xDqwPqDa8c3FLbYmhyvMDKbW0YGLuoEyzag29dL:hn7wRdNL
Yara None matched
VirusTotal Search for analysis
Name 86768f01e7b4d54f_509.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\509.WNCRYT
Size 454.0B
Type MIME entity, ASCII text, with CRLF line terminators
MD5 12cd9dc95503f771f82eb4a184eb6447
SHA1 fc90c31e442cceffb391749b7ecd93488db0c8e7
SHA256 86768f01e7b4d54f5bdf43ef9a11200391029f69779500f78bcf5984afa89b12
CRC32 AEB805C8
ssdeep 12:3XmyFxxGEYUp8MG886AQcVgQearowgQYf1IcgQbgQrj:3XmWxoErbGiuVtrowiac5Nj
Yara None matched
VirusTotal Search for analysis
Name 400e6e276fc3fa82_226.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\226.WNCRYT
Size 2.0KB
Type C source, ASCII text, with CRLF line terminators
MD5 0310f1528ca7a9966680f95117ea487e
SHA1 aaac39321b9677073d716be58343b4a1fcb560b0
SHA256 400e6e276fc3fa823f29629fecff302bd08d1abb896fb500c4faa334aa3293fd
CRC32 22473BA8
ssdeep 48:FzgWyGOLnibA27jnffuuDQGSFKljNIU9P4Pmib:VgWyG6nKA27K5fKjb9aRb
Yara None matched
VirusTotal Search for analysis
Name 7984867d5ae672f4_559.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\559.WNCRYT
Size 442.0B
Type ASCII text, with CRLF line terminators
MD5 253fd0b1e7361c451499ba9f299e5c4a
SHA1 cf13badf5b1c2bc536146d9c78155af7c6d0a244
SHA256 7984867d5ae672f4a5c3b9ad44de3e48f2bfa794bbc0ac5cb93a2b6ffef20173
CRC32 627950E1
ssdeep 12:FarcIdcIBpcIBWcIw4vHcIw4yrcIwecIwfcIwmcIw3cIwv0HcIwv3w3GurR:CcBYcaNUcNJINecN0NmcNsNvucNvAWs
Yara None matched
VirusTotal Search for analysis
Name 4254b56e2d7f5dd7_keycert.pem.wncry
Submit file
Filepath c:\python27\lib\test\keycert.pem.wncry
Size 4.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a5f8e936898bcd5476e6f491c3f9920f
SHA1 f628db0b1ecdcc6d50205923199f40fda6d83445
SHA256 4254b56e2d7f5dd724f11b83ae78cee27307330172e2068c0b28c013f638f34e
CRC32 1C4C208C
ssdeep 96:o1d7owHL9uGxkciF6SiycVAxRbLMe3CbBiL5yoVrIEZDLh4c36hF8NlqVEgW0:edcwL9MF6SiycVmRbYe3ABi17IINqHgE
Yara None matched
VirusTotal Search for analysis
Name c42203ef4a466817_00000000.pky
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\00000000.pky
Size 276.0B
Processes 2632 (WannaCry.exe)
Type b.out overlay standalone executable
MD5 90cb06686ff3d9bb87596c2267f2f1bc
SHA1 162f673cedc068e14bc3258512a0a16d9907ba40
SHA256 c42203ef4a4668177f67b6876f6419fe04a4a6708c99867f3f3197b83e91454b
CRC32 65E67C4A
ssdeep 6:mtNeggHW1TwRfv6ZiMdmD1Xcy/oabNf5rzMdMvQns1/Ca:YelMIH6xdryAabNyfg
Yara None matched
VirusTotal Search for analysis
Name db938715da4930f6_5.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\5.WNCRYT
Size 975.8KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 5fb635bb51d644ade170c95c5984edaf
SHA1 bd35e50f6de36f631701e2e3fe6cc8acdfb91c81
SHA256 db938715da4930f62b31961b51adaf86f87074f8426ea3f073c6242660b70528
CRC32 8C0BE4DC
ssdeep 24576:eDh0BzWodwLCDh0BzWodwLCDh0BzWodwLCDh0BzWod8:3zWyozWyozWyozWy8
Yara None matched
VirusTotal Search for analysis
Name 4d6f637226a6fac6_327.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\327.WNCRYT
Size 2.2KB
Type ASCII text
MD5 6368d86aca168926d271f7c5280daf2e
SHA1 a31d2cf370cc8fb29c9225dc7ed0ddfef17efbda
SHA256 4d6f637226a6fac6eb180d4aed0812bed2cac0cca54d92a00454c8942a007b02
CRC32 0FB0E687
ssdeep 48:hDsNN7HCqxWGTpEf0M1+meRF3R+DZaNN7HCqxWGTpEf0M1+menF3R+DZA:hjXa
Yara None matched
VirusTotal Search for analysis
Name b567f3a653c3156b_58.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\58.WNCRYT
Size 12.2KB
Type ASCII text, with CRLF line terminators
MD5 94a14c41fab6d982132db542a1e5e0cd
SHA1 0b0446f06b52a4a0f0a5c7cbd4a10413038743e4
SHA256 b567f3a653c3156b882d5418aa1f02cbece014e32d25802b93a83fab972963c5
CRC32 C85E236D
ssdeep 192:pGk5EsxIpmggER6fCWshGh0JLFnTUx7mKX3fVa7A2XhJ:pV5EsxIpmrLBmLnT47mK/Vj2XhJ
Yara None matched
VirusTotal Search for analysis
Name bc6274dfdf5057fa_pluck-pcm24.wav.wncry
Submit file
Filepath c:\python27\lib\test\audiodata\pluck-pcm24.wav.wncry
Size 19.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5fa0f943bc92cdc2c6585a0f4be6c0cc
SHA1 f3f6d0f3428975678030c4ce4956e3c455e3743e
SHA256 bc6274dfdf5057fa72220126afc52cb551b0feed4221157cfbacfde0f79cd1d6
CRC32 E586F707
ssdeep 384:teAm4bOlSIh9wZzC09p7EbRiHXrb6Bg7kCKrzIbOBY/4iSTboCIcrUbJk6r:teASlZhszC0cti3im7tbO6W1r0WW
Yara None matched
VirusTotal Search for analysis
Name 9c8961d444933e42_24.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\24.WNCRYT
Size 256.9KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 c72f7b2c934e1446206e9c33b326cd38
SHA1 967c8050fab041152bef18a8ae8d3642138d7d42
SHA256 9c8961d444933e42a1e0a335ce8574e15b993729bfd2d7f3d1b8a7166fc67d61
CRC32 BBFC6AFA
ssdeep 6144:zenv6fx231aXx3hBJcTN+6Hzd4pxJMDeJ:ynv6ZYsXFvScozdW2W
Yara None matched
VirusTotal Search for analysis
Name 0595a246eeda128a_159.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\159.WNCRYT
Size 17.7KB
Type ASCII text, with CRLF line terminators
MD5 dfb202b1a8640bc1f6f96eba7a1cec5a
SHA1 9e222b18433e508564aa0e15e95ac3268a5c4ee8
SHA256 0595a246eeda128a28176a671463635dc1eb3cb474a43184f2611a26635c9495
CRC32 608F886A
ssdeep 384:un94s68dfaewCn1xLKj9ibkQkL47SICEZUKdyL4MWMq4WI2kd:cwCnpMCaKdyLF
Yara None matched
VirusTotal Search for analysis
Name 36d162eaecc825e8_724.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\724.WNCRYT
Size 91.0B
Type ASCII text
MD5 0312508a987d1ebadc1ba96950970d5c
SHA1 ffe9a28cde2e130f64ccb51a76df3a453464be19
SHA256 36d162eaecc825e8e361ceb4cfac6e97e7794e34e616c06a7b35fb4794c000db
CRC32 06BF9A2E
ssdeep 3:yLR9dBkADF2vRtP3unKJRyc6YrQIHev:yL7YmgmKJgc6YrNHev
Yara None matched
VirusTotal Search for analysis
Name afbbb487a45d9d92_233.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\233.WNCRYT
Size 6.2KB
Type C source, ASCII text, with CRLF line terminators
MD5 e6925d7d994b61c347d437a5368b3701
SHA1 ffbd92b6c478674c0924259e3ae486216776c4a8
SHA256 afbbb487a45d9d9202d0fd6a1167cc8718b6ec3b2afa758f1708fbfec99adf86
CRC32 A58246E3
ssdeep 192:neJw+8JKIgFZ4ZcT4KTXGn7b7WoPBaMxmShl5:upIyZ4ZMTW7b7RPBaMLhz
Yara None matched
VirusTotal Search for analysis
Name 9483a995582f2dda_481.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\481.WNCRYT
Size 948.0B
Type C source, ASCII text, with CRLF line terminators
MD5 dcc48fc557f8337d7baa90e13d34b36a
SHA1 f5c5c265092d3852be717f4918611ac94c7faa5f
SHA256 9483a995582f2ddad6b47f85bb300371346ca10e846b923170d39e523815134f
CRC32 557A6344
ssdeep 12:UIBamrLucKRI0X0m1+Y+LPREnkiIIN1z7paqIPNlcrWCnq024q+:XasEQyuszYJ2M4q+
Yara None matched
VirusTotal Search for analysis
Name 0712fc09673febd0_cellobject.h.wncry
Submit file
Filepath c:\python27\include\cellobject.h.wncry
Size 968.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 cc5702523938a50eff754b9550205763
SHA1 39a18df5a39e7b71449646cb85c9860171526d56
SHA256 0712fc09673febd05d96ccb375abbc26a911876d41ef82411ee5ddb3c69c0480
CRC32 FA652FC4
ssdeep 24:bkYYzLvWs/OPXJzHR7U120dloOSZBgD4Qnci:bkrzas/OPJTtU1hlqBgvP
Yara None matched
VirusTotal Search for analysis
Name 3417fc6ed1266011_531.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\531.WNCRYT
Size 856.0B
Type ASCII text, with CRLF line terminators
MD5 46ab9dcf9f03d6f73c36157a3207c7a3
SHA1 2b20f33b212893e88f48e06deb7e10ae12a36865
SHA256 3417fc6ed1266011c7408c84baf1ea5f5cc3354deb1d5f554d1eb28719c9697a
CRC32 A250A213
ssdeep 12:w2mMQjnpkmn8VHiXixmYw2Qj8rRNJWLQiY1C8mAX6QQALy9P3bVHqdWLQiY1MVHb:w2mZpxO0uEgM56DaRfD75ea77V
Yara None matched
VirusTotal Search for analysis
Name 76457bceb89ab329_605.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\605.WNCRYT
Size 879.0B
Type Non-ISO extended-ASCII text, with CRLF line terminators
MD5 1a5b20fcd56bcfa3df514f5586434502
SHA1 0e704fb989b9ae487be139b193f62f3535ab3cce
SHA256 76457bceb89ab329ae07b0e2f0260b48d5f1b590bc67d968caba0e38f2c7a378
CRC32 D142FFF1
ssdeep 24:tY7R+nr78+DYKqhR2Nl7nMTjYN4vcDnuccPGwIbWpvXRAIm8:t++r7qZ2Nl7nEkDnuBPGwIbCvXRC8
Yara None matched
VirusTotal Search for analysis
Name 7db244cd8e05e79e_pkcs11.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\profiles\qxo5wa6x.default-release\pkcs11.txt.wncry
Size 808.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 c60a83d3454a26e4e88d425f54b5d2c7
SHA1 24ef51402ecdb03b3a3f1a10c6cd3656be8a5f77
SHA256 7db244cd8e05e79e29ccc01866025abc7664dcd334064b6a1f5db29bc05841cb
CRC32 4ECA75BA
ssdeep 24:bkDEUJrYIc7eZEqPqS/VyvlD72xv4e3mTv:bkDrbc7iDP/yvi4H
Yara None matched
VirusTotal Search for analysis
Name 48008de92c8581a5_bufferobject.h.wncry
Submit file
Filepath c:\python27\include\bufferobject.h.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 10a828c9a824ff0df1d30ce3df89202d
SHA1 cbb14dbb163787ef1917315e3316219caa6f8411
SHA256 48008de92c8581a5b0bdfe9847723107539b50af5d96f95ff4eb8c4c7276722f
CRC32 15105EA6
ssdeep 24:bkt1EKAdRYefedjOKb9hs0JZaKmOdNpwURv4FqTQcB6vn9y5ueZLg9J8uXckyC:bkt1EKAceGFOKbHxvV5xwURvXan9y5xa
Yara None matched
VirusTotal Search for analysis
Name 954f7d96502b5c5f_166.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\166.WNCRYT
Size 858.8KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, datetime=2009:03:12 13:46:42], baseline, precision 8, 1024x768, frames 3
MD5 076e3caed758a1c18c91a0e9cae3368f
SHA1 f5f8ad26819a471318d24631fa5055036712a87e
SHA256 954f7d96502b5c5fe2e98a5045bca7f5e9ba11e3dbf92a5c0214a6aa4c7f2208
CRC32 81F07779
ssdeep 24576:px5cyLzoy4z5LPrMcs5dmYOYFQn1s97QJv8wBU:pzbL0zzJsKJS1QJv8wBU
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 845d0e178aeebd6c_m_chinese (simplified).wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_chinese (simplified).wnry
Size 53.1KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 0252d45ca21c8e43c9742285c48e91ad
SHA1 5c14551d2736eef3a1c1970cc492206e531703c1
SHA256 845d0e178aeebd6c7e2a2e9697b2bf6cf02028c50c288b3ba88fe2918ea2834a
CRC32 E643BA29
ssdeep 768:SWjkSFwwlUdcUG2HAmDTzpXtgmDNQ8qD7DHDqMtgDdLDMaDoKMGzD0DWJQ8/QoZ4:SWcwiqDB
Yara None matched
VirusTotal Search for analysis
Name eb443bc679231016_c.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\c.wnry
Size 780.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 3f475c6e7bf688ab27ea4ea62c4b6ae5
SHA1 101802232b7233018438eecf8c507ff991cc7dad
SHA256 eb443bc679231016c4ec22356d5128080f7303831c91e7296aac625a4cc598a6
CRC32 8B00ACB4
ssdeep 6:cgi1+IQoKvbHaHqHgVcKKfF9mHRMMPRGS37LlN/sUQqGUSGeTsdEC:cgiqdHaRVcKKfm2MYS3sUQqGLGeTEV
Yara None matched
VirusTotal Search for analysis
Name cd02f3de85dc57cd_no_entry.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\no_entry.gif.wncry
Size 456.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a65ce98ae79291a303ce5a1354407480
SHA1 e21a7c714aad8593a3cc6986e26893388bbb56b3
SHA256 cd02f3de85dc57cd4777e98f946d1bde609499137ea9ae849a310b6e3e11e293
CRC32 E530B0AB
ssdeep 6:bkEYnfZ1YbvTCUHOgoEC+QInWAReFKHcKNdeGOaM3TMuQYL+WKxbUjicZEfvHGpe:bkEy1YaU0PI5N8GOQjYiVUjiD/Gplc+c
Yara None matched
VirusTotal Search for analysis
Name f96b69ac7ac1d0c4_efxszzbotjwlnikz.docm.wncry
Submit file
Filepath c:\users\test22\documents\efxszzbotjwlnikz.docm.wncry
Size 73.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c6cf742d7ef55c48d18eaab2b4492cc2
SHA1 e1ef212e67cabe3758ce7b8bd4dca9aafd6d037a
SHA256 f96b69ac7ac1d0c43ba5b4bc6bd2b269610679a6732f38b884561647baffa84c
CRC32 CB33950A
ssdeep 1536:MqXC4YCRKjAoq7nnY75yyc1yr3SVYDdtUBLMMmee2pfi3np+ztV:cSRWf+U5yycgDdgQQeccnSV
Yara None matched
VirusTotal Search for analysis
Name 43f887eec8cb9ace_34.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\34.WNCRYT
Size 10.0B
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 72a5223e21f17273053277eac8b1dbc2
SHA1 2e614371bff4d2c7421d67d8e7c4e0ead66b4679
SHA256 43f887eec8cb9acecd2cbb4a1bb5092f6653ae4354059b4dfb5e5cbcd889fe1f
CRC32 36842573
ssdeep 3:9nkC:pF
Yara None matched
VirusTotal Search for analysis
Name 2a97b236002001d0_285.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\285.WNCRYT
Size 2.9KB
Type C source, ASCII text, with CRLF line terminators
MD5 491de70186d78b553c589b71c9ca17e5
SHA1 16dca1d464a7866904f15d9fbd8ef2092bec0ccb
SHA256 2a97b236002001d0021d233497c55f9fb256945c0aa85468209cd225d1e5187b
CRC32 CE8DB3C7
ssdeep 48:BGDFGDUQF08XGSnZUzGSX41zJ0zpKXkYjrTHKbTjsf3CMSypPYSNRD9:MglF0vSazGSOG1K0wHEw3zSWPYSNl9
Yara None matched
VirusTotal Search for analysis
Name bca879c66f047296_290.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\290.WNCRYT
Size 2.8KB
Type C source, ASCII text, with CRLF line terminators
MD5 ac961c1d3ff4d96085355ee5fdd1391f
SHA1 0a07729963fe7a94fc65eaad185d67b3712d83f7
SHA256 bca879c66f04729672288035bbb87e567ff0573334d56cde13a9c7ecdc5a7b7f
CRC32 2A2A39BA
ssdeep 48:xH1iZsjf3htgu30YUqx9wSbYP7MYi31U5I00dKLgryaKakn6L7JPDfMC7hi7hN:/x4Yj0NP06eoC0ak6vJPDnKN
Yara None matched
VirusTotal Search for analysis
Name aa0ce24a091839b3_412.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\412.WNCRYT
Size 22.9KB
Type HTML document, ASCII text, with very long lines
MD5 e12a0f120a276fdff591075f15d7baf7
SHA1 113b1b3703874bdd7baff97496fc2e49a85cefb5
SHA256 aa0ce24a091839b38ae815ede32f69f11153248f98bf9c8acd33b140c1a68c18
CRC32 BAD56945
ssdeep 384:QhPZe6ifh8r34vWK01yKXzg8oj6nsPlhtWk5Is2sQEbhVaZQXUh6E:5mr3I200omoK7uwZQEsE
Yara None matched
VirusTotal Search for analysis
Name 14a925e91f1f3d9d_dependency_links.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\mouseinfo-0.1.3-py2.7.egg-info\dependency_links.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 ad5ad4d5cfd2f91e209e2bc22d68a416
SHA1 4aeb70116e75a1127878aaf268b381f233b78d39
SHA256 14a925e91f1f3d9d69cf1de34b24a0025de3aa6a26c5f69f5a1a0bb76c50b1d5
CRC32 C35A8AD8
ssdeep 6:bkE+9566FHmFYSuYUmjTCNSTp9WXHFqK38jhgktulnhX8VmTcmfBkk12ro:bkESBvnYNTOSTp9WXF38jhTInhsVrm57
Yara None matched
VirusTotal Search for analysis
Name e1dde8c8746b270f_news.txt.wncry
Submit file
Filepath c:\python27\news.txt.wncry
Size 509.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 0ca70325023c5872fc908009332d18c6
SHA1 cf440567a7905fc88e8b5e1d8f9d8537f1de0ee5
SHA256 e1dde8c8746b270f57eba4ed1aa45ff67971e42f1fec1c29a6155ee264b463c8
CRC32 824A7400
ssdeep 12288:duCwTXgZjHZTSVyQlfQ6zP9UC2MMmxA+9Ckteuw8WiB3e8JyF:YJXgZzZ8BlfL79IMMK9bte/9iBu8JyF
Yara None matched
VirusTotal Search for analysis
Name 5a36df959db6beb4_msg_42.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_42.txt.wncry
Size 616.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 3176a9b1c1658605378b3889c1a5c8c8
SHA1 57d9343b948e6c9bd4861fb4ef1f0a8eb95b3570
SHA256 5a36df959db6beb458c47c2c99adf4b0c9b20a44131444439d389e2d5aa3d526
CRC32 17D6D4DC
ssdeep 12:bkEz4v/4JKVGx4ePIL2R1bpnou79YYuooEgIRMjUvTAF5NTL:bkik/VG+eQyR1bBouxY6oEgW3AFD
Yara None matched
VirusTotal Search for analysis
Name 6cfe58864ab204d6_224.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\224.WNCRYT
Size 45.5KB
Type C source, ASCII text, with CRLF line terminators
MD5 440a94d156284e27152e06874a9567c2
SHA1 473e6d48d27362d5ec8d874e85a6a9e3d46b6c4a
SHA256 6cfe58864ab204d6513b69f007128734b750ea74ac911aeeb7a22375840b6184
CRC32 A45419D6
ssdeep 384:R1tXHbjZUsxYJO2r16XQRXXQbDH/cfZjpfx5W4yjwrOGt3QW0iyQU+FRkfSiiKil:ZXF21v1OkxU+wwXOT4nFJEE
Yara None matched
VirusTotal Search for analysis
Name 321829a9e48a5bcd_520.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\520.WNCRYT
Size 147.0B
Type news or mail, ASCII text, with CRLF line terminators
MD5 19f247b2d60efd9f0ed83376e8d3928f
SHA1 95bd7ef76ad2e57cd404bb1b8382883ec51dc522
SHA256 321829a9e48a5bcd0f5b0dfebe55c11c0fbebad9eba70b6e95d2ec62ca1d9af9
CRC32 29EF64CF
ssdeep 3:m6y9LReIeAtISin/BIq/v9+5IeAtRATmlL78aeQEeQh+Ov:mAQ67JLv9gQ8KG/bj
Yara None matched
VirusTotal Search for analysis
Name fd1e210a96352b35_readme.txt.wncry
Submit file
Filepath c:\python27\lib\idlelib\readme.txt.wncry
Size 8.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8ffb838fb2199e34025d8fde9de14975
SHA1 eec45fd9bf16a5e326546817a68dee82655d71a1
SHA256 fd1e210a96352b3557b6c8f5d56486736a2457955bad769aebca5635897f9fc7
CRC32 3E3EE947
ssdeep 192:b3hp0CXuv8ylOAhKnYbYu44rAetJoor2rhHl4ob94yV0:b3hpJI88fKn0boeP0r8ob9b6
Yara None matched
VirusTotal Search for analysis
Name a12ac7adf0afeea4_hz-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\hz-utf8.txt.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 fbf44740978ad8e1571f496ff2b18991
SHA1 3f9bd166f20ac0cd9b7abbbfa2abe56baf1bc086
SHA256 a12ac7adf0afeea4b26c92c661accd359651b5c94dd787de44e4d7f38e3a4fbd
CRC32 43FD5FDC
ssdeep 6:bkEMHH+2s3m2s9vLbC9ZobkePKR/w1Mw4OyoN5l6jL6yFuDZWUn:bkEMn+zmj1vLPK41h4OtbAL6y+1n
Yara None matched
VirusTotal Search for analysis
Name e503fd1cf6839bcf_readme.txt.wncry
Submit file
Filepath c:\python27\tools\webchecker\readme.txt.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ab2b2c33c1522478ab9e7ea91d12cc52
SHA1 87ece8f24d01243fdcec08caebe0db32fdd7169d
SHA256 e503fd1cf6839bcf710317dcede6736cdff106a855bc50ad0dcd7b42c75bfa15
CRC32 70397190
ssdeep 24:bkReGCmfTz/3niVOLXBT/b6rF9BBeGJ1yuGdbmU58+QZuG:bkAGCmfTAuBT/OBeGJxGxmy3QEG
Yara None matched
VirusTotal Search for analysis
Name aaae8a1bfa511159_188.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\188.WNCRYT
Size 1.9KB
Type JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1], baseline, precision 8, 219x62, frames 3
MD5 a910a22193122c6a93048b4abfabebee
SHA1 2b8c1a8546d2ddc91a5bdce7bbc17ee0af60c07e
SHA256 aaae8a1bfa51115943caff40a6ed2e1f54d7f27913f1df1c3f21b1aacb6e1647
CRC32 B36D6746
ssdeep 48:1B9YMQuERAUXB3amO8inT/qchkN7VgmCrGAo9J12csc:1LhLElB3o/QN7Vgm9AWJ1Jsc
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 1f363eb477bd32ec_408.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\408.WNCRYT
Size 4.9KB
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 ea20d791ba2fcc54bba2449098e60f3c
SHA1 f7f9b9cf785b4a61f563c2643e9a0625dbab8b49
SHA256 1f363eb477bd32ec288b68901c1a093e63e16adcf62099d73a3e8d5123141586
CRC32 1CB2180B
ssdeep 96:Mpu+Onf577+GxkE0StJycxbKpdKEV7c++VjwVyXrfpr1TXJ7KAQLZl2e29qkYqAf:MYvfJSGH0iCLo3VjuERrlZzQLKWf
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 575fabb3880d8059_430.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\430.WNCRYT
Size 626.7KB
Type ASCII text, with very long lines
MD5 5061ab689fbd713e624cd414d2694e56
SHA1 19e3cf1fce270b7408c7cffa29e5af6020da61d0
SHA256 575fabb3880d8059b3511daf7ab62c66b808a182b5a8148c25bede26a856705c
CRC32 A140341F
ssdeep 6144:EzWQezEwHk1KgYAHGv0CyXo/oiA9J09KthzzK9yd4NHqieP8wy:EXezEwHk13wcoQiA9i9Kt5zOyW9S8wy
Yara
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 8760336066b246b4_log.txt.wncry
Submit file
Filepath c:\log.txt.wncry
Size 24.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c460f58caf2b50f0965183397197db88
SHA1 af61492b37ec0971903313d38bba39e9a6111678
SHA256 8760336066b246b4bd8b4aa713d9a6b8c01c3f31f8b325903f09259ae702479d
CRC32 CB6D107F
ssdeep 384:WdipfqWM8F++8hk+R8J1dhcPpzt4drTkmAFIpoCn03XfhQFWG/Y0jNSTVYZxycP0:0ipCW9F+q+qjdGt4+mFpopXf/egVYZM5
Yara None matched
VirusTotal Search for analysis
Name 05178d243d474b14_id_id.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\id_id.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 603762e4c13334ef417ea3ba72e8de61
SHA1 181b90908de07ed2ae635f7770325ad770d6c797
SHA256 05178d243d474b149d4a1f2142a1d09d4bdab52b0339018115d0e45c56c3310d
CRC32 E2D86346
ssdeep 12:bkEc7QYc5bVFxOmo2uhJEZkGvsJ2dMpEotZWscjVh0wJ/:bkrQd5bVFgGtUJHfZWsiUwJ/
Yara None matched
VirusTotal Search for analysis
Name 5a628c6b58a108a1_jdhejjbwhuxqp.doc.wncry
Submit file
Filepath c:\users\test22\documents\jdhejjbwhuxqp.doc.wncry
Size 230.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 faa6e0e22291f97c60c8dfb2ef4ecb81
SHA1 e7eeccdd4fd1ecfb1e7eb60d8049961d1c150a03
SHA256 5a628c6b58a108a130fc4bde3acb2f7f98d28b5c3d4051d31b4d48301c5c06a1
CRC32 78FE314C
ssdeep 6144:V+1IqJC0f8OED3nAZAXRp3Rl50Cixh7xPud3d8Dei7/Ur:01I0tNcXAZAXz39ixhtKNKT7e
Yara None matched
VirusTotal Search for analysis
Name e391dccb56e047b9_vytyvaoqvtpe.docx.wncry
Submit file
Filepath c:\users\test22\documents\vytyvaoqvtpe.docx.wncry
Size 469.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8df8fd7ca8f9c22819c86595955735e8
SHA1 861e1c5920aea98fcf2271d04dd6bbefef08c0ae
SHA256 e391dccb56e047b9c4e029448629855ceee598d4952b5449f1b4418ac4186c08
CRC32 D450B7EB
ssdeep 6144:sp+HbcoYdc5FuyY6DLgsMvWEnAmV/drmwDzyhKMC04OWV5/UhiJfWIpmorSyhru1:xHbc8vTcsLEAOdrug70w3/dWIpmorZhY
Yara None matched
VirusTotal Search for analysis
Name 17a76974d91bcdcf_uvxrehdtdz.docm.wncry
Submit file
Filepath c:\users\test22\documents\uvxrehdtdz.docm.wncry
Size 86.5KB
Processes 2632 (WannaCry.exe) 2980 (cscript.exe)
Type data
MD5 1f979f4d850f6e4787cceac85cbedb18
SHA1 be4b4d914c8e6fcb26d59a6f40f3a2bdd56045fd
SHA256 17a76974d91bcdcf783550a51f86f33aa0c84e648bfb7bc8c708b0c9e320ee9c
CRC32 72A2C774
ssdeep 1536:ekVZX/WK1Eryd7La4ZtyCYXFB9o+NyLJLkB3eOIp1QDD73JkIE:emHx7LMnN2yOOIp1Q3TJkIE
Yara None matched
VirusTotal Search for analysis
Name c74c324a12a9c12f_ssl_key.pem.wncry
Submit file
Filepath c:\python27\lib\test\ssl_key.pem.wncry
Size 2.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2e7955d61b21f2d07dc41f412e736290
SHA1 85abd99d5daf74462b5c573fbbfa51cfd8970744
SHA256 c74c324a12a9c12fab6b72ca2c20045523a624c1531aae1a64aea771c3f3d66c
CRC32 A9370F08
ssdeep 48:bk54ACNbPD12JXe0jFLsXtEYNKLzkdwBDLZi4HSEkiSH9xuz3NBddIvTcN6h:oBChD1kraKVk+BDLZijbiSzu7LddqKm
Yara None matched
VirusTotal Search for analysis
Name cff71b59c648f096_usertile27.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 f15bc24c02b8f476f211ce728a29e7ac
SHA1 836b9ad7237e61174c4bb3d0f86a37a7386d398d
SHA256 cff71b59c648f09654dfefd33469ec68cbeed35ddaf3e053b0a9f78686a06c6d
CRC32 C258EB14
ssdeep 768:CEnjjTn5HUz++1up6iI/ojPPuuaVyMBsoYPXamdBA2gYHXUoY:CEfL50zupnj+uHMBsoYSeZgY3s
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 01d5422f7f1eddc1_msg_45.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_45.txt.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5000a6390b2567c8274260ddfda077fe
SHA1 46f312a16d980b1d775bb62f0b68095e30db94ce
SHA256 01d5422f7f1eddc161da4c1e7880d1bbed94dc1456ee8e4e4544ed00ee4133c6
CRC32 D6E633D2
ssdeep 24:bkJp2e6o6zIfSc+UEpBdgLBGR55x2JuwyZu/Xk4T4gkkkoZLFh03pEEhbO:bknyzYSdgiQuHATpDVFO5ED
Yara None matched
VirusTotal Search for analysis
Name 2904eb2b8d7af956_readme.txt.wncry
Submit file
Filepath c:\users\test22\desktop\readme.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a5fe1c36a8fd15a597d1c4ecf376daee
SHA1 2fbd2a193985e942c9f7da0399ffa33a74641d11
SHA256 2904eb2b8d7af956679cf4a946adf67cd88775a85ebafa23ff2d55d6176b2d7c
CRC32 C5138B77
ssdeep 6:bkEVVejN/Q0HLbmVCSZ/Tqx2RSPcdgTxpzFbBQWEeZ30bdQ1Yrg8A:bkEHoN/Q0r6VCSZbqCqxpz1Wg0xNg8A
Yara None matched
VirusTotal Search for analysis
Name f77a20bf57dedae7_gb2312.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\gb2312.txt.wncry
Size 616.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 57164a53230f789f911f8cd4c8206bf4
SHA1 fffdc0f5b7ff58af04c82ac4c241ff9ccc2bfdbb
SHA256 f77a20bf57dedae73296894f23af6919df7753cf62d860872862a458907a2988
CRC32 9450E3B8
ssdeep 12:bkEN4asYo705/V1bfcjv4ftPa9r2i85tlUl7FRu5lFHo+IZY4:bk1asT705cD4fENFslHFHPIy4
Yara None matched
VirusTotal Search for analysis
Name f0a650458761b7ed_msg_41.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_41.txt.wncry
Size 488.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 7dfd5d194315e0924bee4f0cdd0ba363
SHA1 124d9d68556fb3f3d610cfa52f9e428b69bc761f
SHA256 f0a650458761b7ed3f188b71fa8e5eb00c3facbf9df4f2f36d5959c6dfe7cbd8
CRC32 A5E5E309
ssdeep 12:bkEPclQjtSnFvDU64v3bQG7c+T29aHzpbAbnanpUt:bkxQjt6U6mE1+6YH1bAbnapUt
Yara None matched
VirusTotal Search for analysis
Name b1e12cf4c4be999f_fo_fo.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\fo_fo.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 11c8a76731e601dec7bd8e7f142f8ede
SHA1 20e41aebb424d5f821d7eb92d02ca8d002b07e11
SHA256 b1e12cf4c4be999f499766a75d9a9fb5c70e33b9778630f6520f3280902d0dd0
CRC32 3FB8F828
ssdeep 12:bkEekDVDEemokItZiqn4kAN7scbj6dnXycAx+wgJ1NMkMe+5IgF:bkVGXmU4kApv36ZfA81NMkcIgF
Yara None matched
VirusTotal Search for analysis
Name 4778a7c5adb08593_exec1.png.wncry
Submit file
Filepath c:\python27\click\click\click_image\exec1.png.wncry
Size 792.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 36823c56bd2f733d19a4492969f45ae2
SHA1 a9d4c3ebe30ae0965eb36b4a282bee2edfd5a2aa
SHA256 4778a7c5adb085932937f61b30d53f612cd45d1d9ab72ed66b9ea9d4719c1cdc
CRC32 7848638F
ssdeep 24:bkPdf/5rn4a0x4OoEfrjgDs6a7AclodSVPS6p+girPmRPn:bkP774a0x4OvHgI6VgVvp+gBRP
Yara None matched
VirusTotal Search for analysis
Name 741821814cf05638_725.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\725.WNCRYT
Size 157.0B
Type PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
MD5 061127b9bfaa84ede23b0b611abfe699
SHA1 cb212cd0ccdb907db929b39dccde68ba7bfa68e7
SHA256 741821814cf056388cde40acd7f0ff0e9e605b020a0f35d07b8dc2b1759bbfa2
CRC32 17204ABF
ssdeep 3:yionv//thPl9vt3layxdlHtm9DLCwSaFcN2lZttU1ISsbMSktp:6v/lhPPLmFLCwSOpnU1ITISep
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 991fac8497f5603d_sl.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\sl.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 65c94b12b957f9e17d1b34445bf33f8d
SHA1 a1724263f22edf595e4a2c9eac51d403d9ada8ae
SHA256 991fac8497f5603dfdbd8ebf4d68abfec392eacb9ccf70325c29baea829781d2
CRC32 D566F766
ssdeep 24:bkiQviuy4KiHCNdSv3WMvQJi1HUwdPqg6gJA5Goun1T4Wr0zGoWhmnxAuRid/Pz7:bki6iuy4KGCoGMvQQnPX9JAc1T4Wr1hD
Yara None matched
VirusTotal Search for analysis
Name 5ee93a8c245722de_119.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\119.WNCRYT
Size 1.1KB
Type ASCII text
MD5 2266607ef358b632696c7164e61358b5
SHA1 a380863a8320dab1d5a2d60c22ed5f7db5c7baf7
SHA256 5ee93a8c245722deb64b68eff50c081f24da5de43d999c006a10c484e1d3b4ed
CRC32 A55D1449
ssdeep 24:4azu8eNsP2/xhsSpf2TBtHQT15j63WN7v9v3l:46it/vs22Te5OiL51
Yara None matched
VirusTotal Search for analysis
Name 43889c61a3830647_ssl_cert.pem.wncry
Submit file
Filepath c:\python27\lib\test\ssl_cert.pem.wncry
Size 1.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 0aa2c9445c3e299c05c59d5960cdc905
SHA1 e77a95cdfda161e08f12044042c93e2e98c37924
SHA256 43889c61a383064731ddf39a8c906b43dfa0aeda77998025918426f1f37ca3c6
CRC32 561C97BA
ssdeep 48:bk1CBVVOxt+v/3IjUOlhWJO+XRtHhoBPZyLM0Py2:o1CXVOxAAjUjrREBBMMYy2
Yara None matched
VirusTotal Search for analysis
Name 29a70eac43b1f3aa_623.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\623.WNCRYT
Size 259.0B
Type ASCII text
MD5 eeb42ba91cc7ef4f89a8c1831abe7b03
SHA1 74d12b4cbcdf63fdf00e589d8a604a5c52c393ef
SHA256 29a70eac43b1f3aa189d8ae4d92658e07783965bae417fb66ee5f69cfcb564f3
CRC32 FE18BE7F
ssdeep 6:SlSyEtJLlpuoo6dmoKNvf/NLoKU3v6xH5oKNo+3vfXM6PYv:4EnLzu8yvf/Nq3v6vF3vfc6q
Yara None matched
VirusTotal Search for analysis
Name 753cd98db2f4376c_en_ph.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_ph.msg.wncry
Size 616.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0d87d66bb26a5d94015c20c73ca222df
SHA1 0707567dcfa3f029fe70e8079a88f930a8016ee4
SHA256 753cd98db2f4376c9a31c98e8684214f15b4485286e252fa0c2a0cd45d5d4ea8
CRC32 D77842D3
ssdeep 12:bkE/vZDvLfdpi6RX5YKEOrqJERXE6k5loc45zu2ooMOtdqgBLWRBDrrc:bksDvfi6HYKEOm4E62loc45Cs5zFB6RO
Yara None matched
VirusTotal Search for analysis
Name dcefd9a6548d6868_47.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\47.WNCRYT
Size 5.3KB
Type MIME entity, ASCII text, with CRLF line terminators
MD5 49e9800d7c2d6f9847880325c1c0635f
SHA1 4822faeb3d94bf08e33b8542cd2d2a9d7f3bf8f3
SHA256 dcefd9a6548d6868ba885a7b38475a3d231f54d4a9a1aea9c4d3ee0def35fec2
CRC32 8228AF26
ssdeep 96:mFtNpFqR3WZ1OBQmC2LsdbdWqRdMGCa3UYSDytFKZ0R9:yPAygSmRLs/8zaxqytFS0R9
Yara None matched
VirusTotal Search for analysis
Name 1869644d02caf2e7_main.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\main.js.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 995f21e7703089b77c2972645b1ba9eb
SHA1 2addc69816d10ddf967e0a0e8008a88df84b4222
SHA256 1869644d02caf2e78614d61eafd9c29a4929d01eafdcc36355870316bb60f5a4
CRC32 D6C6F07E
ssdeep 6:bkEIpzrk8vOaImVRVUqd7GK4PBxaSEofb7WLOSpsVkYnpAA42xXfVvzb:bkE43k7e/dbEcmbB1OEAAZxfVrb
Yara None matched
VirusTotal Search for analysis
Name 131817cd9311c03d_731.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\731.WNCRYT
Size 252.0B
Type PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
MD5 0599dfd9107c7647f27e69331b0a7d75
SHA1 3198c0a5f34db67f91a0035dbc297354cbc95525
SHA256 131817cd9311c03df22d769dd2ad7fa2e6e9558863a89f7e5e1657424031a937
CRC32 2AFCD2CC
ssdeep 6:6v/lhPKM4nDsp7q1hKVlomsj9rxKNgtmN0VZ+GFYep:6v/7iMXVq1ylxemNgtmKVnYM
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name d081706c13111d28_49.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\49.WNCRYT
Size 5.2KB
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 6ef6c1ef5f9e15e271b5d74101fd6e15
SHA1 8a87188092477fe3565a18b151bd9bcacd03adbc
SHA256 d081706c13111d28c4a49d56c9a75a88196343b98b982b13e2878b6fcaf5f3c4
CRC32 AEDA213E
ssdeep 96:d2pJM/SIBUK0e2ZUCpgsZsJS5MBI5uBoGk0dCe:Y2SIenZK1S5MO+oG9
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
VirusTotal Search for analysis
Name 96a7352a3a51d1a1_usertile12.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 3112db426b23656c88a16cb67178da8e
SHA1 d91f012df2c62efac5cf69960e7e2e527a8eddee
SHA256 96a7352a3a51d1a15de013eccb3e13b87c4bc23a0275b7ca9e03fd0c7579e1ba
CRC32 974F392A
ssdeep 1536:uCDQJrJHSmbJA8JYJUvJMQJ1J+8JVBfvFJWo7dDJ6J+kd3xbzaJ2BJfdJsdl8J/H:LDQIoWuzMXZ/wvyXBNNzWSVrJJF8C
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 14ff564fab584571_89.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\89.WNCRYT
Size 1.1KB
Type ASCII text
MD5 9378a5ad135137759d46a7cc4e4270e0
SHA1 8d2d53da208bb670a335c752dfc4b4ff4509a799
SHA256 14ff564fab584571e954be20d61c2facb096fe2b3ef369cc5ecb7c25c2d92d5a
CRC32 7885F20A
ssdeep 24:4azu8WBVUUQ48wsF0nuLsCtJeUFqwv1v3:46BwoL5ScfR3
Yara None matched
VirusTotal Search for analysis
Name debaa8967a42ed24_euc_jisx0213.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\euc_jisx0213.txt.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6a4a4169da89db03f79c1fab4b97b54b
SHA1 3757ad4bf275551a511ce6d30bff45d59e8aa329
SHA256 debaa8967a42ed241e49833916ab06e9624cc6f577d5aab487f37abc5e1166a5
CRC32 3F8E28A3
ssdeep 24:bkUCp97x03S124qaGHtC9TvGfmycGTEwkwKTt+p/W/y5T/NoEL2:bkJf7i3SxqaGs9zrycGTEwjgtjy5T/0
Yara None matched
VirusTotal Search for analysis
Name 862eec831b4df355_pymem.h.wncry
Submit file
Filepath c:\python27\include\pymem.h.wncry
Size 5.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f5d7e2f9660227adcf6992f05d2b659b
SHA1 8dd42341ac9ac3dc685c0a383a226824935e9cf0
SHA256 862eec831b4df355f274f9b79d8daf426d48a86a8717b06133a0b7e664398802
CRC32 299965D8
ssdeep 96:oy55kuPkC33IWaAlwSqNSaHgNng+/vNlyNzzmF8orp9iL4T/OCuRofrGigWE3a6b:x3vbqNSaHmg+/fyNzzmF8orpd+mMB3aO
Yara None matched
VirusTotal Search for analysis
Name d23ee3d6f146867a_305.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\305.WNCRYT
Size 1.9KB
Type ASCII text, with CRLF line terminators
MD5 e558dac2834f977dd2035817c5a13c08
SHA1 98bafa56e0cde6c739a6d4cd1baadf59b564c062
SHA256 d23ee3d6f146867a005c2b27992b3de787ca140663c84f1813ff748c282d35ae
CRC32 84ED2466
ssdeep 48:rlPnqGc+uUrqN+gAIRqZM0KDHZp96TqxVe0:rlPnny+1IRqZM0KDdz+0
Yara None matched
VirusTotal Search for analysis
Name 54209021bf97c525_empty.vbs.wncry
Submit file
Filepath c:\python27\lib\test\empty.vbs.wncry
Size 360.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 388dabf0d115cd063ac62b93b0e191b0
SHA1 fef1564889a963127219652628cbb31b862e6e51
SHA256 54209021bf97c5257ce1a5031fa295027a548e4cf7d47374bf766a6eae8aa1fb
CRC32 6DF896E6
ssdeep 6:bkEL5iAFwbvjGubiTVl2/WFi3LTRG6qeHGEhaDDE/abjl7OP6XBG/n:bkE9iBzjGuGxl2/hGHemPDEibjl7I/
Yara None matched
VirusTotal Search for analysis
Name 1e4dad93790ca853_xdytjzxladdcwzshc.txt.wncry
Submit file
Filepath c:\users\test22\documents\xdytjzxladdcwzshc.txt.wncry
Size 572.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2b0fed34c883c651492e48ccedc042ca
SHA1 e567138c96234d16d460e4449371e1a77182a535
SHA256 1e4dad93790ca853672647b09f62a227583bf00b8435038a9ac7994496983c83
CRC32 7125E7B9
ssdeep 12288:SRcb2twAQ6+HnaRyXNFy5mRiplzb3IJwYDHPIk2D5c3:ucKW6+HaoXyYezDIFHPp2W
Yara None matched
VirusTotal Search for analysis
Name 894629bbbd568263_cave_drawings.gif.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\cave_drawings.gif.wncry
Size 4.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 148001cb2673ca374cf16d67fd7e0977
SHA1 37f3a03eb5700cf87b09d9e0ebe3f9f7997b9548
SHA256 894629bbbd56826314963507a22be7181b28210b67322668d17591971db08cae
CRC32 631FB6E0
ssdeep 96:oCEKHJp1XxZCWhwLJlacMIUlA2ZQ+jqrUVaCQDTqUcAb:QKH1rCLDPMIUlA27jqIQJTvcy
Yara None matched
VirusTotal Search for analysis
Name 963d5f8d5d1259e9_292.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\292.WNCRYT
Size 1.4KB
Type GIF image data, version 89a, 32 x 32
MD5 31490bfdc9e6b5e32d83297670221c02
SHA1 d52b7e1a0c3140d5879ed4c288da06236ae605ea
SHA256 963d5f8d5d1259e9874a263a6621ca6dd1d57608faa5f28f7d61f349583e0781
CRC32 FCD2D0BF
ssdeep 24:3+mUG/W/tE7/nKyHSSVyLMnOoyfHII71wR0aIL/zFl0uGoONkLgK25ax9fD4:3+r9lsPKjLmOjogwRDWET2BsSD4
Yara None matched
VirusTotal Search for analysis
Name 96f8e39f9f51a81d_ta.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ta.msg.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7608a62bff899a526f5e745479bccf8d
SHA1 4237b37835e89f4812c0f1f15c634177c275a4db
SHA256 96f8e39f9f51a81d1e4d4f4dee0f9df03b83b1df89f311da735dd25fcc37e873
CRC32 19D7274F
ssdeep 48:bkEil8M4+K24viHjnVW9cuNn9LM9vg2jxWgut1iV:oBlG+KDvUn0cuNy9vFjZuHK
Yara None matched
VirusTotal Search for analysis
Name 3365e1478905a215_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\128.png.wncry
Size 6.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c6fecd31f3085fb242e626acd3ac9fa8
SHA1 d977b552027e36ee909b8a1b20395b45380e317e
SHA256 3365e1478905a215c65da64724516a81d356de9ecd27001f3002a7af0753ab57
CRC32 C54DACBD
ssdeep 192:r6Cv7Tdk8zBknTrIxOZUPIbvQuAPWfAWdf/o3yHM:BHdnMI2bIv+PRBM
Yara None matched
VirusTotal Search for analysis
Name be0d2dce08e6cd78_100.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\100.WNCRYT
Size 1.1KB
Type ASCII text
MD5 34fe8e2d987fe534bd88291046f6820b
SHA1 b173700c176336bd1b123c2a055a685f73b60c07
SHA256 be0d2dce08e6cd786bc3b07a1fb1adc5b2cf12053c99eacddaacddb8802dfb9c
CRC32 A9B16FE9
ssdeep 24:4azu8ZeTWSS/DatuUSlWCBTtotL8W183eYKvt3v3eG:46sWp/DatBSPtoNmpMt/J
Yara None matched
VirusTotal Search for analysis
Name 26fd072fda6e12f8_m_english.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_english.wnry
Size 36.1KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 fe68c2dc0d2419b38f44d83f2fcf232e
SHA1 6c6e49949957215aa2f3dfb72207d249adf36283
SHA256 26fd072fda6e12f8c2d3292086ef0390785efa2c556e2a88bd4673102af703e5
CRC32 F222D014
ssdeep 384:S93BHSj2cguALeT+sPzy3EFHjHdM2EG2YLC7O3eo75Y3kmA31dv61QyW:S93BHSTjHd0G2YLCZrS14y
Yara None matched
VirusTotal Search for analysis
Name d6ae63b614678898_346.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\346.WNCRYT
Size 1.0MB
Type data
MD5 62aae803de65b704a8cc7f63cafaa373
SHA1 2534eb54c28083a592fbbae927f16b4cbd3aa044
SHA256 d6ae63b6146788982bb259f237c2c9defc6973ee621ef5370ee2e3ba75d5041b
CRC32 0BDB4E55
ssdeep 3072:Gt+FOZJf3/lWt+FOZJf3/lKABwEFUXvSWAErAl3ZnSABwEFUXrSWAErAl3ZnTSWN:CcsYUkCL6
Yara None matched
VirusTotal Search for analysis
Name bc935baba49fc435_gqkwzlhqea.docm.wncry
Submit file
Filepath c:\users\test22\documents\gqkwzlhqea.docm.wncry
Size 82.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c86703ace4215fc3fa1e52b80f3cdefd
SHA1 8d6404b98fd8f3845c61c12b60cd4e7642ac1037
SHA256 bc935baba49fc4357884020970c3d31f20629c39be3889e03daf505e6a7ac5fc
CRC32 0CD8D00D
ssdeep 1536:VWZdjiiQC3JytccOGcJ0D39WMVq0khTlhIsCLLBeLxtCIZTt88eOE+GZq6S6yW3Y:VWZViiF3EnOOWkq9HleLBK0Qt5EFZq7P
Yara None matched
VirusTotal Search for analysis
Name 9aeccf88253d4557_libgcc_s_sjlj-1.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\TaskData\Tor\libgcc_s_sjlj-1.dll
Size 511.0KB
Processes 152 (@WanaDecryptor@.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 73d4823075762ee2837950726baa2af9
SHA1 ebce3532ed94ad1df43696632ab8cf8da8b9e221
SHA256 9aeccf88253d4557a90793e22414868053caaab325842c0d7acb0365e88cd53b
CRC32 7284F22E
ssdeep 6144:+ymz8Jq1p95avGpuO+/jUE8ADu2kNBMY8KHNygoB0+6tMqSsVwvN:+ylSZ+/jU7ynIK5Bb6Y
Yara
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 44ec60df05bb1df4_euc_kr-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\euc_kr-utf8.txt.wncry
Size 888.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 343dc7bdfcdc56ce51472a9553e0ea8d
SHA1 29cf327f94606872a34b4ede80e1bf10d513ea73
SHA256 44ec60df05bb1df4404ef620442d84b52b7ee76219e6746b6f71e8176ba5615d
CRC32 DEA70F6F
ssdeep 12:bkE1Rfpiz/FpTl+OInLvS/o7XN7DIjiI7xBef/TXdKcINjXOiqFuBDclsuyDagvs:bkepiz/RsLEojNc9WzXdgaDFuBDOsuzn
Yara None matched
VirusTotal Search for analysis
Name 9bd38110e6523547_m_french.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_french.wnry
Size 37.5KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 4e57113a6bf6b88fdd32782a4a381274
SHA1 0fccbc91f0f94453d91670c6794f71348711061d
SHA256 9bd38110e6523547aed50617ddc77d0920d408faeed2b7a21ab163fda22177bc
CRC32 1B15B12D
ssdeep 384:SheftipUENLFsPzy3EFHjHdtW2IG2sjqMeo75Y3kmA31dv61Qyg:Shef3jHd0G2smJZrS14M
Yara None matched
VirusTotal Search for analysis
Name dabb967021257c92_node.h.wncry
Submit file
Filepath c:\python27\include\node.h.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 930293efd6eca6f47445e99ffe8b5665
SHA1 428fb0034f60cfee08088d153419c42ed2b6450f
SHA256 dabb967021257c9200200a7bb866809ccd880929e19f22a0a1aba268c98b890f
CRC32 2805C691
ssdeep 24:bkJNuUa5y6bWfmzVeyp1Qd3VnTMGOsu7RQcYzS0BQq2tDOeOtg07dST0O:bkJcUa5jbmmFp1A1TMGOZSzSUZIDO57I
Yara None matched
VirusTotal Search for analysis
Name 2a09f449e3acb90f_webcolors.txt.wncry
Submit file
Filepath c:\python27\tools\pynche\webcolors.txt.wncry
Size 3.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 92f5ad998ad3801adf835b6af5713713
SHA1 939388249321fa22a15e9d131d5eb96f83608f19
SHA256 2a09f449e3acb90fa61bfdf6ffbcbc38223357db981247adae89310b061bae0f
CRC32 EC2C175A
ssdeep 96:oEgWwp/I3KdAoA8vqzVHW9ZOewm+OsIhL7JTzHf8:CWwi3KaoA8yK/wm+5IJVHU
Yara None matched
VirusTotal Search for analysis
Name 4d75f5710ce6f7d2_424.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\424.WNCRYT
Size 2.1KB
Type ASCII text, with very long lines
MD5 8ade3a84846ad501632e9c454c787603
SHA1 219694f5338f21a633c931d307fe944fe54fa185
SHA256 4d75f5710ce6f7d20151a550cc6850e1aa7a822a3e8d8df5934f31ee23df6d6b
CRC32 EDC232F4
ssdeep 48:z839mQxXeVz3U7en+ennjVtQgQKNwTyjRLGztLhGrImOuY1SFrzQPbh:z8wzme+ejTDjNwTcALOFONQzQ9
Yara None matched
VirusTotal Search for analysis
Name 88af7ae24fd08d5e_329.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\329.WNCRYT
Size 50.5KB
Type GIF image data, version 87a, 320 x 200
MD5 34d2114d2ac22dd7f97232d241402028
SHA1 d2510c1db0f35051e8df7eac0e0c522da535175e
SHA256 88af7ae24fd08d5eb144e938a4381d28638bc50d15c8e5f3e30ca73b0fba961f
CRC32 51D0302E
ssdeep 768:vd6Oy1DMq/KpYFcH7XycireZMjfnPxm0Yo9p+zUxSsKYjNl9GrFyXoEDP1w:vd6R1DMQKouCcHZwPWE/xSMjNlCQ+
Yara None matched
VirusTotal Search for analysis
Name db223d088b0b41ea_321.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\321.WNCRYT
Size 10.8KB
Type GIF image data, version 87a, 252 x 213
MD5 9586106e578a263cf24f4878b2f98851
SHA1 d1773a2fbcccadfd6b79f521759416eb691c8b66
SHA256 db223d088b0b41ea77614ec7fbfcde1132f68b2e1c3e40c7c1871a541df625ac
CRC32 7470A6D9
ssdeep 192:6m5ZbG3Vb2GGmLxoREKwfPy1UlpReQ906KgYRDx+oetsuLf7v3kL29sZLPm7s+H:P8amLxoOKwfa1mX99YRDx+ztTfbL9sZK
Yara None matched
VirusTotal Search for analysis
Name 7539d72b173117ec_564.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\564.WNCRYT
Size 281.0B
Type ASCII text, with CRLF line terminators
MD5 411e4408a6493fd9734356eafe9b6355
SHA1 e785ae5a24acbb980b62afe426d10e4e50f58c10
SHA256 7539d72b173117eceed74101e47af530a0e70667bd8921fcb1a79a54edbe8b05
CRC32 5DB5A33E
ssdeep 6:zarc2dc45uc45Sorc4DXc4DaRjlw38RmyzZurRT:+rcec4Ec48orc4DXc4DUw3GurR
Yara None matched
VirusTotal Search for analysis
Name 365be278a502ef57_42.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\42.WNCRYT
Size 509.0KB
Type UTF-8 Unicode text, with CRLF line terminators
MD5 8b7c2200529cf74f077ff06f894e6ede
SHA1 09af15365611fbb2ea99bc3fd308eb5e1b3deb0c
SHA256 365be278a502ef57b135402622f57ae5813c29cb3a0953796898915dff3c1e15
CRC32 D0EE556C
ssdeep 6144:UE6UmB0E+mqOL6Ti6NshwzmjutKbdWK1Rn+WzXngiIARZodLDvRMsUIKPorAjKKk:UzjBt+ngFTdZyWzXfb0DqsUnAl/p
Yara None matched
VirusTotal Search for analysis
Name 340f281a54b415eb_232.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\232.WNCRYT
Size 4.4KB
Type C source, ASCII text, with CRLF line terminators
MD5 a736f759d638f1364404ca6d69313bb0
SHA1 cb7bf107cbabbcc028b90a90fae15b54fa14a0b8
SHA256 340f281a54b415ebdbe39e14e63e2e5f907d99f249d7218ce36d1ae31149dacb
CRC32 BCAA292D
ssdeep 96:ox6IiwSGO+hrq3f/V5WqjbVk/Vqysrj7rqjqs13r9paX07alcX:6irTGI7GjqA9cCaK
Yara None matched
VirusTotal Search for analysis
Name 5186de5a262bdfef_en_sg.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_sg.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 450f0a1ec7242268a769ea84e2cf2657
SHA1 268f0021b00f3e006722f393e0567714b12b2b37
SHA256 5186de5a262bdfef9bf6a953bfc36616504d73eb85d9d19481cd9419d75822a2
CRC32 43739664
ssdeep 12:bkEWJ4NOXny/5LhtdsU7jZzzCqweQS5F9CvwJeleBADFhi:bkzJ4NGyRNtSmvCHF+9Cwoe6G
Yara None matched
VirusTotal Search for analysis
Name 721b7aaa9a42a54a_732.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\732.WNCRYT
Size 160.0B
Type PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
MD5 7cb6b9dc1a30f63b8bd976924b75ad96
SHA1 0c40b0c496d2f2b5f2021c117ec8610ac03ab469
SHA256 721b7aaa9a42a54a349881615a12e3a26983aca48e173fd2f66e66aa0d725735
CRC32 BDF81D3F
ssdeep 3:yionv//thPl3xWrA4RthwkBDsTBZtnAkx/9lVtEHxrPLyN+ltNPhv/l2up:6v/lhPKM4nDspnAkZHVtERrPLygltNPn
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 7145b57ac5c074bc_661.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\661.WNCRYT
Size 279.0B
Type ASCII text
MD5 a76d09a4fa15a2c985ca6bdd22989d6a
SHA1 e6105ebcdc547fe2e2fe9eddc9c573bbdad85ad0
SHA256 7145b57ac5c074bca968580b337c04a71bbd6efb93afaf291c1361fd700dc791
CRC32 92940422
ssdeep 6:SlSyEtJLlpuoo6dmoZA4HFLoZd3vG5oZd3v6X5oZd+3vnFDoAov:4EnLzu8kyFO3vf3v6f3v9dy
Yara None matched
VirusTotal Search for analysis
Name c7e69d77b4ffdd22_thumbcache_256.db.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\current\appdata\local\microsoft\windows\explorer\thumbcache_256.db.wncry
Size 1.0MB
Processes 2632 (WannaCry.exe)
Type data
MD5 aa8de1f02654e64fdcf9a5ee9f77408b
SHA1 360864a8659cb61c4295efda115fba4623dad407
SHA256 c7e69d77b4ffdd2256822eb5cd930e8e9cf8e3aaa762b9bba4a0bac642caf16d
CRC32 25493EB9
ssdeep 24576:cJrtt3z0pK+R4RkzfIB+4K9tlPNEPjm473TIjyzIvj:yrr3eK+ORkjIc/ZoPDT+wIr
Yara None matched
VirusTotal Search for analysis
Name 94a431168af0bb3e_190.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\190.WNCRYT
Size 4.6KB
Type JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1], baseline, precision 8, 500x300, frames 3
MD5 2e8192a8026a9ecd3f67241ca7a074ba
SHA1 48f93eeac35d6c7022d0cfe9eef85fa7f1bfe9f1
SHA256 94a431168af0bb3efe1d7ee14d0b01f15b9a82e3f7c075e68ca892b3c8d7f60b
CRC32 8B5CD4AA
ssdeep 96:1LhSEj4645HFl9FKoXf23AYYPAqGzg1DaXN55+:1dS7FDFK6fsAYYPnGzg1Dx
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 1ae0de121cdc82d4_21.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\21.WNCRYT
Size 341.2KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 be13c51eeaf2f633d3c7125e6245e47a
SHA1 76805647224814bd9bb5772f910ddf58f5d41fed
SHA256 1ae0de121cdc82d402a4049e6fa393be9a88bba6ec4daf1963c2bccbffdbe2bc
CRC32 1CC9A5A7
ssdeep 6144:oRKxgxdHwjE/RRsLvLH1NGuG7e4A4bSNHBrKUev46ZTEJeRKxgxdHwjE/RRsLvY:ELxtwCnqLPNG7esbmVKUi4mEJWLxtwCb
Yara None matched
VirusTotal Search for analysis
Name ba8d77d6c9c62e4e_514.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\514.WNCRYT
Size 664.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 8410d70cec8f5427f52c6def827ea386
SHA1 a3d4f860c499f1ecee0a10c386ec19c4a03f9aab
SHA256 ba8d77d6c9c62e4e238ae03dc702a25e0f170d677f23861c751cb5982d0c9db5
CRC32 9207896C
ssdeep 12:k116arny0x4JKmVNbXmMQZ9mLXgVB0d+Aey2jfg/Z+ykiihVy5tYQew:S4arnLx4JRbXmZm8jAeY+yMo1
Yara None matched
VirusTotal Search for analysis
Name 80134f6d607ea57b_usertile19.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 df26b0a9cf69230bb9a9c49dc30831c3
SHA1 ebbcaa79fd8797996a4704849c6f41702b993daf
SHA256 80134f6d607ea57b73d967361ae39ce71b3339b830cd5382c0b86affdf1df92f
CRC32 82DBC425
ssdeep 768:siyHRw5fiaqnR/AW6PWmYg38nKuP/EFPHb3N3tTdi/w+Jfd48eVrEWrDcC:jqnuFTgK6EhHbFtAZ1djeVrEo
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 1b00229df5a979a0_673.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\673.WNCRYT
Size 978.0B
Type ASCII text
MD5 ae55e001bbe3272ce13369c836139ef3
SHA1 d912a0aeba08bc97d80e9b7a55ce146956c90bcc
SHA256 1b00229df5a979a040339bbc72d448f39968fee5cc24f07241c9f6129a9b53dd
CRC32 07AAE420
ssdeep 24:4azu83jGeo9sbjCjS3jCwjLj+zSsS9CfzTA2Qcl:46OOsJzTvl
Yara None matched
VirusTotal Search for analysis
Name c35da53f1c5bf763_525.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\525.WNCRYT
Size 345.0B
Type news or mail, ASCII text, with CRLF line terminators
MD5 c045ee85a52d1967d69de8a9614085bd
SHA1 da33f4f914ef2abb8871a2edca2814df2c40043d
SHA256 c35da53f1c5bf7639417aecde7052db57700828fcff4600a81751ae13bac03a8
CRC32 B3EE5FDD
ssdeep 6:AXmMQ6b8FptDQ8KMW0YDgaXHfyrtxVq7wDQ8KMW0YDgaXHfyrtxVGVj:AXmMQfbDQyoyJxmwDQyoyJxEj
Yara None matched
VirusTotal Search for analysis
Name 7a465776d6e861c1_456.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\456.WNCRYT
Size 39.5KB
Type Microsoft Word 2007+
MD5 0b58f46136fff9626a1a0d11fbd60fee
SHA1 e6d52fe805ddbcdb39d766a4f3d2409a09053049
SHA256 7a465776d6e861c1a39f164ec5abe662111b8b1d4b9dc3f63148647a4a236adf
CRC32 07ACFE2D
ssdeep 768:Ub8m8CY8lzxH8BzSuoOhF1+ANWBdFdU3Q0Q8FUVlyQXcHv38tvx23OtEc:OHLYezxH8BzSuoOhF1+Aw92F0XS3MJ2A
Yara
  • zip_file_format - ZIP file format
  • docx - Word 2007 file format detection
VirusTotal Search for analysis
Name 6cbd0c10992058cf_python.jpg.wncry
Submit file
Filepath c:\python27\lib\test\imghdrdata\python.jpg.wncry
Size 824.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 eae85a9c164bef92d2c75a95d437c86a
SHA1 049f182ca9c5f02f3775f62196b997adf3aac562
SHA256 6cbd0c10992058cfafbf1f4388d2c13e5088a08fa88a6805a95e6e4cfcd2da57
CRC32 87FA0C6E
ssdeep 12:bkEWABCOGQ1HxBXrUIFQJMKSABIc1zjvrmUo74UeyJjDu+SkvZSEIhssZ2E/B:bksIOGQxprRWJMw1PrmUaeQHZKj3B
Yara None matched
VirusTotal Search for analysis
Name da04675d46d1d200_es_ec.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_ec.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 ccc32711617da8f786dc03d8ffaf8f1b
SHA1 571ed5eaa90fe117cc84442b9336a8d2edfcb6a5
SHA256 da04675d46d1d200785196968db286ee2d22589335fff0e79ac086b2508311f0
CRC32 F9F49407
ssdeep 12:bkEbKq4XkaSvUUEyBvwWRRlCo5X+V2rmxVXqf8KMACp:bk9P+JBIqWkuTi9cp
Yara None matched
VirusTotal Search for analysis
Name 74ce059594746d50_322.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\322.WNCRYT
Size 1.0KB
Type ASCII text
MD5 8a6cf2fa3f07d2b9b2175b6859ad6678
SHA1 7a4b85f9404d9a7676046e16e027cdd18fa87c2e
SHA256 74ce059594746d50a7ff0104927ef00ebb31bcd2dc79c0c3a51f9e11f33c8ba4
CRC32 9FF3678C
ssdeep 24:i95NEcZ7iEzlG9e/WGJ/AXfZXspXUZXFdgdsHUkcerdyGvxB:CNEG7iEzlG9kWGtAR8p+1+mHUveRyGvz
Yara None matched
VirusTotal Search for analysis
Name 4d439244300c46d9_msg_01.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_01.txt.wncry
Size 760.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 31a32b76ef36587aa6fbde65c9fbffa2
SHA1 2e97eab191b29cf25206a0581b52f2c1363aeda8
SHA256 4d439244300c46d965fd733d2a2c386695f99bab179f6a37b2ee2184be9a5684
CRC32 E42F9614
ssdeep 12:bkEuLWxbbFILmf+cCIGFJw4bpSws3Tblldp1zbATOZS15QSKgMGlwSc5lP9fl4e1:bknWxbbGqf+cCIGFtAwoTblHp1YiZ86B
Yara None matched
VirusTotal Search for analysis
Name 8be73f55512d690b_496.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\496.WNCRYT
Size 486.0B
Type C source, ASCII text, with CRLF line terminators
MD5 80b6448ec1c546acf1ee2fed7b3bc25c
SHA1 29e23c40d94ac96cdb6a7e1715d8d06af3c9f4a7
SHA256 8be73f55512d690b897a02594e2b8335611bd3aac97c6fe8f6cb24ad06b13b99
CRC32 EF88A082
ssdeep 12:BboAEURhrTlQ0K+f2Vx7yADv9Ne/9wADveWBov:BdEUf+39L7PvLMrve3v
Yara None matched
VirusTotal Search for analysis
Name 4704905fabf67a04_248.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\248.WNCRYT
Size 2.9KB
Type C source, ASCII text, with CRLF line terminators
MD5 6c1d525854415c157b65eba73912f59a
SHA1 cdfb747778cb4ba2010b002b49e75a3d2a374819
SHA256 4704905fabf67a04887db19fa42e6fd10f74f9b797b43da8c88e61ace2bc816a
CRC32 F0C54C3D
ssdeep 48:bk0z/VzRebToNka80YzehXk9ifKQok5mn8mNdMpWX9V9qER3Vn3yqvVt8nBY25S:A0zdBlJYqhUeCNV0Gln3HefS
Yara None matched
VirusTotal Search for analysis
Name 2b4fd35cb79b092d_sources.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyscreeze-0.1.26-py2.7.egg-info\sources.txt.wncry
Size 712.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 bc8cb71ba97b03699d3f08745d35722e
SHA1 cd702aad3ad704c0acbd5b7e40e0b677671cfd09
SHA256 2b4fd35cb79b092d8dbfe795bc92da5d1344ab2ec3a117312d2b76d8bac613e0
CRC32 EAB64084
ssdeep 12:bkEjoFnYLrLctpCbgiFwdqA983C5v/4BLd7fXYfa4iVj55QqwOWqPXTFxcFBXu8T:bkoo+YObgimU3C5v/CBDXYfadTQLORfK
Yara None matched
VirusTotal Search for analysis
Name a03cd88501df3182_thumbcache_96.db.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\current\appdata\local\microsoft\windows\explorer\thumbcache_96.db.wncry
Size 1.0MB
Processes 2632 (WannaCry.exe)
Type data
MD5 fee0c16e048f90d0873d05abe8cd53b6
SHA1 b14d8bf9f70e6c118bf572ae49e24063e4cd765d
SHA256 a03cd88501df3182d609934fc6989184c1522676e709666899ced5b82317f555
CRC32 41BFEF96
ssdeep 24576:C0LcuR08WaAFz+fli1LwIe3yH9FDAhgLOamv5:/c1t+NIe3SzDAhgLOaM5
Yara None matched
VirusTotal Search for analysis
Name 72f6b34d3c8f424f_331.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\331.WNCRYT
Size 2.3KB
Type GIF image data, version 89a, 68 x 100
MD5 ff04b357b7ab0a8b573c10c6da945d6a
SHA1 bcb73d8af2628463a1b955581999c77f09f805b8
SHA256 72f6b34d3c8f424ff0a290a793fcfbf34fd5630a916cd02e0a5dda0144b5957f
CRC32 4380D243
ssdeep 48:qF/mIXn3l7+ejbL/4nZEsKPKer1OPQqVRqJbPpRRKOv/UVO47f:81nHL4T0KorxvRKkc847f
Yara None matched
VirusTotal Search for analysis
Name 97ebce49b14c46be_t.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\t.wnry
Size 64.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5dcaac857e695a65f5c3ef1441a73a8f
SHA1 7b10aaeee05e7a1efb43d9f837e9356ad55c07dd
SHA256 97ebce49b14c46bebc9ec2448d00e1e397123b256e2be9eba5140688e7bc0ae6
CRC32 065191BF
ssdeep 1536:am+vLII5ygV8/tuH+P9zxqDKvARpmKiRMkTERU:a9LAg4tXPTEKvADmFgRU
Yara None matched
VirusTotal Search for analysis
Name 689c45d7ec7e9719_msg_30.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_30.txt.wncry
Size 632.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 ab6801e137c88da03aa6d6a71314b9db
SHA1 b054a5bb1f3cb97546232e05b943907979291427
SHA256 689c45d7ec7e9719e35e5db392dd8a4f96f68d10bffee127fbbf7a37a494dea5
CRC32 9EC6C599
ssdeep 12:bkEBrCsMHdvKxWxcKGPL2V316ruw0yj2gw8ON3tre2YqRcuV0e1SvQxx+1w:bks/99AAvFwjdT8a0eEvQ21w
Yara None matched
VirusTotal Search for analysis
Name 329e38f5346a97bc_708.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\708.WNCRYT
Size 262.0B
Type ASCII text, with CRLF line terminators
MD5 c59992321103f651ef36ae69da8c935d
SHA1 735011e784da361a6f76ca996c768ad873f2c295
SHA256 329e38f5346a97bc26fb5dae94b8031c06880cdc86864033ea37a6ad8075ca0d
CRC32 73DFCFE1
ssdeep 6:S3GdaXVXIC06/ZLVlscjQ/iqzSZHkVXVCbXVsGdWVCvr0wtD0v:P0FXIFcLVvMZzuEVFMXVsGEVBaW
Yara None matched
VirusTotal Search for analysis
Name 3d9ddbb0ebef1889_topbar_floating_button_close.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\topbar_floating_button_close.png.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b89c3ae6185dd1cc2c6121db9efcfab8
SHA1 7ea76248f24343875a09f2c54b2a1a84b46a7a08
SHA256 3d9ddbb0ebef18892fcda9054ec9e601b892ba1f59e9f451253fae76992dc3fa
CRC32 7D81C271
ssdeep 12:bkEDwWSDw7QfUbTz2GY83DfXvGWaPiOK42/JU2:bkw7MtwTz2wXvGWYiOjqU2
Yara None matched
VirusTotal Search for analysis
Name afdf4a2985848bec_574.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\574.WNCRYT
Size 107.0B
Type ASCII text, with CRLF line terminators
MD5 0cd97b7e94928658ea8402b2d62abdbd
SHA1 62a0a25d165c948e912797a9eac8f59e7efb651a
SHA256 afdf4a2985848bec542587b7a51c328a101d502133feb1ddb51975afb03b3926
CRC32 2214BB5C
ssdeep 3:xwdzrctaRjv2qw3XsRmBwAqLOIOJjF7A:ClrcYRjlw38RmyzZR
Yara None matched
VirusTotal Search for analysis
Name 855e8faf702744c3_pl.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\pl.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5e72ef8cd40bd42277807a1ff2a51dc2
SHA1 5a597215b6835e8a0a450f2dac8334f22174472a
SHA256 855e8faf702744c3f5e94dcbfc2075a17dee0f4dcde86c6bf8e63d278abf09af
CRC32 991067BD
ssdeep 24:bkFK039TxWU0Nb4IPz6+ix6WSlSN0CyXf23Hq1IY73cbB5di+eqQIrjM4:bkf9TEUGsv6tD1nsjdDeCrQ4
Yara None matched
VirusTotal Search for analysis
Name 2c7f163ad831cd6f_kl.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\kl.msg.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 070b225909046a07e1857f69ad0935e4
SHA1 1afea1eb638803d9f2aa71dd6c71660337242e7e
SHA256 2c7f163ad831cd6f62f604e44ac114def9ea8562e151e1773cceae2f9fa0a3d9
CRC32 B0E53D16
ssdeep 24:bk2QqIGTvbsJYaixpsXztq5NzKoSbF3lmtQS80eYrN0p7fLU3MpbHpwrmHs/Xhjh:bk28Gk7jXczubF3wMjGNO7NHpwyHGb
Yara None matched
VirusTotal Search for analysis
Name 6e5c4cc6c3a6ec0f_idle.bat.wncry
Submit file
Filepath c:\python27\lib\idlelib\idle.bat.wncry
Size 472.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 f4964b7721dc8feb0ee851de581a5f96
SHA1 2f65d34b856655e1f324c888d5d7e20421b35254
SHA256 6e5c4cc6c3a6ec0fa3155d10c481de9c954718f5b2d3d34b33b023323dee1e07
CRC32 41EACFB2
ssdeep 12:bkEIYcjAFxwueBiPD6bjy4wmESEtiM9YYPdZaRRbjpK3O8bxM:bkRAbkieXBw1gYva3fYbxM
Yara None matched
VirusTotal Search for analysis
Name c015a449c6dacacf_genobject.h.wncry
Submit file
Filepath c:\python27\include\genobject.h.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 06697125be7a44136fa84b7d89e9255d
SHA1 cc25b49f4ab87b6170d178f0d6ba78c0b33ffcca
SHA256 c015a449c6dacacf4cb9e600365bda0d54ed17e4fe70ce57cdea3364a04a7a08
CRC32 EFFC8420
ssdeep 24:bkoRwnwN0WyPTkc+/zvrxfpNVLqlwzeRq2MuSomMoEf1V6LpxOq6SXxh6X:bk1wN0fPDszvrxfpqlwyR8oZtnOu4hU
Yara None matched
VirusTotal Search for analysis
Name 8c6545a8fd0c9a8d_readme.txt.wncry
Submit file
Filepath c:\python27\tools\scripts\readme.txt.wncry
Size 4.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b5445800941738127691402dc0f090b4
SHA1 d3483b7f65a8a3ad44522a6d6f4779a3a000e95c
SHA256 8c6545a8fd0c9a8d0b8cd2ab8427b390f295f0f9677fbaceed607de4df5af0ec
CRC32 562798E9
ssdeep 96:o5YthEtRNDLXRcmgX3J2vWUrXrE2czvbdDTB:jhEtRN59gXuWUzbqvbdDTB
Yara None matched
VirusTotal Search for analysis
Name fb93d455a9d9cf3f_707.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\707.WNCRYT
Size 63.0B
Type ASCII text
MD5 ec6a7e69ab0b8b767367db54cc0499a8
SHA1 6c2d6b622429ab8c17e07c2e0f546469823abe57
SHA256 fb93d455a9d9cf3f822c968dfb273ed931e433f2494d71d6b5f8d83dde7eacc2
CRC32 CC1DABE8
ssdeep 3:fEGp6fR1FAGoW8vMKEQXK:sooLoQO6
Yara None matched
VirusTotal Search for analysis
Name 6c39616a04ef5736_280.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\280.WNCRYT
Size 1.2KB
Type C source, ASCII text, with CRLF line terminators
MD5 487b8cae212f2f3b71ef693cdca79575
SHA1 baa7029165f907ff9f088e7e6d845af9683730fc
SHA256 6c39616a04ef57369645345c13c6391ef2bb4af78a0a6d0758e758f8c463730d
CRC32 CCC15E29
ssdeep 24:Erq/C/BMPyO59gnPWNoYJPC3yo+mNCNCQ6L6o9OrD6DZyVgMov:rycgPWNHdo+moIbuo8rWlyfov
Yara None matched
VirusTotal Search for analysis
Name 30a142a48e57f194_130.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\130.WNCRYT
Size 1.8KB
Type ASCII text
MD5 2d9c969318d1740049d28ebbd4f62c1d
SHA1 121665081afc33ddbcf679d7479bf0bc47fef716
SHA256 30a142a48e57f194ecc3aa9243930f3e6e1b4e8b331a8cdd2705ec9c280dccbb
CRC32 19D21F45
ssdeep 24:4azu83w0xn8dnzhmmlmYgtg+CKf6CO5ztFSLt8tCtGtv+CKf6CO5ztFSLt8tCtNu:46k0dgmmlmYgtE/t1H
Yara None matched
VirusTotal Search for analysis
Name 0d7f439147910249_fr.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\fr.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 05de3c039cf1de27100604440999368e
SHA1 0d8e73a0f371f6caed995f372124e4d180800f52
SHA256 0d7f439147910249dbfe9738909d1ff4370470acade698583e066dc858c75a7c
CRC32 6B7FFB45
ssdeep 24:bkt1XjPzRyx7S2EvYBEvMYNzgc4RtiP8TDA8Qib8VwCAMjNrbJKQUJCeeUs7w8rs:bkt1XEOYKP8TDA8QKdmNrbABowuXaVuS
Yara None matched
VirusTotal Search for analysis
Name f47bd5823032233e_185.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\185.WNCRYT
Size 3.9KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, comment: "File written by Adobe Photoshop\250 4.0", baseline, precision 8, 120x120, frames 3
MD5 13ee239821fbd6583551a20acda0afa8
SHA1 387875d8145f930004b927af59a554b651e74961
SHA256 f47bd5823032233efe5741cf34a4ad8abf4a7a756f62fcfc8e5e1b35cf3dad87
CRC32 99582A86
ssdeep 96:+GWw75/MT9AkvQKbzfONzV77PKliz7Pr41Y8iF83:aKu9TvLzf3Az7w6F83
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 5ba6e52c8cfe26cf_40.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\40.WNCRYT
Size 144.4KB
Type UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5 14e83a1503793c91d34472ccccef3f13
SHA1 4ee3367bcce1528d678a2a1e02667d26677d03e7
SHA256 5ba6e52c8cfe26cfc75d8f8923ba2cda593a9bd1bcce0ae5078f5417f62a75dd
CRC32 3D1BE742
ssdeep 1536:XO3yZpgWNnAgRUAhCUmKpHJpHOCXsBd3R0wOxNW5xzG7U8YYnexV:00wOxK
Yara None matched
VirusTotal Search for analysis
Name b76aba0e3dda0038_background_script.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\background_script.js.wncry
Size 2.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 c21293e38c97b78148cea7068ff398a5
SHA1 b95b25e93def70553292011d2844e5af4a329f75
SHA256 b76aba0e3dda0038449290395bd0bcbb22e28408968358558c0317e1b34945ec
CRC32 A1875766
ssdeep 48:bk30JeDOjOsE0siflotnFwmiTk8yT5UdbYLeyBryS5UH2PwS2PKtsv6HJcL/Ced/:o30J4OREaflmFwdyC2HsXf6HJa5
Yara None matched
VirusTotal Search for analysis
Name 480ac039362a15a7_620.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\620.WNCRYT
Size 1020.0B
Type PNG image data, 16 x 16, 8-bit colormap, non-interlaced
MD5 91f80d44b0a786e5b0b3049ad61159fa
SHA1 e2fa9ade66052b6c706dec73bae2b44969232ad6
SHA256 480ac039362a15a7738ba76dffe807fd03fa29f7edaa8eb21ca0057c44a1ee8c
CRC32 59894B05
ssdeep 24:O9VAZXvb+z57oNj+DSRzrCzBehEs0JEAlKzj/EMf:O9yVC501+tBeCs0JRKvEY
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 42c34d02a6079c4d_131.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\131.WNCRYT
Size 2.1KB
Type ASCII text
MD5 0b9b124076c52a503a906059f7446077
SHA1 f43a0f6ccbddbdd5ea140c7fa55e9a82ab910a03
SHA256 42c34d02a6079c4d0d683750b3809f345637bc6d814652c3fb0b344b66b70c79
CRC32 2CC53C6F
ssdeep 48:46x9mcib30Rgu1je5YdnULEP8l1je5YdnULEPt:hnIb39ufbufV
Yara None matched
VirusTotal Search for analysis
Name bdd095b57b3724fa_306.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\306.WNCRYT
Size 5.4KB
Type ASCII text, with CRLF line terminators
MD5 cbb605575c62380a2bc4e401b1199762
SHA1 759e7fbb20bc7a69267e9c6c87bf6e27f7d42989
SHA256 bdd095b57b3724fa7240f8e7cf9c520f075a5f57747845f653d6d4d2186de589
CRC32 68449AFB
ssdeep 96:RO9X2LxtX2Lo06GDQ4qDP3e0ntH2wRUEOL6RLmrA:sofoqvP3rntHdKErl
Yara None matched
VirusTotal Search for analysis
Name 31b6a80f51d0ca82_msg_12a.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_12a.txt.wncry
Size 968.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 1536e13943ad742f47ced9904aaf52f1
SHA1 321aa6a07b434163f032bffa71f06dd7dff18ca1
SHA256 31b6a80f51d0ca82bf6f575f6ba7a7489d824d29c6eb6cfd11acef3e5be4fff1
CRC32 84BA5213
ssdeep 24:bkLrvb/S2zxXZBdxarrxAbbTJT67f5h63S55eU9A5Q:bk7S6XJxahgnkebC
Yara None matched
VirusTotal Search for analysis
Name 28b00e9f50111797_27.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\27.WNCRYT
Size 625.2KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 815b2fd9ea8ee0253911a70a3a3d942c
SHA1 caaaf905001d8a6eeca7a5b8d73043127c95b121
SHA256 28b00e9f5011179754cdb498d8706614a65900efe66b9f27e9ab900062db6b9a
CRC32 AE1169E0
ssdeep 12288:JvAf4xqBSBcBdN5YQ5s1vAf4xqBSBcBdN5YQ5s1vAf4xqY:pgSBc3NGNgSBc3NGNp
Yara None matched
VirusTotal Search for analysis
Name 8fd51c0854d90619_hu.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\hu.msg.wncry
Size 4.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 18daa49a6bab2ca91ddaefdb8cbf9926
SHA1 5f7bb5fb5e355d1c85710d80c51eb35f0fab8b5a
SHA256 8fd51c0854d906191034e404282f950126949530c3e7c30556432b3146213a58
CRC32 BAC06B58
ssdeep 96:o492QlqpIfSjrs3usiURqzIjmBBDe1z2bk4wLlcU5J94NcOnxvY:oQD6jrs3u8RqUjmBMh2bjSPcxQ
Yara None matched
VirusTotal Search for analysis
Name b831bc7f9264f349_hibsys.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\hibsys.WNCRYT
Size 128.0MB
Processes 2632 (WannaCry.exe) 2592 (taskhsvc.exe)
Type VISX image file
MD5 e605f5c4e80100278cf57b2a4c5270ad
SHA1 3aee548102eb9b243daad27b03b6c39a882d6bc8
SHA256 6b28b2d18521f8e5a2a2cb158a1ef3f90820f2bc3f2cfe0302a8295143ef90f0
CRC32 1C3E1B65
ssdeep 3:rn/3RXQXRABM:rnfWXRA6
Yara
  • Suspicious_Obfuscation_Script_2 - Suspicious obfuscation script (e.g. executable files)
VirusTotal Search for analysis
Name 4015412aa1e6fa69_tr.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\tr.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d86fdad7bc5ad4f525ddffb71a33415b
SHA1 27eb38ae80ed63ba4cb030769035aeef0d76b3fe
SHA256 4015412aa1e6fa696ae53e94552fc54db561dfedceba0af4dc7857b91124b9cc
CRC32 3B1F01BA
ssdeep 24:bkUvH/gnP4dxpnLJ35QQkBXSpIfBVjv7bZImtgUQpFFAH7wnGRtEpwu:bkUXgnAdxVLjpgXSpEBVjvihhFFA024X
Yara None matched
VirusTotal Search for analysis
Name 9660c76327158284_616.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\616.WNCRYT
Size 767.0B
Type Non-ISO extended-ASCII text, with CRLF, NEL line terminators
MD5 b4a673a60ee1efed0e6052a0df32aef3
SHA1 d1905159a6235849e554c15552772317ecaba1ed
SHA256 9660c76327158284c5b0c954c87febc2b5cd3c83ee35c737daeb397e7685d829
CRC32 94BF358D
ssdeep 12:tFnbki4JIoqumiTgdFy9ro/WB75miPSrZMOSUeomLV1in0roSx76XKB+xASinL34:tFnIOugDI0KwWJbmn8KxASinbyBnpnb
Yara None matched
VirusTotal Search for analysis
Name 800e65632f5995bf_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pygetwindow-0.0.8-py2.7.egg-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 bed19a065fbfcbccc6ecbd971e8c3ec0
SHA1 ee2fe5aa6f7b9718de762232910c22136ff62a80
SHA256 800e65632f5995bf836d9a5217323b095cac26bef948af3970e6e732322a84ff
CRC32 871F934F
ssdeep 6:bkEJspcRjpjKxsOzsZKol6OYp+agU/Yeh1EzAc68xN5i1KhB:bkEJsKFexho0OYQagUAe076Gi1cB
Yara None matched
VirusTotal Search for analysis
Name 9e913a799ff4a7aa_595.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\595.WNCRYT
Size 573.0B
Type UTF-8 Unicode text, with CRLF line terminators
MD5 9b317927370ef9b4730f93f12634af40
SHA1 0cee96e1686682606d8ebc5be65219c92ff50840
SHA256 9e913a799ff4a7aa1ad28b26d45f71330d8562e6f0f198faa503a5a18a222a20
CRC32 346481CC
ssdeep 12:UAwBlIOhXsRl/gaV82ThnKAiQZrLDTDnmucBcCVBIniSvrsvn:UAilIOhM/gaVrnKAiQZn7n0BRBIbCn
Yara None matched
VirusTotal Search for analysis
Name 16a050cbbb01f02d_37.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\37.WNCRYT
Size 10.0B
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type Non-ISO extended-ASCII text, with no line terminators
MD5 4bff91bb61fa0c49a7f58f5c6c66757d
SHA1 48085ee7824361a3eb0b9454723902b5761f52ed
SHA256 16a050cbbb01f02de8ae89ab4b4038ac39d23010670e3205dc979abd61840f93
CRC32 363C0932
ssdeep 3:sTj:6j
Yara None matched
VirusTotal Search for analysis
Name 4ee0b596d3236003_413.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\413.WNCRYT
Size 1.1MB
Type ASCII text, with very long lines
MD5 076be2183e109454009c79a03ce02cc6
SHA1 003547d31612a79a50fac7d0c51dad1d3d992069
SHA256 4ee0b596d32360033ff78cb5f9249aadffb7037b5c752066b74d5fdade4b5f89
CRC32 E367455F
ssdeep 6144:ou9TwMkMgAhcDnR5eTjnZV4VGLPEz1019sZMbPzWab3/m2bKhNHmNfy7xGbg51FS:oeTwAhcl5eTjIGj
Yara
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis
Name 8bf0705e02cfee44_usertile10.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 3b20f5e18b71fcd1d72cfc04349c721f
SHA1 3438a78d3c3b5a9c65a0f5f1d0110adda4d501f3
SHA256 8bf0705e02cfee4457efbaef3cc5f5aeb680d20dcbd7c8d893f386da85baafa4
CRC32 3EB3F7E2
ssdeep 1536:YdVhSSZt1IOeNNq9JNoS+kL7SQnLNfCp6:YNSSZMOeNNuuSdXfy6
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name f5bb3f44f3c3098d_603.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\603.WNCRYT
Size 593.0B
Type UTF-8 Unicode text, with CRLF line terminators
MD5 b66c4af70be29e021be15799c7758dfe
SHA1 f8be1ab523790f534db56c550b71ae34a67a06a7
SHA256 f5bb3f44f3c3098dfe5383779624a7bad2af74cf2620d5b7fcf6559038d84845
CRC32 2CDF8BD6
ssdeep 12:1m2iKxcYJCJOCsoldhG+PuxA42w8fxlST4K7FxToYNk9Izclr:1mHKxcVJdswdh4cxlg4WhMr
Yara None matched
VirusTotal Search for analysis
Name dadde4d63dc8f030_chrome_shutdown_ms.txt.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\current\appdata\local\google\chrome\user data\chrome_shutdown_ms.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 8236194951454077ddab8e8bce32ee0b
SHA1 b8a3083c893a2735bf452d6fafbbdbd30d0cf5b4
SHA256 dadde4d63dc8f0301d7376267d7b32601a24f5b72e80ee397c1f99ba2c6062b6
CRC32 BC1AA2D5
ssdeep 6:bkE8ZICYoH6yf4yw7l3ocJSrJ2MKD50y7MwR8N6SXguunSm731JS:bkE8xYaZwyw7lY2MSqycX3unSm5JS
Yara None matched
VirusTotal Search for analysis
Name 18d6564632c7a550_usertile13.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp
Size 47.7KB
Type PC bitmap, Windows 3.x format, 128 x 127 x 24
MD5 187048b427556605b452d1a18359bb8b
SHA1 19fef45d5f94903ac879fc2404490fc796ad1b08
SHA256 18d6564632c7a550efbc5db58e500e28c107dcf0cf06171ca765632de44a8a2b
CRC32 A9FAA9DE
ssdeep 768:4dECT+gvhA0TF6Q69/90hvr5EZ0HETlWj0GZbYtD8z8r4d6K7EQzs1sCQR0v:4dECicc9/otEZ7TlWhYtwV4K7psSp0v
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name e18fdd912dfe5b45_s.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\s.wnry
Size 2.9MB
Processes 2632 (WannaCry.exe)
Type Zip archive data, at least v1.0 to extract
MD5 ad4c9de7c8c40813f200ba1c2fa33083
SHA1 d1af27518d455d432b62d73c6a1497d032f6120e
SHA256 e18fdd912dfe5b45776e68d578c3af3547886cf1353d7086c8bee037436dff4b
CRC32 6B346763
ssdeep 49152:zUx4db9A1iRdHAHZXaTnCshuTnSQYUB/UZfCg2clOQin2h37l2Jh9iiRKpbXUSH:z/b96AdHA5XaTJvQYUBBgRlJi+rlliRy
Yara
  • zip_file_format - ZIP file format
VirusTotal Search for analysis
Name 2cb8481ab3e85043_521.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\521.WNCRYT
Size 167.0B
Type multipart/mixed; boundary="BOUNDARY", ASCII text, with CRLF line terminators
MD5 e7246a03f431d2319356d920dc643aad
SHA1 56c3ad26a9f5e4e2a0e6f365d89c9df22aa306e7
SHA256 2cb8481ab3e850433403726e6d08dad9517ab90ae440af6c441929fe2d53e1c2
CRC32 9FA037DD
ssdeep 3:/eIeAtISin/BIq/vuWXWMKEhGV8HtRLyewVwL1yodq+3ovY+Ov:/eQ67JLv3XmxitXwVwL65Yj
Yara None matched
VirusTotal Search for analysis
Name a37f8537b2dc9cbb_423.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\423.WNCRYT
Size 590.1KB
Type ASCII text, with very long lines
MD5 d40dd4103307dca8d8aa06f32f513bbf
SHA1 c17a63a4b6d2cce07cc493bf9a6988bf631f03ec
SHA256 a37f8537b2dc9cbb560646b9747e9866cfd9a3ae6dab9425a8b7a0896be276f7
CRC32 1E5978B8
ssdeep 12288:NA7Xbi+l5hg0Gh7wxTMlA7wtO9tChSZSZZ5fFv:G7Xbie5hg0GmB+A7wtO9tChSZSZZ5N
Yara None matched
VirusTotal Search for analysis
Name a75bb44284b9db8d_m_danish.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_danish.wnry
Size 36.2KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 2c5a3b81d5c4715b7bea01033367fcb5
SHA1 b548b45da8463e17199daafd34c23591f94e82cd
SHA256 a75bb44284b9db8d702692f84909a7e23f21141866adf3db888042e9109a1cb6
CRC32 5D2A06BF
ssdeep 384:SheftipUENLFsPzy3EFHjHd02wG2roqni2Jeo75Y3kmA31dv61QyU:Shef3jHd4G2M5bZrS14Q
Yara None matched
VirusTotal Search for analysis
Name 01a1db5a6c306dec_55.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\55.WNCRYT
Size 9.2KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 0658cd348b62bd3a8b22a6810c546546
SHA1 0cfd809d3b6c130c5e1d93889395887a841a683f
SHA256 01a1db5a6c306dec7392d30804e725185ce585ef9367e478492bd71d437d221c
CRC32 75101AC4
ssdeep 192:IG1jGnB4jQYGgGmGuGmGWGmGWGWGOGoGmGmG+G+GYGQGmGWGIGYGYG4GmGYGaH:OBiQYGgGmGuGmGWGmGWGWGOGoGmGmG+J
Yara None matched
VirusTotal Search for analysis
Name 371f427a779d72ba_491.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\491.WNCRYT
Size 271.0B
Type C source, ASCII text, with CRLF line terminators
MD5 7bfe66cb74b82850353f7d8727dfa1f5
SHA1 231a64bba207e92eff23613db104aee75e8efa48
SHA256 371f427a779d72ba7add86412f8dfca65002705948deba9d09d2a69254a12d46
CRC32 BA18B369
ssdeep 6:BhKokQ0sKokjQ6zFw0SWOwVBADM0KDvM0++H0eL70WtYw0eqjQ6dnoKoN:BhzkUzSFO0keD6+pOozN
Yara None matched
VirusTotal Search for analysis
Name bb2e1aa3888a6810_439.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\439.WNCRYT
Size 1.0MB
Type data
MD5 2f30dcd8eeb785eedd65c78f1ccbbe7e
SHA1 f1019a4dde44d68aeddfabb0be2ee9c1eef52a97
SHA256 bb2e1aa3888a681091cd701a6719c1fe80f5b880c8204125ad9cfa43a281c66d
CRC32 500D7648
ssdeep 3072:jL0Ld8WeKUPVfLQLtgMX3xA3AmLILBLnHLgbyLPOZFLe56nLUcC4LUlzIc1zIfL+:WTwTL1R
Yara None matched
VirusTotal Search for analysis
Name 74c398f97c8c0db5_751.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\751.WNCRYT
Size 317.0B
Type ASCII text
MD5 704cfd4d30aac2c81baabdfe293b546c
SHA1 0582b1e6f9d1a7c98664cc75ddc6865fc6835ab9
SHA256 74c398f97c8c0db58e552dd3c9417200ae109b5ce10515e27f929834c55b31e3
CRC32 F563546B
ssdeep 6:kpwa+td7CYpec8k3OgdAwmq+EbKBa1GnBc4jpccX0Wp+SXlQZWjdc8XzdxD:kpwa+LveA9dAwM8AnBLcPa+SXlQIBD
Yara None matched
VirusTotal Search for analysis
Name 581f50067801d7b4_axtzwdbeungqbg.ppt.wncry
Submit file
Filepath c:\users\test22\documents\axtzwdbeungqbg.ppt.wncry
Size 719.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 94dc8b8165a4d78d6a97d5419d946b15
SHA1 034a4308751384d93bb4a2612c53faae905924e6
SHA256 581f50067801d7b41ce3e5420968fb75263eeb01c261103709632db0ff4d514f
CRC32 99B94813
ssdeep 12288:ernfqQU96GlST3Ydhz71DO4y7nQU0asSscdFCTwcF1cXzaLUySZuVuSHNyY5XqFz:ezSP6GT7lOX7n7fP7CTwo18CUySZufN4
Yara None matched
VirusTotal Search for analysis
Name aac4ac970ec47cd9_WelcomeScan.jpg
Submit file
Filepath C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
Size 504.3KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=4], baseline, precision 8, 1024x768, frames 3
MD5 73d4281e46a68222934403627e5b4e19
SHA1 0f1c29cea7ea24ebb75c95114e0b0d26438e1d39
SHA256 aac4ac970ec47cd95dc7c65d7d38d29c1f948be24d5dad1d5aa21053125367c7
CRC32 C579F346
ssdeep 12288:lhozPuhM95uqkMK+FdBDSHtW+XKJE1D0tvp6HPlktXlDyRZs:IPuhHG13gWHO1ov4+8s
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 7a87e418b6d8d14d_101.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\101.WNCRYT
Size 1.2KB
Type ASCII text
MD5 b475f8e7d7065a67e73b1e5cdbf9eb1f
SHA1 1b689edc29f8bc4517936e5d77a084083f12ae31
SHA256 7a87e418b6d8d14d8c11d63708b38d607d28f7ddbf39606c7d8fba22be7892ca
CRC32 E1B1FF7F
ssdeep 24:4azu8qW09HSZ2p60wTyVz5bGzJzzTK+VUuG4CNnvxvB:46JYY5moleiUb42vlB
Yara None matched
VirusTotal Search for analysis
Name 3cac411fa6d2e9a3_157.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\157.WNCRYT
Size 3.2KB
Type ASCII text, with CRLF line terminators
MD5 2a5b3f427846b26805a99fceb82c023f
SHA1 5ff738184fa285a11b7a442cecb99ab3d123d523
SHA256 3cac411fa6d2e9a34c0cc631321e64d42ac37884348ed35872bc9e609c673346
CRC32 BF1BC138
ssdeep 48:hfwVzT4tVK5NUwQ0VbhNiaAOXC3NP0WhY/GnQQXjt8f:lw5GVKUwQ0VbmDZ0WSenrj4
Yara None matched
VirusTotal Search for analysis
Name b1ccdc2c516283ef_exception_hierarchy.txt.wncry
Submit file
Filepath c:\python27\lib\test\exception_hierarchy.txt.wncry
Size 1.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 32ccfc462aa13bab92e1b2b5bd02deea
SHA1 6528447ded5719997d589dac4cc49c660baea1bc
SHA256 b1ccdc2c516283ef617d6d7095a2d8f7fa80436951f7c64f0408be16110ebe9f
CRC32 C61CCE3B
ssdeep 48:bkqRlRjVi5XiiAhp7fbRn+gqFvNswiSb884uK:oeRjAhAhp7oguvNndkP
Yara None matched
VirusTotal Search for analysis
Name 88fb56f5cbb97299_wrinkled_paper.gif.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\wrinkled_paper.gif.wncry
Size 15.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 cb70f394cc25fb0ca057745010c2dcf3
SHA1 542e5b2b80a4c96cb6f70ea71253bffcf6166cf9
SHA256 88fb56f5cbb972990e899193c4f07e383e61f8b103f3da1d979292a86ba79480
CRC32 245BE304
ssdeep 384:mSpxV9a+rOZyOnQJfTYDrTrtLrPky0DvhzMrAwaW:Jjdi2QJjkz1Mr9
Yara None matched
VirusTotal Search for analysis
Name d70a219feaddf751_444.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\444.WNCRYT
Size 1.8KB
Type GIF image data, version 87a, 72 x 39
MD5 d6d3af598661350ba7e957fe578c1196
SHA1 3caf006b5c5c6004e77b41c55e3da8f4084a64d2
SHA256 d70a219feaddf7511af5a0f2b67943949e90c1f281d5d061745b14adfaf16843
CRC32 4939E06F
ssdeep 48:48CSp7kgRYuMFqFJ9gyttOx1cJUYpLfBV:48ztkEYuRH1ttO6UIV
Yara None matched
VirusTotal Search for analysis
Name 91088bbbf58a7041_638.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\638.WNCRYT
Size 251.0B
Type ASCII text
MD5 d8878533b11c21445caefa324c638c7e
SHA1 eff82b28741fa16d2dfc93b5421f856d6f902509
SHA256 91088bbbf58a704185dec13dbd421296bbd271a1aebbcb3ef85a99cecd848ff8
CRC32 3739C170
ssdeep 6:SlSyEtJLlpuoo6dmoEmGvNLoEs6W3v6aZoEmT+3vR6HK:4EnLzu8urvNDs6W3v6a5J3voq
Yara None matched
VirusTotal Search for analysis
Name 401e41b99d8c8d2e_697.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\697.WNCRYT
Size 57.0B
Type GIF image data, version 89a, 9 x 9
MD5 529838106788b9fed77490af8aa1052e
SHA1 30130c178d7ac53ed2f85aa38a70c2bc49a1819b
SHA256 401e41b99d8c8d2eafa41571b8d321aa419a4ca7ab8136fbe1b0adb86084d3a6
CRC32 DC80B95D
ssdeep 3:CMlbGltxlDRoBzEE:/lERoBz
Yara None matched
VirusTotal Search for analysis
Name f78cf215f2659e85_77.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\77.WNCRYT
Size 1.0KB
Type UTF-8 Unicode text, with CRLF line terminators
MD5 732d5c19514e127b1e497584c5c47439
SHA1 727f787865ba8ef26e65b9bf7db8038313dcf9ef
SHA256 f78cf215f2659e8585a66cfadd943fac651501fca02d45c8b0b292896c72e73b
CRC32 C1D6533B
ssdeep 24:tOAvNVSW/8PWqy2iQjDpJLQrzP7tnocg3KilIOhM/gaVrnKAiQZn7n0BRBIbCn:tOAvDS0ht2PDp47t7eKiHWNrnbi8n7nY
Yara None matched
VirusTotal Search for analysis
Name e48673680746fbe0_tor.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\TaskData\Tor\tor.exe
Size 3.0MB
Processes 152 (@WanaDecryptor@.exe)
Type PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
MD5 fe7eb54691ad6e6af77f8a9a0b6de26d
SHA1 53912d33bec3375153b7e4e68b78d66dab62671a
SHA256 e48673680746fbe027e8982f62a83c298d6fb46ad9243de8e79b7e5a24dcd4eb
CRC32 9D47022D
ssdeep 49152:5m9/gUvHrLaQ4Dt4PC+3xhae2cQX7E5zNvQIJZW/1h4+o4:MiuLSDt2C+3baAQX7ETQIr+h4+o
Yara
  • UPX_Zero - UPX packed file
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 620c9400b0b78600_id.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\id.msg.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f63c35b18578c38876ad8f2b369ec608
SHA1 07a3eb913b64c4378cec32dbdf1ad99eceb8071a
SHA256 620c9400b0b78600190b4763c61bc0ecf0c77ca17ab3ac0a92cbbb187eea22e5
CRC32 0B73AA95
ssdeep 24:bkZOw+RI60IrtoSoAtYP2z5PGQWvxV3N0ED+pWqSrrck8oOj4tl:bkZf6IZIrnLTvoWe+pKIk8dEl
Yara None matched
VirusTotal Search for analysis
Name 07abfac693d96c78_345.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\345.WNCRYT
Size 1.0MB
Type data
MD5 0be392759c2a85639920d8e418051423
SHA1 3ac6fe491f36581eedf34eeb266bd401d197622b
SHA256 07abfac693d96c7824eefe6903ce91383e9ea936c7206ed2f8de7b3f393384a6
CRC32 D3774F14
ssdeep 384:GxdmADM2Fb/n0s9GdmADM2Fb/n0s95UmMbZ1fJdSg6/mMbZ1fJbWW4:GdhLnydhLndUmMb/fft6/mMb/f1p4
Yara None matched
VirusTotal Search for analysis
Name 1b0be2381e7813ed_token.h.wncry
Submit file
Filepath c:\python27\include\token.h.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b91fdc0efa8da666666d9590b6f34325
SHA1 07be2204cf312250eab428668a55c42cdd993330
SHA256 1b0be2381e7813ed96fc5ce51c23c7a8b8c88a2cb9c8b457e998d52f8db8973e
CRC32 E8A8A7CD
ssdeep 48:bkgHOgyojnXkl11e/EHyhdxXfxH8slq8gs6ahm5ibKx9Cyq7:ogHFyaXkQcH4dx58stx6imYbCUym
Yara None matched
VirusTotal Search for analysis
Name bad04b1a9e50673c_usertile38.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 4e5c3e1452d39fb8742ce676a5033456
SHA1 fe6df7a297d5697cbce86a110d53f604da85db94
SHA256 bad04b1a9e50673c4f79fef48d129e474be08b367291ad738f0988ac58631a7a
CRC32 38247000
ssdeep 768:i5mp0zt4lKVIJEnxEvfHNiIZZmtw9Z0mJgeewUaUe+nuLLN6aq:xut4lKqEnxEvf8mMtwgG7UaguLL5q
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 4cda150f8c58f5c2_big5hkscs-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\big5hkscs-utf8.txt.wncry
Size 328.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 696ca9b8df2bd3ab44a0b9856c756cd5
SHA1 b149ebb7a7f6277c39e8bc3a4692010ed6c59e21
SHA256 4cda150f8c58f5c20413af1e7850394a1a76185a097c724e0c66583d88357af9
CRC32 B22A32FB
ssdeep 6:bkEvL4nfTZ07Mm3ucT5xkQzczoQHi2HtBdoAU6lLB53US5ZbybgjDJ2yn7ICqB8y:bkET4n7tme6UDNBvU6pPtZbyUp2ynr6h
Yara None matched
VirusTotal Search for analysis
Name 5bdb85a795b0188a_403.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\403.WNCRYT
Size 3.1KB
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 719fbe2b479507aa1348b02a20a363d8
SHA1 600a5534874a0059fac6fea306d6064d6327a8c4
SHA256 5bdb85a795b0188a9373f7c6ef2d711f0699c1377fbfe46f63f1f34b216c8d40
CRC32 B5568ED1
ssdeep 48:TqjzRpmSyXxuxYPCoJMnC2hiy3FXsygdtfxXEuoULMls7M+c1HG0FZ3/WOePPxR7:TUjbyXx3sJSjtfxXEuoMDYHGG3/WOSXZ
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name b6f1c1fefb59807a_craw_background.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\craw_background.js.wncry
Size 1.1MB
Processes 2632 (WannaCry.exe)
Type data
MD5 dd6254bc487a42162d1f04712a3b0bf4
SHA1 f4a3d7559ca7de86145b0fea4ca01eae9ae45573
SHA256 b6f1c1fefb59807ab0312e8b3a37f17c389d3d4ba1bdee9f5eea8679b7e7980d
CRC32 91022807
ssdeep 24576:xMew2lxbXaRhmKpQbfmfkwRxRNNTr0qSa62Bh:xMmhXuh3ptPbN0qtBh
Yara None matched
VirusTotal Search for analysis
Name 16cd155ad6683a0b_550.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\550.WNCRYT
Size 180.0B
Type ASCII text, with CRLF line terminators
MD5 c8492c5ed371481d8fb63a689f8b065b
SHA1 5d857caf84dfe7f1fe855416e0e0cda53bc6c216
SHA256 16cd155ad6683a0b5b746add5931b306e0341e17b29f7f3f1dc0c09ba5128367
CRC32 8256848D
ssdeep 3:x3cKFnOz2LHKFnO4WLHKFjRcnLHKFjRcGcRjv2qw3XsRmBwAqLOIOPLrRCjF7A:SKgKKqKfMKf3cRjlw38RmyzZurRT
Yara None matched
VirusTotal Search for analysis
Name b9c5d4339809e0ad_u.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\u.wnry
Size 240.0KB
Processes 2632 (WannaCry.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 7bf2b57f2a205768755c07f238fb32cc
SHA1 45356a9dd616ed7161a3b9192e2f318d0ab5ad10
SHA256 b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25
CRC32 4E6C168D
ssdeep 3072:Rmrhd5U1eigWcR+uiUg6p4FLlG4tlL8z+mmCeHFZjoHEo3m:REd5+IZiZhLlG4AimmCo
Yara
  • UPX_Zero - UPX packed file
  • Malicious_Library_Zero - Malicious_Library
  • Network_Downloader - File Downloader
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 3965322893101f48_154.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\154.WNCRYT
Size 3.7KB
Type ASCII text
MD5 9835887ae45b8d5b57d0b8acf303c4b3
SHA1 dc26bf315fb83212983d2532bc2abb26a4987f5a
SHA256 3965322893101f480693d45ad365d05cc31099cbe23f5a810c94e2e14d0b6d27
CRC32 D1A95D25
ssdeep 48:g4H5cNWBJdE10M4/0Uli6z8XIxTB2iDxypdmmZbWxOt:F5cN6H0Uli9IxTEbQsb7t
Yara None matched
VirusTotal Search for analysis
Name 2e0fa36f75b191a2_149.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\149.WNCRYT
Size 3.5KB
Type ASCII text
MD5 4396605b50c75e6f7fa1c3fbd6a42799
SHA1 5abc6c66208ff596f49a7c576ebb30d0773f1ea0
SHA256 2e0fa36f75b191a2fee3331ec0215a68dd913d62c2680555c21008286150a58f
CRC32 7505CE8C
ssdeep 48:rpcxYo3XRzvjbhWsHTTYTxDllvOr80nC2dnGHc839kUqg:9caodbhlHYTxDlcY0HpVg
Yara None matched
VirusTotal Search for analysis
Name 94a71574bf954c28_installed-files.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyrect-0.1.4-py2.7.egg-info\installed-files.txt.wncry
Size 392.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 45de51390527360192af2c41a1276eaa
SHA1 1547bb50ec7f6e6ecb102b03ea41e2baa045f6ee
SHA256 94a71574bf954c28fb06558428cec4e490c10cd9b20814ae668ff40e0e3766ab
CRC32 BBEF413E
ssdeep 12:bkEadtDJ5EzmRZqc+FYgff6E2h9UAQywkuX8g:bklXUzm/dafT2h9U9Xn
Yara None matched
VirusTotal Search for analysis
Name dd0d56e083532231_00000000.res
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\00000000.res
Size 136.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 97d169148385d43f19f76ca09ace331b
SHA1 b2d292bd1bd08074023edafd7e48f016768f6d77
SHA256 dd0d56e08353223110d305c900e94aea3bbe93ef7d13c0113ae289a77320ec2e
CRC32 0B04963E
ssdeep 3:/Wl//bl/lltbll7/:/sH/
Yara None matched
VirusTotal Search for analysis
Name 3fba7cc9ffd11a44_174.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\174.WNCRYT
Size 5.7KB
Type ASCII text, with CRLF line terminators
MD5 77207da9662acd3700efc3d65c1b93d1
SHA1 995a5c799b1375c96c707dcbd161851343b0d846
SHA256 3fba7cc9ffd11a44a734f8c448a46e4f722a8d5bd9cf8dd5e7c20addae7064a2
CRC32 C64E823D
ssdeep 96:FlElsomwYMadQBopr3qWaJ8+McDO1+AmMcDOo4Wcg/:FKlmwYMadsQDX8uq
Yara None matched
VirusTotal Search for analysis
Name 4e03a2fe3cd8a5d6_695.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\695.WNCRYT
Size 79.0B
Type GIF image data, version 89a, 16 x 12
MD5 2975e8d3aaf99066ccee1adeb2622379
SHA1 8c190ba2999cf92e521b68561f79f6df94e09b9f
SHA256 4e03a2fe3cd8a5d64eb924d1561ff838f473c10c3d8d97fbde6762f3a1b44611
CRC32 3B2E494A
ssdeep 3:Cw6/R/iltEchkltxlDnFhg+umMZe:R6/R/GlN+ie
Yara None matched
VirusTotal Search for analysis
Name 39f9b47d6974d386_errcode.h.wncry
Submit file
Filepath c:\python27\include\errcode.h.wncry
Size 1.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 05d3ba9ea1163e5eff86f62116266bde
SHA1 8a09dd9fbcd774d0dac0c3bd2474129d640b122f
SHA256 39f9b47d6974d3863d7bf8766ec0dd43602e243cbfcea4e94929b0773d82c806
CRC32 BF581787
ssdeep 48:bkxqY12yghJVHLQ2bGV+TFHyVEImXmcs28SfCpPxKOCX7b1:oQY12JNs2KV2FeO+HPxKp
Yara None matched
VirusTotal Search for analysis
Name 1c99489111112d21_548.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\548.WNCRYT
Size 121.0B
Type ASCII text, with CRLF line terminators
MD5 15acb038b5c2e03d56f5b588a077bf22
SHA1 09a1d643b7a3d233b047324c303e6295bfd93263
SHA256 1c99489111112d2150db0e18bbd474ff45f78fef80fa0e533dfd9ecfc6a3a480
CRC32 9B264929
ssdeep 3:hBWtHUVeRWRsjYR0uZjOBoVTDwwGvAgKVnA4lJMov:hBmHUAzYuYOBuaXE/lJB
Yara None matched
VirusTotal Search for analysis
Name 306c58f29ac7e9eb_747.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\747.WNCRYT
Size 171.0B
Type ASCII text
MD5 0bcdb4cd5616a139c3774159e9871e5c
SHA1 3d8ee96a47a540ff7ec4664db7951bd3fd24cc61
SHA256 306c58f29ac7e9eb5b08ec4d43ba1d69956b108a40f0627236861a00cfa2ea7b
CRC32 FCC16858
ssdeep 3:LUs/mtVX6obSecvnivcecz+B5yG6Se2tVdtTVIVkZLXSgUvSVcecX:IKmtVX6cSDfiEeczaFrtVdtVNjSR62eQ
Yara None matched
VirusTotal Search for analysis
Name 69ff858d26bff9df_33.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\33.WNCRYT
Size 10.0B
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type Non-ISO extended-ASCII text, with no line terminators
MD5 b3a1b25deddca030a8b13093fc72ecd0
SHA1 2fc8e5c8fd219dca84cfdfe1bcde48bd30c0a191
SHA256 69ff858d26bff9df9b4d7421b0446b817314f6ed111f44d178d046b152440114
CRC32 EADE8EE6
ssdeep 3:+57HO:+5DO
Yara None matched
VirusTotal Search for analysis
Name b8158342926da30f_144.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\144.WNCRYT
Size 2.7KB
Type ASCII text
MD5 bee15dd39fa7291fa7ccbc2171bfa885
SHA1 3e6327758ba97ef3c27527ad7fadcd5252eb297b
SHA256 b8158342926da30f6d52aeaf5c61f68866674da22d511770eb2c1685634a34bd
CRC32 99269332
ssdeep 24:sqH4qCtvLPgyqL+1ylnJzqFJHNaXSxFF4RTDuurIlnB:dYJtDPgDjnwIXSZ4RTDuTlB
Yara None matched
VirusTotal Search for analysis
Name 4248776e3fc28ebb_test_doctest.txt.wncry
Submit file
Filepath c:\python27\lib\test\test_doctest.txt.wncry
Size 600.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 841b3b1449b4d5a6e4da1ee0a42f2163
SHA1 12b84a3ba3db641415cc91f7e1be52d6acb08ceb
SHA256 4248776e3fc28ebbd382033af9ebc64385c659220fb41229f7250871b4d243da
CRC32 552A66C2
ssdeep 12:bkEhwyLKbJl2IFCoRH6PKT2i2rHXukOoB0Qj7JMW99EjFk74Ka4tR:bkowbJlXXlHo6IXmFksI
Yara None matched
VirusTotal Search for analysis
Name d8964c65dadac245_history.txt.wncry
Submit file
Filepath c:\python27\lib\idlelib\history.txt.wncry
Size 10.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 0d063c1e358c87da1668938094542fe3
SHA1 9d00f7d115e3b03a5b3a41747ece66bc3129c1d6
SHA256 d8964c65dadac245be52892c577e3b7bed79113ed2e4b3ee78d44d86ad964e45
CRC32 33E0692F
ssdeep 192:DzR7lAkig6gLbEHNfpeWqYm+IhlsZary5RzzWFMq2GHH5ZDg5Ex76PEsHe/nsfd2:D7oRgLbEtBPNm+IzsoGnKh2epgC96ssW
Yara None matched
VirusTotal Search for analysis
Name 15166cd5308967a8_sv.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\sv.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 730a7b001ed0986fe1f82bedb4935454
SHA1 86a1453e4e87ff0a8d40502f23187262fa6515db
SHA256 15166cd5308967a88a3b3ceae49fddd24c39260ada2f1a221347f0dfce78d3c0
CRC32 78824C69
ssdeep 24:bkc/G6YNUzKv1Sst5JEgn1hzbhWcBafUxbph2snAAkHT86JiBntWutm1RjDx9Q6l:bkUYKOvLrJh1R1WcBaypwAkHTLJomPjj
Yara None matched
VirusTotal Search for analysis
Name 5fe413812269f29f_folder.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\folder.gif.wncry
Size 360.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 15d3dd1f6575428722f7935947a27b59
SHA1 7134361ef0a7b28e9924c13c1636509036542cd3
SHA256 5fe413812269f29f661fd5e2c89e16dae0a1a4db2f05b103d69ef66a49538c44
CRC32 DB79EBDD
ssdeep 6:bkEZiZI274pJbLsJtzNXbjPiualKK+Bqfg1HJZIvZA766382wsDkz1n:bkEZQ8pVLq7LjNBq8HJZ+ZhH21DS
Yara None matched
VirusTotal Search for analysis
Name 805cfbd136d9cd8c_tkwin.cs.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\pref\tkwin.cs.wncry
Size 2.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a1258cc19db93285e30c3cba6f40ecde
SHA1 ce7c0c3d59fed9e41ef9ae43b0eae7fdc8e23e91
SHA256 805cfbd136d9cd8c01f40ef2afea688a13b0e4a36de3a1150c30dc51c4ecfc1c
CRC32 230F71ED
ssdeep 48:bkO6dfFv6RTGNwA4O/HcgXu3dRdextwI3OzVUBh81S6hZfXjPIbVOSDRrF:oOB9CjRvcgXaUTwjVT1dbmZxF
Yara None matched
VirusTotal Search for analysis
Name 7ace926f23c1999e_tlwqfcbpzg.ppt.wncry
Submit file
Filepath c:\users\test22\documents\tlwqfcbpzg.ppt.wncry
Size 876.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1a871342a6f8e49764d51e77e805d049
SHA1 1df32a539051b612b27af1a0217a147bfa160487
SHA256 7ace926f23c1999efa25f4cdc7706eb29be91bcc45b772e66e260d20dfdf76ea
CRC32 F60474D1
ssdeep 12288:hY5+pBzwdBGRHI3cLfpiDxjHYvy6W56qdTD9yTU5/GenxnDXd9tJJCHqngs4cLx:CyzmGx9ujHd6mdT8TKnnxTdTJ8KgEx
Yara None matched
VirusTotal Search for analysis
Name f384dd88523147ce_115.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\115.WNCRYT
Size 2.1KB
Type ASCII text
MD5 cd589758d4f4b522781a10003d3e1791
SHA1 d953dd123d54b02baf4b1ae0d36081cdfca38444
SHA256 f384dd88523147cef42aa871d323fc4cbee338ff67cc5c95aec7940c0e531ae3
CRC32 9CE738B1
ssdeep 48:46UcQdZnlcQfAQPWQEHKr9nGUeDjDpxpWQ1Q3QuQoQLX9TSQ2QIQPQHp7+8i:hNdR7cr9nMvXI0i7F89TSn1KX
Yara None matched
VirusTotal Search for analysis
Name 1bc22af98267d635_646.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\646.WNCRYT
Size 251.0B
Type ASCII text
MD5 1e6062716a094cc3ce1f2c97853cd3cd
SHA1 499f69e661b3b5747227b31de4539caf355ccaac
SHA256 1bc22af98267d635e3f07615a264a716940a2b1faa5caa3aff54d4c5a4a34370
CRC32 84A7323F
ssdeep 6:SlSyEtJLlpuoo6dmohvjbJFLoI3v6rZoho+3vjb0f6HK:4EnLzu8PJFB3v6r23vbq
Yara None matched
VirusTotal Search for analysis
Name 959f12c7fb3a23f2_sliceobject.h.wncry
Submit file
Filepath c:\python27\include\sliceobject.h.wncry
Size 2.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 294be595e0c9dcf92b8b8b659c130f1a
SHA1 e2bad89338880e7dfba232f6598e4455aad49d16
SHA256 959f12c7fb3a23f23c0b1ea0d0c8775594fb2cf74efb9123a7b0d466c5da7598
CRC32 743D41BB
ssdeep 48:bkbdP7G1CE0n5bIGcjs3GPWT5o5+UDvrvuv+ecfO7Q6+WnhDKKN:obdPfEusG3GOT50vrvuv+K7Q6jYKN
Yara None matched
VirusTotal Search for analysis
Name 77c46ff2f128090b_510.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\510.WNCRYT
Size 921.0B
Type MIME entity, ASCII text, with CRLF line terminators
MD5 9abf261619e558163df2d42c6ad47f25
SHA1 d620960adef7d05179bc1dc1d5069b3bb24335cb
SHA256 77c46ff2f128090bec0bb1170c21077d5b212ca8bea5b5396a83e459f0a5e659
CRC32 14EF09F2
ssdeep 24:3XmWxoErbGiuVtiiaR+yRO87yRO83yaNj:mWltu/Ra1C2o
Yara None matched
VirusTotal Search for analysis
Name 3e5aa481aadf4a8c_eventpage_bin_prod.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\eventpage_bin_prod.js.wncry
Size 23.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e1d11a0c145edfe01a5d5bfddb7033a2
SHA1 781dbe662bf633ecfdc014c81c5aab7a93e39d7b
SHA256 3e5aa481aadf4a8cda4ed05b3686681c3b211bd48c4814f4ec4041346709ee54
CRC32 3F62844D
ssdeep 384:xMPM4qRrMBdL1d6u3uW2AJ+5z6mSdOHRy/tIhLnk+dkC911MeYRmhSXxAZkw8QHu:2oMLpdRbLM5o8HRy/yXdD911BYU2akwS
Yara None matched
VirusTotal Search for analysis
Name a5b07c01c3ddb224_cjgznzwbcxyhnbkzq.txt.wncry
Submit file
Filepath c:\users\test22\documents\cjgznzwbcxyhnbkzq.txt.wncry
Size 31.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 cfaed506cab9b31f3eb02d920834006c
SHA1 9fe3fb78080560b9757e82589f3efbc602c69c34
SHA256 a5b07c01c3ddb22426a0cf6873f56a587c279f1bdb8682aeb2f4349b97653df8
CRC32 B6A96400
ssdeep 768:Dv2sZFgjHqW+/ZBPBNof/BGk2cCTaEcJ9KbwgU9U+QI:T2sDGHqp/78/IwCTRcJo/WURI
Yara None matched
VirusTotal Search for analysis
Name 9b2f91be34024fbc_94.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\94.WNCRYT
Size 2.2KB
Type ASCII text
MD5 e152787b40c5e30699ad5e9b0c60dc07
SHA1 4fb9db6e784e1d28e632b55ed31fbbb4997bf575
SHA256 9b2f91be34024fbcf645f6ef92460e5f944ca6a16268b79478ab904b2934d357
CRC32 86FB9F58
ssdeep 24:4azu8+v+39bYW4v+0Wn4Obg+EKkJQg9UWWY+YcYGV97Wu9TJGJABRF6RrJFdsvjt:468XxCSpAWL8jdL
Yara None matched
VirusTotal Search for analysis
Name afa7f3a814e37c2d_readme.txt.wncry
Submit file
Filepath c:\readme.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 419ffc39894a21aa56750c572a00919c
SHA1 737a6989eb0074400d0bf1f8db33ed610941f975
SHA256 afa7f3a814e37c2d1a1dd8aa3f1914175d4996327b21d94bb673103c1632eecc
CRC32 942406FA
ssdeep 6:bkEcT5c9PHCC7TowQ09vCk3Lr/zciYj3/TjaTXanqOAn6:bkEcTS9aeTNQ0FHLTw7ftqF6
Yara None matched
VirusTotal Search for analysis
Name 32c0e38cbd5660bd_iso2022_jp-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\iso2022_jp-utf8.txt.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7724caa5e914908e0426b091b7b5ac6c
SHA1 7c319aeffe470a3613485d2660c97b7c8453d6d3
SHA256 32c0e38cbd5660bdf5c9f3e3d8c0cc3c7e7689796b8260347cb021d448e68ba0
CRC32 A99BDD6A
ssdeep 24:bkJ8K7k84CjeZDu2Zd4B83ZhVIdcohj0U7E7SqOYLhiD3XNqB9HGKWYwnh0svvEF:bkyV2UZ3NsJD7CSbOhiDNwtNwhs
Yara None matched
VirusTotal Search for analysis
Name 1f1b0f5dede0263b_670.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\670.WNCRYT
Size 914.0B
Type ASCII text
MD5 ce834c7e0c3170b733122ff8bf38c28d
SHA1 693acc2a0972156b984106afd07911af14c4f19c
SHA256 1f1b0f5dede0263bd81773a78e98af551f36361accb315b618c8ae70a5fe781e
CRC32 0030B922
ssdeep 24:4azu8acGEXctI9tdb/7579g6tdhUgQbVg:46GBEXKI9tdHtdwg
Yara None matched
VirusTotal Search for analysis
Name 47c18aa241102aa5_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\psutil-5.8.0.dist-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 6b4eb2274f154e667bc9fbc048d37e28
SHA1 bd7f81b5cd5c2f220f96abe54154cbff455a460b
SHA256 47c18aa241102aa554bfc44acbbb92346902cd018cc15aa70c60315bfc414650
CRC32 68A2DB05
ssdeep 6:bkElaUmFw+fTWK1dEeaVMyVxlwGc7jnOH3PXAoSxu2jIvFhlK3IaNLhwTPO1y:bkElaU2fawYRDtcPOXP7hE6FhlK37NLy
Yara None matched
VirusTotal Search for analysis
Name dec96ccc71dcb571_536.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\536.WNCRYT
Size 928.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 82eaf4cde2003d09f460e8c58826cccc
SHA1 4770be62e3e35389809769fedb0a44aa85365ef8
SHA256 dec96ccc71dcb57147e1223a57e9df02ef89161037f91859ef376f2b6b7cc0ff
CRC32 1F787A91
ssdeep 24:SENirrL4J/+LbXmCjrOcUl8RgXbg4ANWfTy+WfTy+9:SqKrcJ/+LKC27ORScTNWby+Wby+9
Yara None matched
VirusTotal Search for analysis
Name 1aec0469b9f385eb_518.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\518.WNCRYT
Size 529.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 165c6cf8a023b25a0a65c03f8978895a
SHA1 37ab42e723ffbb435257c1c8c57727a1a29263fb
SHA256 1aec0469b9f385eb590c4523e76c4da535998f49a3e14508e0e83c2dc0735c32
CRC32 5A4BCABF
ssdeep 12:k116arny0x4JKmVNbXmMQymLXgVB0d+Aeym3fymsVyGZy2jf0x:S4arnLx4JRbXmom8jAeNfsrY
Yara None matched
VirusTotal Search for analysis
Name 11294be2b840f164_72.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\72.WNCRYT
Size 16.0KB
Type ASCII text, with CRLF line terminators
MD5 2db7cb21e18f31c854991d6638a376f4
SHA1 6ec49d280d4682c94697ba53b1e2a84555ae22a6
SHA256 11294be2b840f164b089df4e8e12d9f47f9d281dfe7e6752bd51087a1ca555cc
CRC32 0892183B
ssdeep 384:dClR1qIkd+RBnmexCD7nrrSUXoirdtpmxb0llm:dCS0RBnme4/r+Uoirdixb4Y
Yara None matched
VirusTotal Search for analysis
Name 3801bd205bf0bde5_570.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\570.WNCRYT
Size 166.0B
Type ASCII text, with CRLF line terminators
MD5 693badcf60b8773c17a16829c8541067
SHA1 af35eee3c527a6b7170625eacff353cfe5a4a366
SHA256 3801bd205bf0bde5ec3d69478534a87efb5b888404fb3f9b71d61cab8e087915
CRC32 B473F102
ssdeep 3:xyAWJgR7zrcqWJgR74LcqWJgR4c6cqWJgR4cGcRjv2qw3XsRmBwAqLOIOJjF7A:AAWJSrcqWJ1cqWJFVcqWJF3cRjlw38Rt
Yara None matched
VirusTotal Search for analysis
Name c6b692d00a960aa0_pgenheaders.h.wncry
Submit file
Filepath c:\python27\include\pgenheaders.h.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2addd38fe5c191a1f99d193ab7e45766
SHA1 77a429f54ea7a9400ddc44fb75f5e41f207d175f
SHA256 c6b692d00a960aa039fe0aaaafa0e4ab4f5f3833fbde10c7dfedf7f8822f80d1
CRC32 A68C929B
ssdeep 24:bkSzZl99OreGLHofwPgCHbznFRQ8ociwQofXlQCNUgxG/bo1GClrztr:bkeZl99OreGboovbzn/Q8o5TofXlcToH
Yara None matched
VirusTotal Search for analysis
Name 2683517766af9da0_691.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\691.WNCRYT
Size 339.0B
Type ASCII text
MD5 e0bc93b8f050d6d80b8173ff4fa4d7b7
SHA1 231ff1b6f859d0261f15d2422df09e756ce50ccb
SHA256 2683517766af9da0d87b7a862de9adea82d9a1454fc773a9e3c1a6d92aba947a
CRC32 1D92FF84
ssdeep 6:SlSyEtJLlpuoo6dmoOpxoPpSocvNLohX3v6ZhLoh+3v6fJ:4EnLzu8WvNo3v6b3vu
Yara None matched
VirusTotal Search for analysis
Name a5cd6b84d688ab1f_msg_29.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_29.txt.wncry
Size 888.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 7dcd01a394dfe167834e36cc54095b80
SHA1 6d4c8f1d73e4eefefa82b141c9d1a95a9b74f8e0
SHA256 a5cd6b84d688ab1f01e715091f2a0b14d7ef5b168cf3b785d6da63ba82d620c2
CRC32 022B1652
ssdeep 24:bkgMEvXBsUohwh5mJwJ0KI333zzjqB2AWnHn:bkzEvXaUouhYwJ0KI3HDqAbHn
Yara None matched
VirusTotal Search for analysis
Name feddb16bb8e55310_271.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\271.WNCRYT
Size 8.7KB
Type C source, ASCII text, with CRLF line terminators
MD5 f3a9419f7f2a96634c1543b02afaedf3
SHA1 278ce2253b529cfdd49523c6ff52be02b9901dec
SHA256 feddb16bb8e5531081d42a7afa7e21986b418653c7f7b9a66449649d27582bee
CRC32 3EE0A78F
ssdeep 192:Bz+PW5kt0kQQvtvw3XTqC1mMeKjZiOO+uG7RNNNWVLnSY7b1SNt99Sz7UZ:Bz+jZQyZwnTqC1mMeKjZiOO+uG7RNXFL
Yara None matched
VirusTotal Search for analysis
Name 1582d6984b4fd2ed_227.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\227.WNCRYT
Size 1.2KB
Type ASCII text, with CRLF line terminators
MD5 ee293911e2b74b3aaf1f8599fb88ffb8
SHA1 5e55b2971a9a1d3d835cbe2cce56b63d3c6db684
SHA256 1582d6984b4fd2ed407cbd50b3ad97b79fa95451d39333f1d6966fac40262974
CRC32 75F031BD
ssdeep 24:vLt+MWMARRRkyo8glMxuLTZMHcqWWmFD+pq+c9HkqRc:p+M7ERsWHvWWmRhE
Yara None matched
VirusTotal Search for analysis
Name bbfce1fd26089982_189.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\189.WNCRYT
Size 15.4KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, comment: "File written by Adobe Photoshop\250 4.0", baseline, precision 8, 228x233, frames 3
MD5 b80ef81d806b7b368ef56427b5a49df5
SHA1 071eaa2eb2dfc680b1ae47304f2e54dbc883ede1
SHA256 bbfce1fd26089982b84941b75bebb061a639973a8f99fa0073df38b74c0ced84
CRC32 C7D38EE0
ssdeep 384:ypTIa8k+AuG6mxNYaZ8RtFfFhBx8QZ3X1tYLN/jLB:ypTIa8DAKmxYtPhBWQZ3X1A/R
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name bcc0e6458249433e_336.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\336.WNCRYT
Size 1.6KB
Type GIF image data, version 89a, 64 x 100
MD5 dbfae61191b9fadd4041f4637963d84f
SHA1 bd971e71ae805c2c2e51dd544d006e92363b6c0c
SHA256 bcc0e6458249433e8cba6c58122b7c0efa9557cbc8fb5f9392eed5d2579fc70b
CRC32 A4AC1843
ssdeep 48:aE45BzojC3r1WAQ+HT2gAdKhPFZ/ObchgB8:V5Gb1WN+yfcObmgW
Yara None matched
VirusTotal Search for analysis
Name 3b92fede080f9b0e_168.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\168.WNCRYT
Size 581.3KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, datetime=2009:03:12 13:48:18], baseline, precision 8, 1024x768, frames 3
MD5 bdf3bf1da3405725be763540d6601144
SHA1 d997e1c37edc05ad87d03603e32ad495ee2cfce1
SHA256 3b92fede080f9b0ec902afc58831191b5b8ccbaf6732352fd7a8b445d1e9f0bd
CRC32 462F6303
ssdeep 12288:8omLCMmR7ooWhKlxfOFHEV3+jsK2sca2P7T7tKkP3ZOztswbGXrzr6L8llV1o3J4:JH7othK/mFHEVyD2scaE7tKuJGPbQT6E
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name f75a29bb323db435_679.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\679.WNCRYT
Size 251.0B
Type ASCII text
MD5 899e845d33caafb6ad3b1f24b3f92843
SHA1 fc17a6742bf87e81bbd4d5cb7b4dced0d4dd657b
SHA256 f75a29bb323db4354b0c759cb1c8c5a4ffc376dffd74274ca60a36994816a75c
CRC32 F7A986B2
ssdeep 6:SlSyEtJLlpuoo6dmoGNv+9/LoGU3v6rZoGNo+3v+6f6HK:4EnLzu8GvWe3v6r5F3vmq
Yara None matched
VirusTotal Search for analysis
Name 2a681855b3dfcac8_enumobject.h.wncry
Submit file
Filepath c:\python27\include\enumobject.h.wncry
Size 552.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a9d78aaacc009fd80d12d432ec2aef6a
SHA1 d985c89ea56d8fbd3a2685c4f3085410a483ab97
SHA256 2a681855b3dfcac8e01fb8bf5dd129f80a862b5052a85234b878594dbffe1d36
CRC32 59C5A85C
ssdeep 12:bkE5TtqF8sB7ksYTAX4lQLMfeDwnBEJEmvNtYRReV6vF06eOr:bkTnhYMX4lQLMW8BEjV2RVtZ/
Yara None matched
VirusTotal Search for analysis
Name d49149c207dc6698_msg_20.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_20.txt.wncry
Size 824.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b42ab87ced07f763cef99a7bfc4d3118
SHA1 e6312f3056aa9c81308a8aba28d81c71d50ca1ad
SHA256 d49149c207dc6698c8f1d19b54aee6c166047600a35830d8dd4a508f0aa307da
CRC32 526E8F7E
ssdeep 24:bkyY4haEYFKdw3UbpgjKUUMQnoEYRJyJTQeslOu:bkyhwt8dw3kiKwQ+WTjsD
Yara None matched
VirusTotal Search for analysis
Name e3268c95e9b7d471_654.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\654.WNCRYT
Size 251.0B
Type ASCII text
MD5 6a013d20a3c983639eaf89b93ab2037c
SHA1 9abec22e82c1638b9c8e197760c66e370299bb93
SHA256 e3268c95e9b7d471f5fd2436c17318d5a796220ba39cebebcd39fbb0141a49ce
CRC32 D281BF02
ssdeep 6:SlSyEtJLlpuoo6dmofriP/FLo3+3v6rZoY+3vrig6HK:4EnLzu89+nFO+3v6rw3v+lq
Yara None matched
VirusTotal Search for analysis
Name b32b7924fdf342f9_gxefffgqwhrjd.rtf.wncry
Submit file
Filepath c:\users\test22\documents\gxefffgqwhrjd.rtf.wncry
Size 954.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 68b2103c36097d9b7b93c3e7f84d6d7e
SHA1 4a880f06692b5beae2fc88c7a45a784586b5952a
SHA256 b32b7924fdf342f9c98aaee7ecf415a67e20f7dd9433ba8c60e95f7e1e3cc8d3
CRC32 FCD982DD
ssdeep 24576:Mn0OdwwH2nN1l7Xypg8HBFfAQ4JZpYvMahyJLbTngwWAo3vUa:MLKwWHl7F87EZpCmlmAo3vr
Yara None matched
VirusTotal Search for analysis
Name a26c9f6c70265247_kok.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\kok.msg.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 36ed1a064cdd4b815e920baab665124e
SHA1 8e8b47f7aa2df3173f9cee746c81dbe0abfe644e
SHA256 a26c9f6c702652472fca341c906d4adb096ba76e9baa1a01366e1f250c96e72d
CRC32 7C5D7047
ssdeep 48:bkB1tYybUZzPDsVdVk+r+NCqbXE9Qu4a2oaoLQ49G3C8CcEj:oB1tlUpDsVzr+NCqbDu4ut4ozj
Yara None matched
VirusTotal Search for analysis
Name 0d60ed8e9ff0b130_notebook.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\notebook.jpg.wncry
Size 3.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 94affb7b08431f55b88ec4af11210826
SHA1 86679f916a65a94f0945ba61759c149388903e16
SHA256 0d60ed8e9ff0b1301fc8c64b96540da27472130d491c3c819b8316aab14155ba
CRC32 227FB26F
ssdeep 96:oGXlu513Gu6FwmkCRNhpaVFN3BnKvKpH6:hO1WuExHXoLntB6
Yara None matched
VirusTotal Search for analysis
Name 71d101428a95fb71_744.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\744.WNCRYT
Size 107.0B
Type C source, ASCII text, with CRLF line terminators
MD5 21b3cbdee2e4f0ca46e48380db150dbb
SHA1 e5ee14a579eefec0febc6fe048e647efde5b14fd
SHA256 71d101428a95fb71ebeb9d326d39f311572ac3db91ce1292e1a0a14da514c701
CRC32 D8AC4A1C
ssdeep 3:XBAjWhZiXMLUjE4Nk+rBNorLRhCA/hosYfYy:RAqPM7E8rmLRhPZGV
Yara None matched
VirusTotal Search for analysis
Name f26546d2559895bc_todo.txt.wncry
Submit file
Filepath c:\python27\lib\idlelib\todo.txt.wncry
Size 8.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4434f586db4c13a08b9576c663fdc9d2
SHA1 e3f2cc0c1a63c75bf84040b9a11da858b0a55794
SHA256 f26546d2559895bcc4b4022982b800f7d3be580ed1c9d80cfcbf3fa8045adc2c
CRC32 F37A6A0D
ssdeep 192:T7hCQgH522dVm7cDhT01V0A/xlfGor+x5XI:x+Z9A7wYsy1q5Y
Yara None matched
VirusTotal Search for analysis
Name dac3cc4d408f764f_grammar.h.wncry
Submit file
Filepath c:\python27\include\grammar.h.wncry
Size 2.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 df3c338e38085195893a532b2382b90b
SHA1 f17635fb1aaeaca2da5b86676ccc2a5e638f11f0
SHA256 dac3cc4d408f764f4a041d9363ace19006511cdce5a00acb5be2ac28d723d58f
CRC32 039E8698
ssdeep 48:bkQbVAzNOlT3B4lzOISzWEvK6MXTzHj8lzr/GS3hfILyXvRPuh:oIU094lzyzWEy6MIl//R3LZu
Yara None matched
VirusTotal Search for analysis
Name a3419af7bdefcb89_140.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\140.WNCRYT
Size 4.4KB
Type ASCII text
MD5 9a24b935d8e3f60a0947cf3f16917575
SHA1 e9db0557f08272c2a82fdaca06d46970347b476d
SHA256 a3419af7bdefcb892bf6410ec71bf95eea2e715e9bbac53fb93b63a3f84256ce
CRC32 698FCED5
ssdeep 48:R9gwwTNGN62C9Gq+quUa9DwvlgtnSsgPVp5QanWQfl5:Rq7TNuC9Squg9gcsgPVcS5
Yara None matched
VirusTotal Search for analysis
Name 9f2bffa3b4d8783b_121.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\121.WNCRYT
Size 1.1KB
Type ASCII text
MD5 d827f76d1ed6cb89839cac2b56fd7252
SHA1 140d6bc1f6cef5fd0a390b3842053bf54b54b4e2
SHA256 9f2bffa3b4d8783b2cfb2ced9cc4319acf06988f61829a1e5291d55b19854e88
CRC32 987BDB67
ssdeep 24:4azu8pYpzzktTYyUgC0CIKjblie5f9kwAAs+CFsFoD6GADvtU6svO:46dCzWTh2AA9/2F4oD6GAztU6KO
Yara None matched
VirusTotal Search for analysis
Name d4af28809128a228_msg_15.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_15.txt.wncry
Size 1.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5a2e0026ef55e69434845890bb4636d0
SHA1 4020d3010d93bceb1b6b406dad9e57e0f5cb54ea
SHA256 d4af28809128a228cd34b8260d2df322106cd2e4f6292271380fe78df4fe234f
CRC32 82A401E0
ssdeep 48:bk3I5JqYqd69iB3zGhckPAiFkCWgXEOAyBiBjuHOhl5n:o8pu4+wXnAy+KOhr
Yara None matched
VirusTotal Search for analysis
Name 36ce4a658caea5cb_cp949.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\cp949.txt.wncry
Size 648.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 7fc0c23b8bfd362974c45381a8c594ac
SHA1 11d489ca8f718e9ada199179a0b69c5ca0b362f7
SHA256 36ce4a658caea5cb655ea95e989891fd34ad93e4e0088d4684cae2a3ddabd814
CRC32 C939CB7E
ssdeep 12:bkEqgR34S0NoF8uwZw9czNy5fuL307WMuXSxeBpiYE8Mkj/GWfdeqLCtP1:bkfgJ4SXxUyQLE7WMIVPiTkleDP1
Yara None matched
VirusTotal Search for analysis
Name 96c5a3fd00ffd52f_python.gif.wncry
Submit file
Filepath c:\python27\lib\idlelib\icons\python.gif.wncry
Size 872.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 d06e0b5a3c2dc083df74d5c5f287c611
SHA1 cf835fc492b4c31f476ce5e4514260729236e937
SHA256 96c5a3fd00ffd52f3c273c7eff17d614afcae311d6a4a360770dbf03f9360aff
CRC32 3BA095EA
ssdeep 24:bkwqVQ5HYa6W8ZTIbtCzg4FVYlWvOKtVShvUp:bkwqcOKws0VYlWvlto8p
Yara None matched
VirusTotal Search for analysis
Name 5ede808b31b0c72c_ru.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ru.msg.wncry
Size 2.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8e2719cd11c2b9f66ca87a7f82b44dec
SHA1 6dc2de782665340e84673947a1d3d545235ef607
SHA256 5ede808b31b0c72c459531da08b732f2e045417fd25fca20a40afc09e8d79be6
CRC32 D4946444
ssdeep 48:bk5vTGS73IEM4C2eoiT7yHXYxhE2BRGDq4:o5KO35eqFW73sq4
Yara None matched
VirusTotal Search for analysis
Name e4ba8987a1a318ef_sv.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\sv.msg.wncry
Size 4.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2376e56232a0bf2a0d4990ec90e44e85
SHA1 6f3c9637d731648bd339d71c0294fa452cc4dd74
SHA256 e4ba8987a1a318efa061e7b9a0b1b85228b488ed03ec00b90e6f526cd107164c
CRC32 43E472F5
ssdeep 96:oKoVHRlZnp8u+jj9OmTKoLewz+pg9zJf+5uj628p6ZjCLEJ:AVX9pb+X9OcKoLegpltsuOYpq2
Yara None matched
VirusTotal Search for analysis
Name 5f7114e783345f5b_sgigray.cs.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\pref\sgigray.cs.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f53c608db8bc8d47e92f9d0d1c1a16cb
SHA1 bab53b43358e0f22c2227958779e985b328f0407
SHA256 5f7114e783345f5bd8f6aa239699484af2c043ca11536fb0d9ef9d5a870dd25b
CRC32 5F55321D
ssdeep 24:bkZ6Qa5mwKvjJ3O0Q8WtUjAkJwnHptocG/JR56Cn+v0pV3qwLnzvJYP:bkZ6vAA93ptK/JR56PGdfLzva
Yara None matched
VirusTotal Search for analysis
Name e69d5cd20d198ac5_stucco.gif.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\stucco.gif.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f151188da2bfb27bff9108ffea74b43c
SHA1 ead8e5c18094e0037cfe2752927d1c48ba82dbbf
SHA256 e69d5cd20d198ac581aa2fd4e602be4f77488066b4b9fc12911148789b05c1d2
CRC32 AF85AC9E
ssdeep 48:bkRsPnq6HYLgRhpTONqw4oVXsuzDc6Vb/y4n4T/+:oOPndJfMN37VcuPbyyQ/+
Yara None matched
VirusTotal Search for analysis
Name ec4a2514ff760192_158.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\158.WNCRYT
Size 1.9KB
Type ASCII text, with CRLF line terminators
MD5 73c3862d4d10c1218813e3864b02909a
SHA1 4058a0c48510a85eb10b81d61eef52a62d888b57
SHA256 ec4a2514ff760192253d736e1f5c66ffeb0ed729723f07d79516fb06b8304ec0
CRC32 D8FCA3EC
ssdeep 24:lytBaKnIRqEpSfEmZEisUZPNRh5JfKmIE0y/gE09t8lhB627Y/AT7GGtkiZLRHDi:lN2IRfvdezNFi2g2QSP4CGUu
Yara None matched
VirusTotal Search for analysis
Name 7a7f1f724e2e2bc1_cs.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\cs.msg.wncry
Size 4.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 86acccd1ab6e27f29e16f22f520b066b
SHA1 6a9d2bbd7ac64620ba89bae56d8fa14adbc29036
SHA256 7a7f1f724e2e2bc15479a3419c797605f2a6b49dc24d97ba3f24dcb2f2a4253d
CRC32 60B2A9F6
ssdeep 96:oIkiIUh9luVI78s7RXouKhyf2s09lJq+Hjb1myRUUBJxsQ9g:hkiF9j84BoPA2sklJq+HgyRpBJxsQg
Yara None matched
VirusTotal Search for analysis
Name f26385b412d2b348_en_gb.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_gb.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 885bfdb025e6cb4d3cc9e067f1a28fd8
SHA1 5ca3638e1dd0fa2dc91fc6419ca9af538a778f54
SHA256 f26385b412d2b348371b46aa5cc1654d6740819f6960f8353ce85a11b53fc73d
CRC32 FC2EAC4A
ssdeep 12:bkEUdoKjNh9QrIiv4Kmp3uTYdF4LOTcqFd/cadgbh1s:bkDyblMdF4Ld0pnGbDs
Yara None matched
VirusTotal Search for analysis
Name 1ac0f583cf836284_methodobject.h.wncry
Submit file
Filepath c:\python27\include\methodobject.h.wncry
Size 3.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 04d9a455240f865ad22d368f7f46857b
SHA1 6649b32ed4dd026d9ef7cf48edf2035a1853a070
SHA256 1ac0f583cf83628425cf412b5d122a437806dfa78fa0588f937065c08281f99b
CRC32 3935083B
ssdeep 96:odiEeoNXpSQRBtHQzvDOLbo+mVVnWWIrprzES:AJXpScHQvodUWDrpfp
Yara None matched
VirusTotal Search for analysis
Name a8d03aaaf372a201_138.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\138.WNCRYT
Size 3.8KB
Type ASCII text
MD5 b005708aaa4abe1f11c6447284d54d32
SHA1 93599683b9558fbeb07bff9b07792bd34e1ca692
SHA256 a8d03aaaf372a201790eed7107f2024d73a024a850d1241b4a40af08a33a2776
CRC32 C9A48F90
ssdeep 48:RBM53MSplFy+0yD5BZvP8Es0ULBZn/ZSHc/DX:Y58Sp/y+0yDTZH8EsNLBZn/ZesDX
Yara None matched
VirusTotal Search for analysis
Name f6786b5d4f612cd3_file.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\file.gif.wncry
Size 360.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e539db0753ad6b4ff18a3c1ee9d02465
SHA1 7447d88ef69b09510a62a6688b9a7d1f019931f1
SHA256 f6786b5d4f612cd30f91ed3abc0221905631b49f0d0b1fae113b6ac14cbfea50
CRC32 9F1A0542
ssdeep 6:bkE/AcL0vJ17gu5cBXbmW3QUv6EZMq1nv71sZxnsnspHAGOhxjr+0WfkN8xDt59T:bkE/Au0T7gAcBXqmv6E6Qnv7GZYNGOnQ
Yara None matched
VirusTotal Search for analysis
Name 2efbad274fedb8d7_topbar_floating_button.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\images\topbar_floating_button.png.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 4fc620e6179627e3c27c8b2698e917fc
SHA1 6278f9b53c1d027cedece322c32d6981792c8cfa
SHA256 2efbad274fedb8d72533ffba4288c592f6d31acbbd4ee3db282535db0ea68b15
CRC32 2D03FEBD
ssdeep 12:bkEUM4NyD2J+Y3X7/tkPLMQvYJLuRmwNCzGhu6hfNK:bkX483rwLuL3w74KlK
Yara None matched
VirusTotal Search for analysis
Name 50ecff66625dc219_ro.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ro.msg.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 cff0a1d335ebebfa6100cda8811fd82a
SHA1 6f03f1fd10e44011d23f5078b210767cf9608145
SHA256 50ecff66625dc2196fc454b6afa69776dad7c390f6b5a4f5f6e3b5bc0f5f7455
CRC32 AB823DC4
ssdeep 24:bkqml5u1HlqIzF/ksGM0OyoG0EPiOio0Zxnazg4JzJXLYrxQJeOvc3vn:bkqme1hksG25BFZxQg4zbtJeOKvn
Yara None matched
VirusTotal Search for analysis
Name e2af420551571d9a_609.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\609.WNCRYT
Size 91.0B
Type UTF-8 Unicode text, with CRLF line terminators
MD5 437aa7e2dd37c856a1eb2f225c301144
SHA1 0d7377bb97cee2b30c61645ef84a38315966b817
SHA256 e2af420551571d9a97c782d85a885b0cf4ac35244063c7272b750c584a26ee70
CRC32 7757167E
ssdeep 3:hWumyAQiascULAdRFDAQkADoqDJSMvurcxcv:hcQiascxRFcQkAUqjvOke
Yara None matched
VirusTotal Search for analysis
Name cf2e78ef3322f012_134.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\134.WNCRYT
Size 2.1KB
Type ASCII text
MD5 458a38f894b296c83f85a53a92ff8520
SHA1 ce26187875e334c712fdab73e6b526247c6fe1cf
SHA256 cf2e78ef3322f0121e958098ef5f92da008344657a73439eac658cb6bf3d72bd
CRC32 6BDE82DB
ssdeep 48:46+ytFoQAQPHUKPo6eQ4QBuQ0WbQcJeyFQDWZlQD1QbS7XQn1Q7mDaSAJQ7GMLzM:hIpP5tzYhTUhAgEAE+
Yara None matched
VirusTotal Search for analysis
Name 812db204e4cb8266_634.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\634.WNCRYT
Size 300.0B
Type ASCII text
MD5 db734349f7a1a83e1cb18814db6572e8
SHA1 3386b2599c7c170a03e4eed68c39eac7add01708
SHA256 812db204e4cb8266207a4e948fba3dd1efe4d071bbb793f9743a4320a1ceebe3
CRC32 D89DE103
ssdeep 6:SlSyEtJLlpuoo6dmoyejbJFLo63vULo63v6p6HH5oy7+3vjb0y6:4EnLzu8YeJFL3vI3v6QtS3vK
Yara None matched
VirusTotal Search for analysis
Name 64f796c5e3e30044_656.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\656.WNCRYT
Size 251.0B
Type ASCII text
MD5 f3a789cbc6b9dd4f5ba5182c421a9f78
SHA1 7c2af280c90b0104ab49b2a527602374254274ce
SHA256 64f796c5e3e300448a1f309a0da7d43548cc40511036ff3a3e0c917e32147d62
CRC32 9E5B3897
ssdeep 6:SlSyEtJLlpuoo6dmoXrUFLoXK3v6rZoXs+3v9f6HK:4EnLzu8VUFH3v6r83vMq
Yara None matched
VirusTotal Search for analysis
Name 5c5ef7504e5925aa_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\128.png.wncry
Size 6.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 08581936e74689a1d254ff1c7f31ae10
SHA1 3e9192268a4a320f29b3c8c85e8644a099b31248
SHA256 5c5ef7504e5925aa64df64da6136c7d2fd9465c935f935bbef1410dff8e50a5c
CRC32 B2CA3648
ssdeep 192:ML1WQosaiayrDjRKABGVb1hfb/SRLfovA9:M5xosp5rDjRQVxhfb/Tvy
Yara None matched
VirusTotal Search for analysis
Name 16580c2ef1eea215_grammar.txt.wncry
Submit file
Filepath c:\python27\lib\lib2to3\grammar.txt.wncry
Size 7.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d877ac8f830b772ce8dfc66181cc91fc
SHA1 b33fbd58b43b3fc3c9c66a93ea5cfb4740fd055e
SHA256 16580c2ef1eea215198d852f1363d6044725d3543ec7ba01500bf1f67a11166e
CRC32 88CC572E
ssdeep 192:Ep5BTcxTzC3IFpKjn/fbyuFxS8IxcNVX0lwv0Vtk6p67Ao:n3GIFpubyu3nNUbi6p67Ao
Yara None matched
VirusTotal Search for analysis
Name 146f61db72297c9c_m_swedish.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_swedish.wnry
Size 37.6KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 c7a19984eb9f37198652eaf2fd1ee25c
SHA1 06eafed025cf8c4d76966bf382ab0c5e1bd6a0ae
SHA256 146f61db72297c9c0facffd560487f8d6a2846ecec92ecc7db19c8d618dbc3a4
CRC32 8C353111
ssdeep 384:SheftipUENLFsPzy3EFHjHdb24G2ZKLVdDeo75Y3kmA31dv61QyE:Shef3jHd/G2w6ZrS14w
Yara None matched
VirusTotal Search for analysis
Name b86fcc1361dd2f83_600.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\600.WNCRYT
Size 355.0B
Type DOS executable (COM, 0x8C-variant)
MD5 3deb7891c1dd6d40a300d5c7d1f2314e
SHA1 5396a75bd36d811e3d3b9bc6472a6da8a52223f8
SHA256 b86fcc1361dd2f83e54cfd586192dbff7ab8a89f50b003ed8deb706cffd36fae
CRC32 681C3E95
ssdeep 6:1VHpFV1WYeL29UFVfJRwFAOFcZaxRs+aRdULEEdtVV1lKVNl/Ny:1VHDV1WrL2iVfDwSOCgxKLRCDVVLify
Yara None matched
VirusTotal Search for analysis
Name fe7ce80d2794fa44_ms.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ms.msg.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 dc49bba38dfd26b7ff055b33e1d3d424
SHA1 2d57ea15dd7d10089a315561d7d66de0d573ab74
SHA256 fe7ce80d2794fa44145d9f9b350e8d9d17804a660547f73a66494a7804411e8d
CRC32 38E6B927
ssdeep 24:bkFgQkPr0+ketkJgnfwo0+Zinkr7zMlxkXc3PTE0EKgXX/qFbbcYnaaGsdxTU5wF:bkXorPztkJfo0lnkrnGkXiPT1EKSX/4b
Yara None matched
VirusTotal Search for analysis
Name d851be6d72edf19a_connectivity.gif.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\connectivity.gif.wncry
Size 2.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4adcf4fbda4bc85f3126781edf6574b6
SHA1 48e4888f6192fbd513f969de238977501ae65be1
SHA256 d851be6d72edf19a791bcc4a69eee580eb22a664cfa45f1aefc81e43ef01ae25
CRC32 73C8D5CD
ssdeep 48:bkTi2NABzpwXnF9Clb12LFK9SnXtBfedsOQ/5aMEKmy7prJ0zFQm:oTi08SXnK2LMIuKha/mrJ0h
Yara None matched
VirusTotal Search for analysis
Name 32d1871f15ddadd2_af.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\af.msg.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3c98fcb8b14be507d821fab667cc975d
SHA1 488eb796401e831e40396fd0cff828a25aa5e31d
SHA256 32d1871f15ddadd2e278e7555af6202aceb91e3c1ed4d873636509dcab3e99fb
CRC32 928E86C2
ssdeep 24:bk6YhkSwJNy8dTFUVvROkGG/IKIERf/LKZXqBxRLWCUUkmBtTzA:bkVwy8dTFUVvYHyR39BxZhNkeA
Yara None matched
VirusTotal Search for analysis
Name efd94c0216af5fac_266.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\266.WNCRYT
Size 1.3KB
Type C source, ASCII text, with CRLF line terminators
MD5 770d0d55f33dad84fecf9d43c9b66d57
SHA1 2d3a6af96d8228e5bff088ed0ef22150e4ee71c6
SHA256 efd94c0216af5fac866de53bebd3165d7904701c5febaf807b868328a8c0dce7
CRC32 1C16F848
ssdeep 24:sgc6jJ6chW4qQ2zB8xk0kmtlOgxcKku6LC6jQgx:sf6jw2mNOPdkZVjbx
Yara None matched
VirusTotal Search for analysis
Name 72706690d85a3d42_es_ve.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_ve.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 df76ed0d13ad28b3787b2033a2cff30c
SHA1 27bdc5a20981b7384e6f29cc4fde594e81ba43cf
SHA256 72706690d85a3d42d7cad6a2c1a98927eb7d312b5f22798b94802acfc94d8134
CRC32 598FDAA7
ssdeep 12:bkEXVawfXWScKTKVvk7PovfqmLve8pURcRDT3LbHzC:bkSUKTKVMzovfe8pU6R3HW
Yara None matched
VirusTotal Search for analysis
Name d236d5b27184b1e8_112.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\112.WNCRYT
Size 1.9KB
Type ASCII text
MD5 e7938cb3af53d42b4142cb104ab04b3b
SHA1 6205bd2336857f368cabf89647f54d94e093a77b
SHA256 d236d5b27184b1e813e686d901418117f22d67024e6944018fc4b633df9ff744
CRC32 593D83F0
ssdeep 24:4azu8Z448VcOVczWdSVcqVcR0q4vTqBBiXCVcqVcR0q4vTqBBiaMv:46u48h0qpBBaR0qpBBVu
Yara None matched
VirusTotal Search for analysis
Name c39595ddc0095eb4_120.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\120.WNCRYT
Size 1.2KB
Type ASCII text
MD5 31a9133e9dca7751b4c3451d60ccffa0
SHA1 fb97a5830965716e77563be6b7eb1c6a0ea6bf40
SHA256 c39595ddc0095eb4ae9e66db02ee175b31ac3da1f649eb88fa61b911f838f753
CRC32 4E78A10B
ssdeep 12:4EnLzu854moKR4mtPoTckd8EnO6z3K4jwxI1LRhtm3ni8FwxIBgdE4RsMZmB0CLs:4azu8yNgyJxPEyRhonO+AjTg0Okvpvn
Yara None matched
VirusTotal Search for analysis
Name 94b629c5d62635d2_requires.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pygetwindow-0.0.8-py2.7.egg-info\requires.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 7330529e802cc34318622a5001f6edfc
SHA1 276209362f3f547192851540c2dda7f4b5651139
SHA256 94b629c5d62635d2d75af953ae8acc05e7d90ca4952a7106e1211fb560ed0bcb
CRC32 E1257D24
ssdeep 6:bkEJB4m5+DBgkz6XGV0GFHTmXBLc/oj05dnjJIaHTjxUiZCAmed:bkEf4moDBJMbGFH6BLmoj+jVzNUS5
Yara None matched
VirusTotal Search for analysis
Name 9c9ac0da393062e4_498.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\498.WNCRYT
Size 903.0B
Type C source, ASCII text, with CRLF line terminators
MD5 3801ec1949600df951a19af21adca8e3
SHA1 e639addb54f8741c9cc6d6ab48a120868cd6f5e6
SHA256 9c9ac0da393062e4fa612f5dd3e756641ba280adc10ead6fc849c8483f502f25
CRC32 5596E878
ssdeep 24:3A4EvxJhytxjhRzR5tBTGzZxUGhSnbYSnZUo:3ApZyNXZGzPBMYc9
Yara None matched
VirusTotal Search for analysis
Name c5ac28c128fb80d9_msg_32.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_32.txt.wncry
Size 712.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e5dc08e291d4d163e90a3c95a115cd40
SHA1 cb294e1d78917258843b61b5be00bf50a8546471
SHA256 c5ac28c128fb80d9a51e49f1205e2f402834f1626942b85612b46e18f0550348
CRC32 8404F0F8
ssdeep 12:bkERsnKP94FRTQbO6SJj2R709YlGqgsz5oer9n9o+dUlO/8WC0tCyqSD5I5cxJAC:bklKFsTwVSZ26Yl/zoeZn9o+z8WC0cVa
Yara None matched
VirusTotal Search for analysis
Name ee3e1212dbd47e05_716.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\716.WNCRYT
Size 24.0B
Type data
MD5 b623140136560adaf3786e262c01676f
SHA1 7143c103e1d52c99eeaa3b11beb9f02d2c50ca3d
SHA256 ee3e1212dbd47e058e30b119a92f853d3962558065fa3065ad5c1d47654c4140
CRC32 6025C71D
ssdeep 3:ill0:il
Yara None matched
VirusTotal Search for analysis
Name 54b96b6c92fcac8a_tclconfig.sh.wncry
Submit file
Filepath c:\python27\tcl\tclconfig.sh.wncry
Size 7.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1d830a9bd899b1cf4879d9ea7061cedc
SHA1 2aed8316299edc0fc78094553b845e98f146d562
SHA256 54b96b6c92fcac8a3e188a463410261ab3bda1e6b5873a5742d1f194cd579f5b
CRC32 5C374351
ssdeep 192:EYC3cBXflNd9BMzQ0B8MqPSPccTarF363y7W8z:lC36Xfl5B0Q0B8VSP92JSgW8z
Yara None matched
VirusTotal Search for analysis
Name 36cb7cca5a262c77_703.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\703.WNCRYT
Size 79.0B
Type GIF image data, version 89a, 12 x 12
MD5 483493cacb6af1a40c9250a85b53cf76
SHA1 48f9428bd056e4f2eb286937a8fa812fe39385b6
SHA256 36cb7cca5a262c77937b45b9ed3eac3cacc85181c133c45913fac7481221197d
CRC32 7ED7B222
ssdeep 3:Ckkaaa/dNlMcyltxljpWer17kyR0dEn:Hd/d8bViu0dEn
Yara None matched
VirusTotal Search for analysis
Name 0bbfe9f8ed169889_eu_es.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\eu_es.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 1b137b74894c28a0d093667070c3b14a
SHA1 d2f120028feb61cb1273d8728ea5ddf87011c4b2
SHA256 0bbfe9f8ed169889cca70d5d0a11f76a7a223651b04d2899037891d8dd7a4f39
CRC32 9ABC1C26
ssdeep 12:bkEcm5DsF+a7Ssn7Xbb3GuGICoI3IfjHkEzBfQ3nG/MLaSlgI276FLDdn:bkhOWnXSuGQIsHhB/MLa/Ad
Yara None matched
VirusTotal Search for analysis
Name 26440d0be0c8bfd1_754.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\754.WNCRYT
Size 233.0B
Type ASCII text
MD5 841e6549feb094d818721e3a9934c8ef
SHA1 e10cbb001de6835c3a84bcc4dde8a0feeea2cdec
SHA256 26440d0be0c8bfd1bec5b7b7021ff64d8f396eb382cb62c66060c9bd52b688d3
CRC32 8A0C82D0
ssdeep 6:bCwMmtTVR2uvfEcs2xUMmtTVhVWUTjbOeTAL1LCMkLwMmtXHddO6nvEX:bHTVUuvf6BTVhVWUTOzkCXHfO6vY
Yara None matched
VirusTotal Search for analysis
Name 94b0ecdc72d91ae6_readme.txt.wncry
Submit file
Filepath c:\users\test22\documents\readme.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0e6f29a6cdd6d4bdace8f75a92e491b3
SHA1 6f97004ef9051f80211f58bb7f1de9cf5f69fec9
SHA256 94b0ecdc72d91ae653b3c23ab1413b1351862b2f480e29dc58ca6769405b7c92
CRC32 68C4F873
ssdeep 6:bkETpOpOZvAISHxKFsuKbYiYX+3gNd/YX58Sr7WYMm3RnzH4:bkE9u5ISQmufy+mX5pr/V3G
Yara None matched
VirusTotal Search for analysis
Name 92a8c68061ba1111_sw.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\sw.msg.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 df574e09df58eb5e3b71f999ebdea1a8
SHA1 740c6ccf034f3089d8654cdac54c2de5e44ee7bf
SHA256 92a8c68061ba11112e71e4ba7531e24cd19cc8b969be5508abab6646e1435850
CRC32 56884BD1
ssdeep 24:bkOXGBC955uenPmFyyGX1ZUvrrdzKczZ2m8ge7MItfbef0IByvYDwps8N5OFbbd:bkFgHNnPmF/GEvrrdzKwJe7lcqYkpTwP
Yara None matched
VirusTotal Search for analysis
Name 45a448cdc133631a_fr.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\fr.msg.wncry
Size 3.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 92c0965307fc908b32bcd74539cb406c
SHA1 3f57bd47b55dc065a58b2c1eec0043fab1e12376
SHA256 45a448cdc133631a92dba07d8dcdc121a02ffe5a0403eb7af31cb29616b992a7
CRC32 32C7544E
ssdeep 96:ohC5ZymeXIQE2ppbIqXxJSVRUfhyv31B55bVLOXjPnV5+IgkH9:oC7mX5fpbIqhjpC39krVu29
Yara None matched
VirusTotal Search for analysis
Name 5c7f6ad1ec4bc2c8_m_chinese (traditional).wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_chinese (traditional).wnry
Size 77.5KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 2efc3690d67cd073a9406a25005f7cea
SHA1 52c07f98870eabace6ec370b7eb562751e8067e9
SHA256 5c7f6ad1ec4bc2c8e2c9c126633215daba7de731ac8b12be10ca157417c97f3a
CRC32 62567C2E
ssdeep 768:SDwtkzjHdLG2xN1fyvnywUKB5lylYlzlJpsbuEWeM/yDRu9uCuwyInIwDOHEhm/v:SDnz5Rt4D4
Yara None matched
VirusTotal Search for analysis
Name 3c6fbe2b848cd17b_msg_06.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_06.txt.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 8bf7b26418c7b204d7df58aa3655e61d
SHA1 5c8dfef08922b9c36e4a6cea42abcf8353ed29de
SHA256 3c6fbe2b848cd17baf1f859442917ad089ed5c00701165aaf8626c1b54fb146d
CRC32 D7467665
ssdeep 24:bkmJdonbFldgEcMhoIGu4CgZifhxTiyxpxAUrCbNZg887iwDPLtlyK9SFb+C:bkOk9vcMhIRCXfvxpxXOZg8EDbz9ebp
Yara None matched
VirusTotal Search for analysis
Name 8f89379c0fc7bdaa_previews_opt_out.db.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\user\current\appdata\local\google\chrome\user data\default\previews_opt_out.db.wncry
Size 16.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3b5201a18e1aa4cd0cc44f313e918a2a
SHA1 c26f0e793e6c004b09518b1024b6eda01a79c3a9
SHA256 8f89379c0fc7bdaa4fd11ebcf174aff4166e2d39453c962cf2dadd5515fa6006
CRC32 695B05B0
ssdeep 192:LPjpqJSvZazYPLamBmizCtrWhoXhNRMdiBRbubz8SXCrc6PKq/0LNnQb0UUFOdn+:na0eQWRUdiBgXXCrYq/10EfcQ0+J1M1
Yara None matched
VirusTotal Search for analysis
Name 8bc1a431896adc9f_225.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\225.WNCRYT
Size 1.1KB
Type C source, ASCII text, with CRLF line terminators
MD5 3e68d396b3e0d7f4ff02a7753b4b37c4
SHA1 42e611a9842d525fa769a1034968bdd8f0bcae63
SHA256 8bc1a431896adc9fc1d6b57327c9f142b98ca9b09cb96b9f799baa5330e9e84d
CRC32 7C10484A
ssdeep 24:Kfw/cUDt4jvcW3OGIkcrLz2OtxmDVExtJTg+Tjcy3Vl0P+y3ltO:yw/DtUcKWpX6OrmD8tJU+Tjcy3EP3ls
Yara None matched
VirusTotal Search for analysis
Name 25f1cae70b5ffe98_page_embed_script.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\page_embed_script.js.wncry
Size 504.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e9ad368a9abc21ea74324f644d635edb
SHA1 423efcc36ac863bcb4d78d93c7e2af256d971896
SHA256 25f1cae70b5ffe9823c11a7afb7baf92eefd2d7ed9837576ac8ff974a3db7bf3
CRC32 46499398
ssdeep 12:bkEZF3xSQPHLsoyuuPIRZvMSOypdDU+2kNnSV+Iqn:bkGCQPYoy/FynPGV+Iqn
Yara None matched
VirusTotal Search for analysis
Name 793420e8d0f829b0_WelcomeFax.tif
Submit file
Filepath C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\ko-KR\WelcomeFax.tif
Size 88.2KB
Type TIFF image data, little-endian, direntries=15, height=1056, bps=22864, compression=LZW, PhotometricIntepretation=RGB, width=816
MD5 5874da41ce3869480b695461cf5db2c5
SHA1 7cbf74fc46422891de95884533e1f1ebeb8d7759
SHA256 793420e8d0f829b02354b5f000ce67b55303bb87c3fd1c51d51d23f22d3386c9
CRC32 F120959C
ssdeep 1536:fWu1ifZZrYTngebR0Sl/JX+RlZLtrcOq/QJsyn4UwR9HCrA/5CHMW:upcTgeN0auBKOwRK4UwO9H5
Yara None matched
VirusTotal Search for analysis
Name d13f073432749486_45.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\45.WNCRYT
Size 1.0KB
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 7af82a765496b841e51844efdb4d26ed
SHA1 f6b65be21d499ef7272dd6fccc19af563f22c263
SHA256 d13f073432749486fe695b446d3b1ab4be990d60c71db6ad36af48ec9295b271
CRC32 7EACD8E4
ssdeep 24:SENirrQXmXlLt6jllqFB9MKlqyXbg4dUbXmoSENirrsllqFB9z+Xbg4eWn:SqKrxXlslkB90Ec2joSqKrslkB9zocgn
Yara None matched
VirusTotal Search for analysis
Name 5b7af05fa928568d_317.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\317.WNCRYT
Size 6.6KB
Type RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, stereo 11025 Hz
MD5 1279235abb00e2bbd25f33be9b13c06e
SHA1 d238db180dbfc35fd028daf15dd87656584927a8
SHA256 5b7af05fa928568dc9dbf39845da83a48720e019214a0f250aa5e8de0ebec4bb
CRC32 B45F52CF
ssdeep 192:BJ3rYC1J5ygdII9JdTMcmht4vSH6eG2/sJ7UGmY:k6JogdNB4cGVaeGhn/
Yara None matched
VirusTotal Search for analysis
Name 04ff727324f30133_html40colors.txt.wncry
Submit file
Filepath c:\python27\tools\pynche\html40colors.txt.wncry
Size 552.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 279cfbfa4b33d78827ec0d1568c0757d
SHA1 d0f3c4eb1b0ece52f3494e7f95929a1fd96516ab
SHA256 04ff727324f301330c897ef6f2401fe75ed5a46941d77a4cb5b545378199cac4
CRC32 9211E9BB
ssdeep 12:bkErgyr5Yf/EUHt6PxyJBT6edK3l/Yln0o8THe76wfcIu5QiWTeZmqrUWK:bkEy/3t6JyfhK3tYV0od6nLZmqQWK
Yara None matched
VirusTotal Search for analysis
Name 122a06d4b0393529_cast_sender.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\cast_sender.js.wncry
Size 48.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6cccd02e25f5ead70fd5751ab3ba63c0
SHA1 f17b28d2108855e06ab8a5508fb6e7205b8711fd
SHA256 122a06d4b0393529a3b1ae61fb0c3fc840f76087879205bcb55edad1e6e5a972
CRC32 2534EE92
ssdeep 768:7yhOAa0BY7Ir3LLTs2+rIfDKIYzHH7IxCd5EpBBWgUZCq6HV8iWDfuulRjIXtqti:7d0QInsxrIWIGnN5EEggCFbOf7RjS5r
Yara None matched
VirusTotal Search for analysis
Name 3298229740ea08ee_es.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\es.msg.wncry
Size 4.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 191ebe79021374268c5d9abf6bb93529
SHA1 2cff891ea490eb000ac00742f8944d7bcddbe6db
SHA256 3298229740ea08eea4bf0ebb3e1e00be87a7299b46515ea6124d2c162dc4a65c
CRC32 5BC923E5
ssdeep 96:oYnU6aOGz5N3FXYt/lzC7gZ+lB/cQy6yt6OHzlQ:zGD3dYtBC5lB/G6u666
Yara None matched
VirusTotal Search for analysis
Name 325a2b399f7ea1e9_507.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\507.WNCRYT
Size 586.0B
Type news or mail, ASCII text, with CRLF line terminators
MD5 e962c8ae318036ea68a574ca080a9e70
SHA1 1690d78f1fef7645a367e15dafd35a6135c397b7
SHA256 325a2b399f7ea1e9762ea4df254fd932777defaff75e1038feef6e3d2d2b8f97
CRC32 545564AF
ssdeep 12:7rXmMQ8e4bcJUkeuAc5CQKodsTdCQJCTWKwdxyn:7rXmf4b43eod8dlJ3dgn
Yara None matched
VirusTotal Search for analysis
Name d39762f4289c0aa3_602.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\602.WNCRYT
Size 767.0B
Type ISO-8859 text, with CRLF line terminators
MD5 c84bc6c03710bc30282d3525dcc3bea9
SHA1 39e114da47c766a4136c62eba5c1ced8087538ab
SHA256 d39762f4289c0aa308808933bec6c900aecc713a060187832178f61f05856fac
CRC32 86D37FB2
ssdeep 12:tFV36/0aIocdi3n69LJwift5dXRk0jDj5GwWmEPBYNQGltSHPBSGgZtXvygGGMXu:tFVbagi38LyidBkmhGwBQ+tSHPBITXqi
Yara None matched
VirusTotal Search for analysis
Name 49cf452eef0b8970_90.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\90.WNCRYT
Size 1.3KB
Type ASCII text
MD5 4c5679b0880394397022a70932f02442
SHA1 ca5c47a76cd4506d8e11aece1ea0b4a657176019
SHA256 49cf452eef0b8970bc56a7b8e040ba088215508228a77032cba0035522412f86
CRC32 61E8BA98
ssdeep 24:4azu8f4sO4fETEtd3N5EPIK+kJQz3R3VJ2PYYITCF3eYGCvt2/v3eG:46/ETKN5EPIKfsxV+pBtMJ
Yara None matched
VirusTotal Search for analysis
Name d563f1626b2bb49f_310.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\310.WNCRYT
Size 2.5KB
Type PEM RSA private key
MD5 6ddbe31400acfe2ce8461b557e502b7f
SHA1 4aa659b0d38b65a53701c96a12115f2494c6874b
SHA256 d563f1626b2bb49f6c3ef0122525fcd549032856a570de8d30faa77eeabf1fe3
CRC32 C340A99D
ssdeep 48:LrHwmuDW7TDCoyjx5/YDQsjS2/xOUX1y5MEAn0o3DtrEC:LrQm+W7TD7OID3e8rUVo3hEC
Yara None matched
VirusTotal Search for analysis
Name c5c19ed07a597eea_msg_23.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_23.txt.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 6278b6449e980a7059c6dfce558495ba
SHA1 8345a0b7e680c752e71faa9e48bd197c1203b8b0
SHA256 c5c19ed07a597eeaee8277252b0845cb3123a865a4f822216920e4486754cad4
CRC32 AC0351A4
ssdeep 12:bkEiOtOxv+DUPeUeS8mzWk0utMHQpK+A4ln73A:bkCtOxv+ueU6edOHQg8nc
Yara None matched
VirusTotal Search for analysis
Name e7ba2f7a95679695_147.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\147.WNCRYT
Size 3.6KB
Type ASCII text
MD5 2c904d110ba900583a86838ae264438c
SHA1 cc7c444bda43fd5ebe0b00f68bad42e7dfb816c2
SHA256 e7ba2f7a95679695504164c92b86b92ab5f7d08dcf34029e391c1683ac9ff5f3
CRC32 320FC783
ssdeep 48:fkErYNxfhFBqFHjApxKSOzbgRujzSAEFlBGr3jd:fkErYLpaV0KSHtXcN
Yara None matched
VirusTotal Search for analysis
Name bee07f14c7f4fc93_675.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\675.WNCRYT
Size 254.0B
Type ASCII text
MD5 a3b27d44ed430aec7df2a47c19659cc4
SHA1 700e4b9c395b540bfce9abdc81e6b9b758893dc9
SHA256 bee07f14c7f4fc93b62ac318f89d2ed0dd6ff30d2bf21c2874654ff0292a6c4b
CRC32 5D0C5368
ssdeep 6:SlSyEtJLlpuoo6dmo5VsNv+9/Lo5VsU3v6rZo5VsNo+3v+6f6HK:4EnLzu8rVsNvWiVsU3v6rAVsNF3vmq
Yara None matched
VirusTotal Search for analysis
Name f666f0b67263cf14_uk.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\uk.msg.wncry
Size 2.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 25f1d07510d1acab04dd191ebe07f0fb
SHA1 9603b19a6d5578d4713c7cfcf8a5a395210befa1
SHA256 f666f0b67263cf14de628bdaf356b2f4956b14726a3ca70b71a9beffb9c9f8bc
CRC32 E9F7E478
ssdeep 48:bkqmYj2tbl+mKiaOB93r6grKd2NmytiWYKbIInGfX4qRc9ItACor:oqmYj2t5+QaSdr6holskCXhRc9K3or
Yara None matched
VirusTotal Search for analysis
Name ba6bf0c91af412f5_he.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\he.msg.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e564fc861d74ef32e34accd15d829b7a
SHA1 1a712e1a21033a7b6dadac7dc00a8fd78a5d481d
SHA256 ba6bf0c91af412f5f1ea7f319d28c2160e3414f1b164cb42869e139497d1557c
CRC32 017BBCA7
ssdeep 48:bkI56UVLOv/1cTaf/rw5hTQpm3Nd/rJeA:oIAU1WqGfjwLyGNZrJeA
Yara None matched
VirusTotal Search for analysis
Name 1a8696be83f0985b_cp73a0ug.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\cp73a0ug.txt.wncry
Size 472.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 29d16212c7216b9a05ad71d8354a50b8
SHA1 2eaa7b2964e47732bb64e0f4565b24b8c62a94e9
SHA256 1a8696be83f0985b4776b38589f18449054d4afe132497965ebd6719661a819a
CRC32 5C485992
ssdeep 12:bkEua8AKy1IkhQBSKDMfU/sEMkGyzvGZmEmi:bka8AKKIkm+f/jyzuM1i
Yara None matched
VirusTotal Search for analysis
Name 789f6d625252d856_es_hn.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_hn.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e3d65a912bc3f0fc0651fa4b86b33ccc
SHA1 b2281a8dd7177415117f3d4ff4fa332ddc69c2f0
SHA256 789f6d625252d856e8210916040b71068b56d4762a2a99dc50c746a81cbf821e
CRC32 920E1E70
ssdeep 12:bkE0+435ysLWh5LKyApP2/kbLm9eZgZIxkQ5JM8Qq:bkZb5ys22y2P9bzgMXc8Qq
Yara None matched
VirusTotal Search for analysis
Name ed38782ae7170208_500.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\500.WNCRYT
Size 567.0B
Type C source, ASCII text, with CRLF line terminators
MD5 355b94816641a526661001725b8e5064
SHA1 7f31cbb7111bff609ec3ffeab9acb8727d5f1977
SHA256 ed38782ae7170208bcb094faf3152e2af231c2a51066b76c540bcdf03cae327e
CRC32 05B8579F
ssdeep 6:U/OrwtRmgPfUQ0y0jQ6zF8VrHMEDRKF0OaQYEScFKIOvKCyeq+hFCUrgGCe78oet:UWCZPc9KdX4rjOCPeRO+tm
Yara None matched
VirusTotal Search for analysis
Name 9e7582c1f0b0b3b5_179.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\179.WNCRYT
Size 6.3KB
Type JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 640x480, frames 3
MD5 ef7814883cc6b5a7428da53edc7a1c35
SHA1 88df4f08fa67f940681a53630fe2490d2fdf97b5
SHA256 9e7582c1f0b0b3b5a0704dd0c04dea6b13ef47caf69a94fff5c96fcbcf48b3ef
CRC32 4BE9CFEC
ssdeep 96:bwrWMic+ooX3MnMYHoQSc9/IyX9PIFHnUAf6OEdnsN:boiyoX3H0DSc9g2gHnJf6OJN
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 158bae2f9a914912_454.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\454.WNCRYT
Size 53.0KB
Type Microsoft Word 2007+
MD5 150fe19f9cd10774e879e9547b879b2e
SHA1 288c054d85cb12643ad158769bbf66d7cb2c36d5
SHA256 158bae2f9a914912aeb60a78485c826c5e0f0c57f969291e5e371826906753f9
CRC32 6A4A5D15
ssdeep 768:VfJurP6njKAsYHc7Vlee6Bjfe83nx3CKyx+htEL:aj2rH0Vl0BjegZCfxEQ
Yara
  • zip_file_format - ZIP file format
  • docx - Word 2007 file format detection
VirusTotal Search for analysis
Name 4c8c35cc382762bb_cached-microdescs.new
Submit file
Filepath C:\Users\test22\AppData\Roaming\tor\cached-microdescs.new
Size 14.2MB
Processes 2592 (taskhsvc.exe)
Type ASCII text, with very long lines
MD5 06af7d0a66ed04582f3ca5a201e004b4
SHA1 c68e2ce1990b48115eae2b54e3eeeb7530aef698
SHA256 4c8c35cc382762bb738ffd1c993542e9db5b57a86ba8f9cb6400ffe228e03f26
CRC32 56B8F17B
ssdeep 24576:NIpIHVThgOIjvziWIEfSdIeCzT9S26PwgOgW2RHKs03jYqEQcmd2VLEyzSSKqakT:3UFLE+DYx0xGOT69PgPLtM
Yara None matched
VirusTotal Search for analysis
Name d790e54217a4bf9a_86.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\86.WNCRYT
Size 2.1KB
Type ASCII text
MD5 1a3abfbc61ef757b45ff841c197bb6c3
SHA1 74d623dab6238d05c18dde57fc956d84974fc2d4
SHA256 d790e54217a4bf9a7e1dcb4f3399b5861728918e93cd3f00b63f1349bdb71c57
CRC32 F02B60F3
ssdeep 48:46dJRQPQ86AK0xQuEQS3oQsDptuCrQICZmQ8ZVDtN1QFqQLtCSjZMpktvp:hdP6HIZoFnl1Rgx
Yara None matched
VirusTotal Search for analysis
Name 5786bd08a61ad0d1_textfile.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\textfile.gif.wncry
Size 360.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 c71e336a7914006fde9dd033b4760bf0
SHA1 672441ca0e45bdf0e62ee8086d2a5c73fd25e231
SHA256 5786bd08a61ad0d12c7daa008b686f7ec7db9a832d79c148159b1f34d48017b6
CRC32 15510168
ssdeep 6:bkED6xvKvuWqq+iWG2pyEa7Ya+65cAX1SDh2u2njIHjs3y1wI7XmqbjWzpHV2G3q:bkED6xv0uY+iWsTU165crDguyjIHjv9Z
Yara None matched
VirusTotal Search for analysis
Name c2b2e8098aaa63eb_msg_33.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_33.txt.wncry
Size 1.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a61ba5cc0d7f20b615a007f3f6560d5a
SHA1 3ff020771a571fd57fd33b84871dbfc0644176ae
SHA256 c2b2e8098aaa63eb54a5ca88e775b1d4eee4b9c0747448ef2a3f182be8b91a07
CRC32 B9022DD2
ssdeep 24:bk8UGBCEh8MS0DTqIw6iICu4MltW3qQI91TEUWBllp9Q9OuXDhzA:bk8UGBCc8MfTLim4woaQIDcTmDhzA
Yara None matched
VirusTotal Search for analysis
Name 3f191f850b206800_494.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\494.WNCRYT
Size 271.0B
Type C source, ASCII text, with CRLF line terminators
MD5 529a5dc15c8111178c4aa1cade18da1e
SHA1 8e14c9e45927c4030859cf2db0e2b79e61c315ad
SHA256 3f191f850b206800a02d831df69c60be486b5a590ba3746aa74c3fd326f419bd
CRC32 FDBC62A3
ssdeep 6:BeXWAQ0t5jQ6zFMSy+KopmcBZUeVaFuAcRdQ6r5jQ6dnc7v:BeGAPu7LenAsLiv
Yara None matched
VirusTotal Search for analysis
Name dcb216d5201fe012_intobject.h.wncry
Submit file
Filepath c:\python27\include\intobject.h.wncry
Size 3.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6dd6e01389c9bb84749611f39818bb0d
SHA1 91182574a3933c473a5a78c90ee1c18c3c55d694
SHA256 dcb216d5201fe012d8843fb8c94fcddecab7e67c9eec806f1e4c7f11ec291635
CRC32 FACE3BF7
ssdeep 96:orKeKfuWflegDQYpKjkKeYEgc84vZLQz7g:SKrfuovDppjmEgmBcz7g
Yara None matched
VirusTotal Search for analysis
Name 84a4da0e4c52c469_170.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\170.WNCRYT
Size 762.5KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, datetime=2009:03:12 13:48:28], baseline, precision 8, 1024x768, frames 3
MD5 2b04df3ecc1d94afddff082d139c6f15
SHA1 9c3dcb1f9185a314ea25d51aed3b5881b32f420c
SHA256 84a4da0e4c52c469ace6e0c674a9144cd43eb2628c401c8b56b41242e2be4af1
CRC32 E3E8BA49
ssdeep 12288:OqWPGZU9GZxnB4ssVV32HAnCuyaEYVcDsDRgzK4mVt1rIQcU+cp4V1YzSl6JPGV:NWPYU9GZxnBGVV3dSYVcD+ReTmH1FcUG
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 898af92c8e8d1f75_codecs.h.wncry
Submit file
Filepath c:\python27\include\codecs.h.wncry
Size 6.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a39dc2d9b447c4b6821dcdc65634c100
SHA1 e50a3d72f9d36531e2ba262fa9d1d580e706f14d
SHA256 898af92c8e8d1f75da4787b767783b2ca93894e46df38598492fbfd0c61c9d38
CRC32 79176EF2
ssdeep 96:oVgI6z4C5WLEDSnFEq1u+Mzs7cfJL6mN6VysITWMcgTLN68MEPrFxb/m9AcOp32:8f68CornF31u+2dn/sEVc8MEPrIo32
Yara None matched
VirusTotal Search for analysis
Name fee7117f5262fbee_pwrdlogo175.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\images\pwrdlogo175.gif.wncry
Size 3.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 091b2d62ea0cc4b55c270b2a5184fb8a
SHA1 b756557c421ba021621d7dd57f7c07b47fdd98fb
SHA256 fee7117f5262fbeeab750ac3a0f81729c6439973f2755a852e5ef2d725c69159
CRC32 817AC4DE
ssdeep 96:ocxRbu9Auld3/eAciazxuCTdsHBsV1FbH2paSNP63:P89AsdPbc7+GKNP63
Yara None matched
VirusTotal Search for analysis
Name fbe10c0c7d282e31_298.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\298.WNCRYT
Size 2.2KB
Type PEM RSA private key
MD5 598ea3255fb276209072332552903ed8
SHA1 ccd234d34d488634569a4064a65d643e070e80ed
SHA256 fbe10c0c7d282e3136341735aa4a5716f2c32133828bca64f700c572d7492550
CRC32 1A6F67F1
ssdeep 24:Lr4JlIgc0z1qwQMxwBvJ8dWSCRWAS/43G80xwda324JlIgc0z1qwQMxwBvJ8dWS6:LrYcuwZJ8WWAS/4C+YcuwZJ8WWAS/4Co
Yara None matched
VirusTotal Search for analysis
Name 52542733943a17c4_275.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\275.WNCRYT
Size 6.4KB
Type C source, ASCII text, with CRLF line terminators
MD5 b24b767171ab529e43394f6295a3cbe7
SHA1 1ca2b2c430a11f9e60a71c8efa7b1a1e7dba2900
SHA256 52542733943a17c49c260ed4ae2a51e44e7f408ee2d85d558455da9bfd962d4b
CRC32 69566AA8
ssdeep 96:/KaU4ebdRkU5mToPhq8zq7PhRHoQghMY9/ZpVj2uURd:/KzHR5mTAhqQq7PhRHo1ZHLyXRd
Yara None matched
VirusTotal Search for analysis
Name feb4c6fe856ac3e6_python.bmp.wncry
Submit file
Filepath c:\python27\lib\test\imghdrdata\python.bmp.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4e6096d128cf507a118f8420734e3b31
SHA1 f8852c697a6659f55848f8a4b38d54a27ebc0b46
SHA256 feb4c6fe856ac3e67bffa4dc840fd3de0d8a413c7ba0bdb99b50b950f969e71d
CRC32 D54A5BF6
ssdeep 24:bkQJD46hVK0qRps7HAuOj8qy/dAYtFgPEC+VCcpiW1vgUmTk5FW7GiyGCE:bkezcmguOj8X/2YtE9+rpNlP5KGOh
Yara None matched
VirusTotal Search for analysis
Name 21895a92c2a24cbb_726.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\726.WNCRYT
Size 95.0B
Type ASCII text
MD5 55ddc934deb1b6ff32131cbf21c69aac
SHA1 c905665276ff5dba2d052ad4c11588c3172f81f8
SHA256 21895a92c2a24cbb59b7eb59392ce324d7dac74f7f6354083a14e69763e9747b
CRC32 875CB127
ssdeep 3:yLR9dBkADF2vRtP3uwVQokBYGi6YrQIHev:yL7YmgmwVQWB6YrNHev
Yara None matched
VirusTotal Search for analysis
Name e737d8dc724aa3b9_87.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\87.WNCRYT
Size 1.8KB
Type ASCII text
MD5 11fa3ba30a0ee6a7b2b9d67b439c240d
SHA1 ec5557a16a0293abf4aa8e5fd50940b60a8a36a6
SHA256 e737d8dc724aa3b9ec07165c13e8628c6a8ac1e80345e10dc77e1fc62a6d86f1
CRC32 2002B606
ssdeep 48:46scAXuQfuQVoQAWN5EPIKfD8WQjQ3QgQaQLSqQsQGtQWCQMmt1f:hD/zQaPIKfTSiF3KVfVCqp
Yara None matched
VirusTotal Search for analysis
Name 31a4b74f51c58435_676.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\676.WNCRYT
Size 346.0B
Type ASCII text
MD5 9c7e97a55a957ab1d1b5e988aa514724
SHA1 592f8ff9fabbc7bf48539af748dcfc9241aed82d
SHA256 31a4b74f51c584354907251c55fe5ce894d2c9618156a1dc6f5a979bc350db17
CRC32 0C8B6AEF
ssdeep 6:SlSyEtJLlpuoo6dmo56SFZhjNo56m5Ybo56TGMZo56a/W3v6mfvLo56TT+3vOAEP:4EnLzu8r62vjs6m5YS6TGN6a+3v6o66J
Yara None matched
VirusTotal Search for analysis
Name 4b1d673ab618b0ea_36.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\36.WNCRYT
Size 10.0B
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 3924b02bc1bd68a95a864e70c2b63d8e
SHA1 c79228bcf701707d6b1bcceef3416dec9c4c9c23
SHA256 4b1d673ab618b0eabf51b9b7598e85bfac3a373a25b32153787b27c566ddbee8
CRC32 025575FD
ssdeep 3:UBSpt:UBw
Yara None matched
VirusTotal Search for analysis
Name 47d255536046ace0_compile.h.wncry
Submit file
Filepath c:\python27\include\compile.h.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 516148f86b59eb7f73cbb509f557fd12
SHA1 04b27e8113057f13de00207b59664089accc3c02
SHA256 47d255536046ace07b8b860fb3f0116e0dae333e461058102ce3e52f071a6811
CRC32 4A2E90A0
ssdeep 24:bkclk3IXVqbZco0Wfsy6ft3t6ZHTpd5iSs13rI65akitkFdq+f9V1u4dMnZP3NVC:bkcMIlqbZco0Fdl3yd5iSa386tXV1xM8
Yara None matched
VirusTotal Search for analysis
Name 94ff64201c27ab04_653.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\653.WNCRYT
Size 251.0B
Type ASCII text
MD5 d24ff8faee658dd516ac298b887d508a
SHA1 61990e6f3e399b87060e522abcde77a832019167
SHA256 94ff64201c27ab04f362617dd56b7d85b223bcca0735124196e7669270c591f0
CRC32 D4E2C911
ssdeep 6:SlSyEtJLlpuoo6dmo/5UFLovE3v6rZo/a+3v9f6HK:4EnLzu8XUF13v6re3vMq
Yara None matched
VirusTotal Search for analysis
Name 024edad688355bf9_normal.dotm.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\templates\normal.dotm.wncry
Size 20.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1349633942a246102e4822965b1a508f
SHA1 cc4505b4a0e3c88e6148fb6a9809dcef42b3526c
SHA256 024edad688355bf93f6d76c282e09d78166ab6d352671e02108f936663f9a6b1
CRC32 32BF5B4D
ssdeep 384:YDOAYOEG5yt0+RexH0zWbiuiNWj5X0m2WD2bQ9OO+/T/ALpx7Li:+L5I0+RhWGuMy5X0dWDLOrT4bi
Yara None matched
VirusTotal Search for analysis
Name 98ce9ca4bb590ba5_637.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\637.WNCRYT
Size 245.0B
Type ASCII text
MD5 f285a8ba3216da69b764991124f2f75a
SHA1 a5b853a39d944db9bb1a4c0b9d55afdef0515548
SHA256 98ce9ca4bb590ba5f922d6a196e5381e19c64e7682cdbef914f2dce6745a7332
CRC32 0512673C
ssdeep 6:SlSyEtJLlpuoo6dmoOr0l5oOK3v6wLoOs+3v0l6C:4EnLzu8WL3v663vlC
Yara None matched
VirusTotal Search for analysis
Name f895bc131d293795_peacock.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\peacock.jpg.wncry
Size 5.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7aa65b86871e6d559e8290f32cea7e81
SHA1 308d01bbe176e2fb0739a413da0167e451f552f4
SHA256 f895bc131d293795b5f84016170591342102e32bf04126a9bd7f6f0c3af65bed
CRC32 92BF4298
ssdeep 96:oz8P3QrJ7x6iUZYp3pfA+Mp7g6ekCaJkytAmRaaq0/QQp/CFsP9XD+O+p6h:Y8WR8i71ipNXZJkI4F04QxPh2I
Yara None matched
VirusTotal Search for analysis
Name ecf4aab1f35c4297_msg_13.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_13.txt.wncry
Size 5.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 90f568e3a7dcae0cf614353e1e193666
SHA1 06adba97058d2b5b2ed73afcea3108d144536339
SHA256 ecf4aab1f35c429743b05f781c9572f7fed609527520d2655f6c99ee361c5835
CRC32 5B2FDD43
ssdeep 96:oXRfjSD2Piu+sUzJYf2GYjBqjNYPI8mY06zjlACyA+fQftd+7vDZ3fVQLKXAsfki:aRfOKqV9owpVm8sYs3fimXA+k10/9z
Yara None matched
VirusTotal Search for analysis
Name 11d1411baa1d63fd_patterngrammar.txt.wncry
Submit file
Filepath c:\python27\lib\lib2to3\patterngrammar.txt.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d52808e22232614c290580b415e6a361
SHA1 0c6b73438a304e5f67241c7a15e0fb50b7e2f9bb
SHA256 11d1411baa1d63fdb1f874672f9fc56c0bc61cafeee3341c58831fd500be20c6
CRC32 FEC8D682
ssdeep 24:bkpt91PnND5YifWKlVwh3uj3ZqxPHmJe13h58sweE:bkpt91PnNR/saqxPHmJ030RZ
Yara None matched
VirusTotal Search for analysis
Name 72be28f80907c4a7_msg_04.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_04.txt.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 57036822ebd20b10236ce29dd500a467
SHA1 f3948e699eb947a49900153e4027a9d33ef4eb92
SHA256 72be28f80907c4a7d3cc059609fe20ea600550537a74b578808198c7a18af4dd
CRC32 F4BDA0FF
ssdeep 24:bkvu0UkPWMlkNPkuoKWj3V8mWGK8A/jONJnAw3T3qQwCxYB7:bkvlUkPWMlk+ubWj3umWG3PJAw3T3q2W
Yara None matched
VirusTotal Search for analysis
Name 4f1184d1e22d87cb_es_gt.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_gt.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 cc7220a35003c50a33f21ea9132c4794
SHA1 a8e7b941a6dced2ed7b010aa6685558891e194fb
SHA256 4f1184d1e22d87cb5d976a98809f3983511a27d4c59fdb2d4c1f126ae43bdf63
CRC32 6A3BDF26
ssdeep 12:bkE8TCEUqcYKbR4j/tYVNjtRBuGeU4EmvITwjKoKOefIvWBDN5tXjup:bk2EHY4j/E5tnsU4Pv//vqN6p
Yara None matched
VirusTotal Search for analysis
Name 010f60d2927a35d0_167.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\167.WNCRYT
Size 826.1KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=6, datetime=2009:03:12 13:47:43], baseline, precision 8, 1024x768, frames 3
MD5 ba45c8f60456a672e003a875e469d0eb
SHA1 30420d1a9afb2bcb60335812569af4435a59ce17
SHA256 010f60d2927a35d0235490136ef9f4953b7ee453073794bcaf153d20a64544ea
CRC32 197626AC
ssdeep 12288:QmOrX1Zu6DXAS9qTHMinPziabcH0FkTc8+RCnLFB27OKpGe8Z4qrzvPkhZ:m71ZuWASuMinP+rTc8+RCLhNvq
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 69ef7c7b54c715c0_519.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\519.WNCRYT
Size 396.0B
Type news or mail, ASCII text, with CRLF line terminators
MD5 5d0ac048fc93da51e0cc9f2dd7fbff44
SHA1 1f31adc19275b3912fcf7687bb2cc2ebe16b2971
SHA256 69ef7c7b54c715c07694c6b9be274e4bd3311c19160db77981a453bf2569659c
CRC32 509E0625
ssdeep 6:BYLCWAQ67JLvjDPaQ8KMW0Y0aoXmMWdwy0baQ8KMW0Y0aoXmMWdwkBw8FDW:+L6QcnPaQeaoXmMW0baQeaoXmMoBFlW
Yara None matched
VirusTotal Search for analysis
Name 89d48f5833932bdb_credits.txt.wncry
Submit file
Filepath c:\python27\lib\idlelib\credits.txt.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 71ef72a27a19d74415785d114f5f17ba
SHA1 0db2e78c375e63cbf5c283af3053c939d55d18e9
SHA256 89d48f5833932bdb71cd831e35520dbc43efae68d9307082fb8e1a5d07278bda
CRC32 0D09F894
ssdeep 48:bkV6Tatr/PaAd3Y9aMXPynIKzHN+PB/BFoDeEAJokRGqnpP3Uf:oVFPaGMgIKzHM/BQe7hMqpPEf
Yara None matched
VirusTotal Search for analysis
Name 381f558949d5492c_pycapsule.h.wncry
Submit file
Filepath c:\python27\include\pycapsule.h.wncry
Size 2.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a599edf0f9abddde782a84eff54e8635
SHA1 b4523ea85a50b28aa83b021f234930e29a8b0153
SHA256 381f558949d5492cf2d6cf8f47aacb98cc8da999da2c88f4feb073948d1201b3
CRC32 BA04DF8D
ssdeep 24:bkH5bTLTK5nfk/0w2BivPETrfNs2VHO+3TIpZdCDZ2GXQXXF+4+75dcPQiiHK5nu:bkH5nLKrFBivPEnLHDUp3xXh+Riiq5SN
Yara None matched
VirusTotal Search for analysis
Name c7c6f3df5c8edd3a_lt.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\lt.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 edec0e7f38b7252d81017ff89361668f
SHA1 5934edb3363fa80f254f491ee988ab1e4e8d6a84
SHA256 c7c6f3df5c8edd3a2daef56a28ad81bca2dfc4d5ad2a893e1d6f1417c520fd5b
CRC32 BD070E05
ssdeep 24:bk5X20s3KFmk1R7T+lUXTDRNsgQSSyRZumTwFRRfJLWFHSjkvhfFFFTx91ZG2+uB:bkB26zR7T7TNNgS/b0fJCSQvh5TxX+uB
Yara None matched
VirusTotal Search for analysis
Name fb0676b1572270e6_f.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\f.wnry
Size 320.0B
Processes 2632 (WannaCry.exe)
Type ASCII text, with CRLF line terminators
MD5 ee765fa92dad085673f06e22701f464e
SHA1 83551b40b2f8b61009345a599380a091f264e6fc
SHA256 fb0676b1572270e6a5d10cdc5cbc8ba3d8d15b3da8801b9ee1690e19ade461d6
CRC32 5A79DDE9
ssdeep 6:o/KGLAyklVA5c/y1yklVA5WRNeqZykwOmQpcLJ23iKKdK8K1AuPiVhMxklGGfvgn:oNe/hu9OLM5KkfPi42fRc
Yara None matched
VirusTotal Search for analysis
Name 591c26f5b9a27c9d_pystrtod.h.wncry
Submit file
Filepath c:\python27\include\pystrtod.h.wncry
Size 1.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 56b6b994eabbaef3d01ad80f2847d71a
SHA1 99c9d0d9e31ac2cccf3515cc12daa3369e782e6c
SHA256 591c26f5b9a27c9d6b2a659114d120dc13a9cc777de4f48d34ab82edfa6db586
CRC32 8CE2E4F7
ssdeep 48:bkl4hd0umj1B0+GE1yJ2eNYp0U0s84cgk9r9777SBcXcN:oWdhmnDJeNYiU0ugPSBYcN
Yara None matched
VirusTotal Search for analysis
Name a431014fc1ee6605_tiki.gif.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\tiki.gif.wncry
Size 4.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5f7d71333ca215c3a4ffa12ec6172fd3
SHA1 21b40c77902569e77b70e2997e71c7cc60318add
SHA256 a431014fc1ee6605e1f57e097fc6b4ce819dacb420a4ce8e37400d9784af1bbe
CRC32 35EA7111
ssdeep 96:oHWL/JQYj5MDbvPTAhW74a9oIgcN0brZd7PvFMT59L8JBq3KS0FwMXzZRnkc+e4I:sW2sM3jca9hgcN0n37nFMTbwB80FwMXr
Yara None matched
VirusTotal Search for analysis
Name 9a8d3bc4fd5edb68_164.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\164.WNCRYT
Size 57.0KB
Type UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 69632bbaa56df25385825cd636c01973
SHA1 74d5b30ee09b12945c96503f9ac3f5d235e0041a
SHA256 9a8d3bc4fd5edb68c1dfb895a562ac47314b51c318d3ae364a00ac8880d508fe
CRC32 6370B21A
ssdeep 768:NlNVjQeP3qUNCjZrdKoFZim9OmTyqn1ska7xq:DNR6UN+Z/4m9nTWH7xq
Yara None matched
VirusTotal Search for analysis
Name 4f03b266ab7f4491_422.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\422.WNCRYT
Size 2.0KB
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 9780908f016e104f086dce7062eeb921
SHA1 dc865a9ea172685414911cc6cfbc4525e6f903b7
SHA256 4f03b266ab7f449151a9621defa437a87703f41f89c0b3d0a663dc636ff82fb3
CRC32 37319275
ssdeep 48:JBgJpAfpzIK01ncLnyaIcbdg62y6Ab+PRdlObH55yy/N:qKBzIrCdOrACTIbH5gCN
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name d293702b42b6a9f6_license.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pip-19.2.3.dist-info\license.txt.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a94f5c0c671f1ee208cb654734f47216
SHA1 f3a7cd02ab23a7845e884a5c9862dc23552865c3
SHA256 d293702b42b6a9f65347dce678213d73387cc4e05e4055073b742bddcec49c66
CRC32 76213ADD
ssdeep 24:bkoOdb5vgOwXnirakv75Ih9qs3E1f9L8n4OeNHzAGzhVkH+Cfk41YTOE0xah:bkBdb5QimvhI1f9L8nTeBzAGzhVkH+UK
Yara None matched
VirusTotal Search for analysis
Name db58b8473ce62701_complexobject.h.wncry
Submit file
Filepath c:\python27\include\complexobject.h.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3e3fd3397a87174586185942711b730f
SHA1 df112a1d658c5edbe35b86d637e73d9f58560999
SHA256 db58b8473ce627018ec86d3b9f8c23a515c2b4abbd587e029b896bcee3618220
CRC32 197FF8A9
ssdeep 48:bkUqbMlQubmicMN70h/Nu1o5P8kJiwbJc8TvOSsLDPfnJD:oUqbODSb9QBwbJpvOxfh
Yara None matched
VirusTotal Search for analysis
Name 4b993e1da2c29a7e_610.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\610.WNCRYT
Size 85.0B
Type ASCII text, with CRLF line terminators
MD5 74d6d0d09ae7b668d3a001cfc24dc927
SHA1 9449ffa0de00d0ce71010bf350d830871d4d44f5
SHA256 4b993e1da2c29a7e254e1186a2dcb3253c58f0f1474dd8836cd7910dd7af8513
CRC32 FCBB6B37
ssdeep 3:hWumyAQiascULAdRFDAQkveRBn7ALyn:hcQiascxRFcQkveKy
Yara None matched
VirusTotal Search for analysis
Name 611b4d1f209a859d_hz.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\hz.txt.wncry
Size 376.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 3300ea3ac9d910e6994cf0fdb6d34526
SHA1 d9ec73e04224b342d8ec821901cc6f34ee9b3924
SHA256 611b4d1f209a859dac58889d0defdc00e10e02e7181c79617eb4a296d9c546e8
CRC32 B2F7D5E5
ssdeep 6:bkEFv1UfW1QUDFB3fMxXYwHdaJi5gQlthE9RUS7VAzHx125orQYYTtv2nmeL4pSP:bkExefW1QaZ+Yw9G5Qtk/h2H3mUQ1Tte
Yara None matched
VirusTotal Search for analysis
Name c2d349935a7b80e3_pyctype.h.wncry
Submit file
Filepath c:\python27\include\pyctype.h.wncry
Size 1.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 11e76dad1aef98043ba225c2143c4188
SHA1 e1fed1488d06ba046bbb35c62738e7ffefa75a60
SHA256 c2d349935a7b80e3af48bade0857198672118c39d0ead3566050a7065d135a7f
CRC32 FEAD0029
ssdeep 48:bkMUxM4W+S4g4KvpfXkeHd1fNKYgSJnm3Uei4/aCW1/gRk:oMUxMLp4g42keHbVgSxqUa/v8d
Yara None matched
VirusTotal Search for analysis
Name 77a250e81fdaf9a0_libevent-2-0-5.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\TaskData\Tor\libevent-2-0-5.dll
Size 702.4KB
Processes 152 (@WanaDecryptor@.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 90f50a285efa5dd9c7fddce786bdef25
SHA1 54213da21542e11d656bb65db724105afe8be688
SHA256 77a250e81fdaf9a075b1244a9434c30bf449012c9b647b265fa81a7b0db2513f
CRC32 B62F0032
ssdeep 6144:Ir2r5rFriGKbgai112Yq/5hcQTcGzAHzSHeqoftOEEdD4B2pihSpKOKm:naiV25uQTcGzAHOEW+Pzm
Yara
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name ea32622af2e3a765_51.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\51.WNCRYT
Size 5.1KB
Type ASCII text, with CRLF line terminators
MD5 e02035411f68802f24a533eaa5980ba4
SHA1 dde285533bebcf630ddfe486fbf225e21449f950
SHA256 ea32622af2e3a7651d58dc0d6daf0befce13950e98f87387e6e6863ac0c6ae50
CRC32 33A8ACB6
ssdeep 96:tcinSWABzBo1ppHBbTNSTSSTDST7ST/STRFSTnSTMKo5z+m/avRH6:HsO/yH+Tc
Yara None matched
VirusTotal Search for analysis
Name a3fe4b1b49cd0353_578.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\578.WNCRYT
Size 127.0B
Type ASCII text, with CRLF line terminators
MD5 5ef6791e65baf439f76a265d1f85c8b7
SHA1 6edd36870a241abf17911d146637daac3d69b418
SHA256 a3fe4b1b49cd0353a2147a492cc505a1cde643675cf5d5a240064db0440b50a1
CRC32 D15AB9D8
ssdeep 3:xxGQt66KizrcBQt66KiaRjv2qw3XsRmBwAqLOIOPLrRCjF7A:M+rcftRjlw38RmyzZurRT
Yara None matched
VirusTotal Search for analysis
Name 2b3e88de6b15ecc2_requires.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyscreeze-0.1.26-py2.7.egg-info\requires.txt.wncry
Size 648.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 1ac7ceb1dec36e91af91f043cb779194
SHA1 df195df4f1a048f2a6975c1dbe299f9b5125d880
SHA256 2b3e88de6b15ecc2b9634c0b7c4b6c95a615b2462d4975391152a02c40ac3870
CRC32 D4AD9BC6
ssdeep 12:bkErKHIxdcIMNm7+4WmBivqDtoUapWf04M7gmMiwQbk45aQ4MPiOcmJwHxAuH:bkJHIxmu7mvqDFkWc7QlN45aSiOcjP
Yara None matched
VirusTotal Search for analysis
Name bf984ec7cf619e70_82.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\82.WNCRYT
Size 1.9KB
Type ASCII text
MD5 0a88a6bff15a6dabaae48a78d01cfaf1
SHA1 90834bcbda9b9317b92786ec89e20dcf1f2dbd22
SHA256 bf984ec7cf619e700fe7e00381ff58abe9bd2f4b3dd622eb2edaccc5e6681050
CRC32 BCCC2EAE
ssdeep 24:4azu8fnkFewadQxvbkMPm/FiUoAwonC9UFsvSnvMq:46dw/L+C9cKSvF
Yara None matched
VirusTotal Search for analysis
Name 0655f5b86be27c86_264.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\264.WNCRYT
Size 21.5KB
Type C source, ASCII text, with CRLF line terminators
MD5 12e553cc7a522452a52c4b43ef2d06fa
SHA1 d84581a632cf5d0d124720de0f679d52bab49d16
SHA256 0655f5b86be27c8600ab9350f6a74389abe37d0bdc9a533b90a9bd77f068c974
CRC32 E7199E62
ssdeep 384:rGbGMpOukkk8/McYuw8BsRhpuDaBUMiBaZdVsdgh3nIog:rGbGMph9TSNaaZIaZX1Iog
Yara None matched
VirusTotal Search for analysis
Name 7ef26308ed9b2f53_object.h.wncry
Submit file
Filepath c:\python27\include\object.h.wncry
Size 40.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 32d13f95fd7cf11322f7093726cb6286
SHA1 ff9bf30c860e48abe5f185769500b2ce55155464
SHA256 7ef26308ed9b2f53043dd175810659f6fa30aed4ac6b63ce27025f469d15c941
CRC32 9669E2A2
ssdeep 768:6cH/H2j0Ue2/GuZ8E5y2VqabVVCh++r6+VIB/FKvVN0zSMS+7X5:6cfH2oUeTMrtbV3b8IBgVNwSMnX5
Yara None matched
VirusTotal Search for analysis
Name b55d409cc4f19bf6_ceval.h.wncry
Submit file
Filepath c:\python27\include\ceval.h.wncry
Size 5.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4b2bea29ed69e9a0e65604adbe6ee03e
SHA1 fa12d74359e9027fd717ad0740cd444ffe60744c
SHA256 b55d409cc4f19bf613f24d64a6e1d5c6c7bb393ce508bbc873701609e3ce0a9d
CRC32 B6820C49
ssdeep 96:oaOqojpzJe+jEWZU8QL5CDFfIMD4si3iDBol33UlzJKzcJ1sv91DEXwVUxgYn:jOqGjjEWZj2oFfIM9ykd7JW65xl
Yara None matched
VirusTotal Search for analysis
Name 8de86c91e51d02d2_ar_sy.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ar_sy.msg.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 72ae0275a1d7f6e4fd9ebabacd5282b9
SHA1 c7d98234faff87d2354c627da9b7f5262ab3de26
SHA256 8de86c91e51d02d2e68ac46ee321f965b57e452c18795b41705013c8d6ab6c25
CRC32 360A50E1
ssdeep 48:bktv8IYn6dyWkTF1WZWyVrVXI+hbNMyJ3u4AaNvNs/S:oPYn6dyWkrvyVJXIGbxSadNsa
Yara None matched
VirusTotal Search for analysis
Name 297d4d7cae6e99db_88.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\88.WNCRYT
Size 2.2KB
Type ASCII text
MD5 b387d4a2ab661112f2abf57cedaa24a5
SHA1 80db233687a9314600317ad39c01466c642f3c4c
SHA256 297d4d7cae6e99db3ca6ee793519512bff65013cf261cf90ded4d28d3d4f826f
CRC32 C6C96D3C
ssdeep 24:4azu8adWa9tUEVcqVc5VcaUTVcHVEVc+7VclEVcNGVcn0VcMG/0VcMjVcMK7YXs+:46C07LetHigetH1YES
Yara None matched
VirusTotal Search for analysis
Name 2ef16b95588741fc_325.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\325.WNCRYT
Size 1.0KB
Type ASCII text
MD5 730055872ca0f48ab1412deeacea11a7
SHA1 169a631d43e01e3eb2ba7928e9c73a56a0b44efa
SHA256 2ef16b95588741fca2581c142ce58b000781bef22acac68585ffbebef124c44d
CRC32 0CBB5780
ssdeep 24:792cN47i2RlGn0WGJAXagXspXFjXFdcdsR0xk8xerdyGo7:RN47iilG0WGJAP8pB1mmR0x7xeRyGo7
Yara None matched
VirusTotal Search for analysis
Name 4800aeb3366123ce_249.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\249.WNCRYT
Size 2.5KB
Type C source, ASCII text, with CRLF line terminators
MD5 0185af9d589fd6b4bc7d9c39c0029aed
SHA1 cfa3f635b037b1c217175e201199281a64612d31
SHA256 4800aeb3366123ce6e8687497f8e05a3d18ed2adbe4a46b5637aff301bc8a738
CRC32 8E80B43E
ssdeep 48:Fl7dgDg7CSMi99Q6KnfJm/aEqoOaRyYX4Ycw7:JgDsKn0SEa7Blw7
Yara None matched
VirusTotal Search for analysis
Name 394368cff21b93f9_mitopbdqvuil.txt.wncry
Submit file
Filepath c:\users\test22\documents\mitopbdqvuil.txt.wncry
Size 44.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 72b84a8f6c88376f70a9525234764530
SHA1 afd6cf9b5a855a038cea2c8a29924908015b2234
SHA256 394368cff21b93f9a7b53fd3babe4875d67f9e57fd0fefca0e3fc5fdf3231797
CRC32 B9826EDC
ssdeep 768:6FSJ8odo2u87xonkhxMjcvM18J5HfTELVoY4i+MKAZM16LDa26NoFotYwXbzcgPS:6F4d71/MjcvDnHfTkV12X16LW2goFotI
Yara None matched
VirusTotal Search for analysis
Name 1311dee0b5644150_581.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\581.WNCRYT
Size 10.0B
Type ASCII text
MD5 5f30e462704064bf71f87cef1e69e9c0
SHA1 246271b40521caa10016166f89611a87f0027547
SHA256 1311dee0b5644150d870cc70b093131f4d651f293818bcd1c623efe211834630
CRC32 6BBB90D7
ssdeep 3:Hn:H
Yara None matched
VirusTotal Search for analysis
Name f377c977b9fec4fc_openfolder.gif.wncry
Submit file
Filepath c:\python27\lib\idlelib\icons\openfolder.gif.wncry
Size 408.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0f799427a0ce6276c6df76f29241660e
SHA1 88e8152c6abfbbc3f37069884d0f8e47f80d4977
SHA256 f377c977b9fec4fc6a802bc1ee988510d3503c68eca5a9c819d69204b51308ee
CRC32 2EFBEF63
ssdeep 6:bkEvtGodRmqBwHHEDzCL7mHL6F/LP699ahaqxWzlWhqEfeZ0IhsNQfxPZy:bkEv5d3gHKQmHONP6UaqxWzWmaksND
Yara None matched
VirusTotal Search for analysis
Name 3a8b8abcb78f561c_{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x0000000000000009.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows\caches\{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x0000000000000009.db.wncry
Size 265.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ddc3983ee6e2a8b20cb41b33fb96ae45
SHA1 3d299671f662a4d5ed67d2b4a0859464f61f54fa
SHA256 3a8b8abcb78f561cc21b6b580445584d2bf68c3eb89938878982212467d6ab3d
CRC32 ABCF2F71
ssdeep 6144:3bz0uqQdrgFU6iPw9E+mnHTzXIDS+YuZWDxHQX+/GhW6xU:3/03DK6FUzzXeYuUDxHQvW6xU
Yara None matched
VirusTotal Search for analysis
Name aba044f08911bbf4_ko.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ko.msg.wncry
Size 1.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f1a49e862d93d65ce7732454ab2d7491
SHA1 1df62f196cdbc81ca00128cbd8baae5b2e6eb0dd
SHA256 aba044f08911bbf42d3950a7efb9d0c04bce52b18b4c1759f54f834cd89b478d
CRC32 AA9C5EBC
ssdeep 48:bkhDBb63r3bfRDqC5ipvwM6LQt8YJjzGIH:ohFm7bfRYdg28yV
Yara None matched
VirusTotal Search for analysis
Name 91fd0a1bd0f2a164_76.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\76.WNCRYT
Size 1.1KB
Type UTF-8 Unicode text, with CRLF line terminators
MD5 d02e7385b81823d3837b57015a8cff80
SHA1 ab894483f1847aa0a4006b1c930464701288303f
SHA256 91fd0a1bd0f2a164c1cda525964511df352b5182993658476da7375b9d2b6e36
CRC32 84D640D5
ssdeep 24:tOAvNVSW/8PWqy2iQjDpJLQrzP7tnocg3KilIOhM/gaVrnKAiQZn7n0BRBIbHmW:tOAvDS0ht2PDp47t7eKiHWNrnbi8n7nX
Yara None matched
VirusTotal Search for analysis
Name e4e34f1dab5725eb_566.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\566.WNCRYT
Size 480.0B
Type ASCII text
MD5 ef197fa924a18e834ff7b9b4bd19df9e
SHA1 68597d5b553540af8bd9dc0d91e965e57a33d287
SHA256 e4e34f1dab5725eb31f9f4e962fd9768555caa78e3e08a5a97d95b3acbab8f92
CRC32 43B2796E
ssdeep 6:ne0QNWubWeWuRQWMEZJsWERkWvvcYR4z6k5Pz6kD+zEWNEWuROcEWMEZJCcEWv6:ne0QjcfcYRW6kl6kD0jhcFYco
Yara None matched
VirusTotal Search for analysis
Name 81b6ddf3e7c8a879_descrobject.h.wncry
Submit file
Filepath c:\python27\include\descrobject.h.wncry
Size 2.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 cc1b3a7dea1f880aec2d5664e9cc6f75
SHA1 aea139dcb26fb88e973dcca56b5e697db6b2245d
SHA256 81b6ddf3e7c8a879d1abb8b98833ebff16343674be94acf6e67db3da447c1cb0
CRC32 60192D6D
ssdeep 48:bkkSxCROSTmmFlubb07r8kgrcaumob79CTqjN1mF/5/JTkH2OKE/pTvqS1C:okoCA5b84k48939o2mFx/1dOZM
Yara None matched
VirusTotal Search for analysis
Name 2da588ad6fb5280c_xlicense.txt.wncry
Submit file
Filepath c:\python27\tools\pynche\x\xlicense.txt.wncry
Size 1.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5d6093e06772b48844d0414bbecaa5c2
SHA1 ad162b38f499df1844cd270b802e318650c7716a
SHA256 2da588ad6fb5280c7bc1b8bda615959db4161b228542f5fdf93c62c638cb5a29
CRC32 12CD3399
ssdeep 48:bk5toqT2yAHMEnIVL7pCcpksWr51qpT9gTEOsdyw8XUhEP50:o5ttHAHfOoekrrsgTKGP50
Yara None matched
VirusTotal Search for analysis
Name 9be20f2a38a8972d_gb2312-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\gb2312-utf8.txt.wncry
Size 776.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 8df7ddab7dd8cc646c57b7a0c9c30e10
SHA1 d6f8da37e54d6c3324b59395f3c34801058aee87
SHA256 9be20f2a38a8972d848424324aa9b5469c33252895381c2ae7876d30077d722e
CRC32 943BAC75
ssdeep 12:bkE0+FtSOES/oDgsCbBs+xAL+ZrnodB6edeAbD3aNgAEcxQpBHh/6vvwwQNYGVGk:bkEy9gHBscAiZot9GvQpBB/bNYi3tH5
Yara None matched
VirusTotal Search for analysis
Name 6ca0eafb20496edf_169.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\169.WNCRYT
Size 757.5KB
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, datetime=2009:03:12 13:48:23], baseline, precision 8, 1024x768, frames 3
MD5 5a44c7ba5bbe4ec867233d67e4806848
SHA1 3b15be84aff20b322a93c0b9aaa62e25ad33b4b4
SHA256 6ca0eafb20496edf23fc1480e8b545399f484a630698324be652ed10f45fa2fc
CRC32 54B590EC
ssdeep 12288:8xopjwMf7bcn/JuPOKeAgqryRwgO8inb02qgtLTB1LOwjR7kTMUGRTE1JtOXPm9I:FFwMU/0PwAmK8ib0yB1hN7k3z3tJI
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name f3a8c59f2688b96a_blue.cs.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\pref\blue.cs.wncry
Size 1.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5154e71827bca5ded4e372bcebc3882d
SHA1 99d43baa869d9580805f9e27b68cb97cf9ab69c6
SHA256 f3a8c59f2688b96acacd4cd1d3c6d46ba41a63a5a8f7ee1c2a1bbdbefd15381d
CRC32 BE4AD596
ssdeep 24:bk1o8O8U0IvE2Kf8MtCoyOyXhDGSZRr30yg8bZLXlshVEmblDlwhct:bkqi5mLKEMtCo1yxCql30yg8bZLXlJmf
Yara None matched
VirusTotal Search for analysis
Name 78cfbb37a0a8bd5c_eu.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\eu.msg.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 758804c32cb8a648d57555389769f423
SHA1 7dee74d0eb4d789d8f96689ad36071dd2ccab1c4
SHA256 78cfbb37a0a8bd5c1017f1ae60998b615192e724789dc107f489538f80c74fc4
CRC32 15251CC8
ssdeep 24:bkOTAl1bI0bP+FZui54/Ij4333MZW2LYJmbpkBZbAWAh7Tqp0KS3:bkOTwU0bZI23wEJmNI4hXqA3
Yara None matched
VirusTotal Search for analysis
Name 58279472eafc4e41_274.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\274.WNCRYT
Size 32.7KB
Type C source, ASCII text, with CRLF line terminators
MD5 fe641f542adb70adfa6eaeb1bb03c189
SHA1 007cbf7a53f400b22efd39f2e668fdbb451afca6
SHA256 58279472eafc4e414f44b209ecc849d8609c94fff396f1d303c8cda332a9952f
CRC32 6C45EFC6
ssdeep 384:MZyXoF2bDbOwKllrCpwiI2/MwXuukqX83QsCbRENWf87AK7QZLuSZ8a8hx:YFKil0p5MwUqsQKNWCSmNhx
Yara None matched
VirusTotal Search for analysis
Name 6ff22c87fb5ee105_223.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\223.WNCRYT
Size 6.8KB
Type Non-ISO extended-ASCII text, with very long lines, with CRLF line terminators
MD5 d22ff2cc70fa2eec94aaa6c6f49e6eb0
SHA1 2458a3d696698e2c4550b91e54ff63f4b964198d
SHA256 6ff22c87fb5ee105b33346dbb3f13f3049a292981e9df1eb8591e858ccf4d782
CRC32 46A7FB70
ssdeep 192:J0mELGgOErIc3lYgFWESM6E87cpN6FWGHoh:JPE6FEflYgFWJRDYpN6FWGIh
Yara None matched
VirusTotal Search for analysis
Name 7e491e7b48d6e34f_m_japanese.wnry
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msg\m_japanese.wnry
Size 79.9KB
Processes 2632 (WannaCry.exe)
Type Rich Text Format data, version 1, unknown character set
MD5 b77e1221f7ecd0b5d696cb66cda1609e
SHA1 51eb7a254a33d05edf188ded653005dc82de8a46
SHA256 7e491e7b48d6e34f916624c1cda9f024e86fcbec56acda35e27fa99d530d017e
CRC32 4BC82D78
ssdeep 384:SXZ0j2cKKwd1lksPzy3EFHjHdI2MG275rQeo75Y3kmA31dv61Qyr:SXZ0qbjHd4G2RNZrS14P
Yara None matched
VirusTotal Search for analysis
Name 0b173e76299e75bb_fr_ch.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\fr_ch.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 c1577909f682b7a46577f3c061cdbdc7
SHA1 9a826ab868d5e489d30f6d6d10836db4da56f10f
SHA256 0b173e76299e75bbefc8d05c70909af9e3bdaea5ded1039ae248f320f069c05a
CRC32 547DC1BB
ssdeep 12:bkEHm45RqWF2za9LLCbwyA6iODhDWJCkvuwkorHowDauCTLxYLA:bka5RqWF2za9SE6HD9WJOOYuCTyLA
Yara None matched
VirusTotal Search for analysis
Name 7b38a83898fff662_readme.c.wncry
Submit file
Filepath c:\users\test22\documents\readme.c.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 f00859e79695dac05de06657dec65f46
SHA1 ce2d5e95e298f1547ff226d983dfb8ec90f918a5
SHA256 7b38a83898fff66295e190ac4694c3c1ecad2ddbed04ea18be3ed5338ea14efa
CRC32 B10AE2BD
ssdeep 6:bkEYT540GpZByj/6gEH/6IQKBcEKx6VV5UapgLBJWz8tnTTUnNUqOABWdR:bkEYTeZqj/pU2KBcEKsVaaKdJWyn/Uq/
Yara None matched
VirusTotal Search for analysis
Name 50ec7f9488e5e5fd_msg_36.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_36.txt.wncry
Size 1.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 784132668a5413373724eb4944365c40
SHA1 42784875fb41c97c6f0b91c5d8acf10ebdecb303
SHA256 50ec7f9488e5e5fd1d36987904223cbb026f56215a8bee4e66fe6ef384d93f70
CRC32 240DA31E
ssdeep 24:bkbm/bKitsh1GC+zgAzAEmjB1Z4suAUL0TiCbLW2huFDxQ:bka/uiKh1mzgAzATxRKbEL5
Yara None matched
VirusTotal Search for analysis
Name d80332fc4afaa081_ar_jo.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ar_jo.msg.wncry
Size 2.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 48e7091296c1b4e3a16247068b27366b
SHA1 e710a07e7d337e820b300c731e2916d60d27a587
SHA256 d80332fc4afaa081fb2afdff612cabf8a52832e84ecd3a8247b3fd139486090b
CRC32 3DD5BE31
ssdeep 48:bk9Ny9nkWAZnyiWdth38Tyv1Y5AXMSKJF1b2NIV/XZZfu496:o9Iyki2h3r1YiKJTV/XZZJ6
Yara None matched
VirusTotal Search for analysis
Name 12ad1546eb391989_641.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\641.WNCRYT
Size 251.0B
Type ASCII text
MD5 b7e7be63f24fc1d07f28c5f97637ba1c
SHA1 8fe1d17696c910cf59467598233d55268bfe0d94
SHA256 12ad1546eb391989105d80b41a87686d3b30626d0c42a73705f33b2d711950cc
CRC32 DA786BF6
ssdeep 6:SlSyEtJLlpuoo6dmodvPWHFLok3v6rZodo+3vPUe6HK:4EnLzu8DgF93v6rC3vs3q
Yara None matched
VirusTotal Search for analysis
Name 1e72bb2717157e6a_moduleobject.h.wncry
Submit file
Filepath c:\python27\include\moduleobject.h.wncry
Size 920.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0d9a4b585d3ebab6d6c6778b2a2cf2a4
SHA1 aba5600f316b0ec0a4ebfcea3a2ce1c25f245cfa
SHA256 1e72bb2717157e6aa0784c7e1a78ee4179ff1e2ec5b9d94851b58b5af4e44360
CRC32 8F35AF36
ssdeep 24:bk7Ry/cPLZHvgJxOi7MKx1sxTBXAZS6Vk00jSb:bkQ/ctvg/OULWTKhij0
Yara None matched
VirusTotal Search for analysis
Name aa57d5fb5cc3f59e_687.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\687.WNCRYT
Size 251.0B
Type ASCII text
MD5 293456b39be945c55536a5dd894787f0
SHA1 94def0056c7e3082e58266bce436a61c045ea394
SHA256 aa57d5fb5cc3f59ec6a3f99d7a5184403809aa3a3bc02ed0842507d4218b683d
CRC32 A1B1A86D
ssdeep 6:SlSyEtJLlpuoo6dmosDv+9/LosK3v6rZosDo+3v+6f6HK:4EnLzu8eDvWbK3v6r5DF3vmq
Yara None matched
VirusTotal Search for analysis
Name 0cb7eadd027c78a2_flapper.gif.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\flapper.gif.wncry
Size 69.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 7e5bcbaa9c34e8a0c790e9f0efa9a74f
SHA1 09ea379e023f96087b7894fafa463e3cc087f3b6
SHA256 0cb7eadd027c78a2058a904c334b6575e0c484b03837d7ebc31f348d6bbb2219
CRC32 39026B4C
ssdeep 1536:j90JZIINH5YJZrd76KqpANRcyI8xAON/ZeZKjjJruIVteCVUY/nm9Lyj:J77ZkKvCypxTpZfjjMutfBmC
Yara None matched
VirusTotal Search for analysis
Name 073592d710725b31_69.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\69.WNCRYT
Size 16.9KB
Type ASCII text, with CRLF line terminators
MD5 9c140cd85ff39480f66b5e88cdf0ca09
SHA1 43d8068835de9380bc3449f6a828fe1e2d8ab51e
SHA256 073592d710725b3181ad7cf78751870bf543f2fe1d493c1d3c3db1dc62ac23d1
CRC32 8717B6B1
ssdeep 384:BGaALk09ZT7vFvAQY28QvW+V87WzSN7txFLaJ:BGH997vFvXvW+G7SSN7rY
Yara None matched
VirusTotal Search for analysis
Name 35df66646c7300f4_488.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\488.WNCRYT
Size 289.0B
Type C source, ASCII text, with CRLF line terminators
MD5 530146606049912d05a5a4368b779491
SHA1 90d9bf412cf0a63dc8b7b13d4d46876f4f97a73a
SHA256 35df66646c7300f48cb47f4dbeafef82adbbb0c7c78ff6423a65e9920426754b
CRC32 4A958C7E
ssdeep 6:mRrrQ02jQ6zheMl7kFlAKe2iM0KWKe2qqM/da5jQ6dn3:mRrr8hx7Qli9KBlqqv3
Yara None matched
VirusTotal Search for analysis
Name e316d91fe6d2e7ae_boolobject.h.wncry
Submit file
Filepath c:\python27\include\boolobject.h.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 5b3c7e8a71a8e05dd87706d605aecad3
SHA1 05df2acf74bad3e9ffd7a743f7bf0a7369b4f91f
SHA256 e316d91fe6d2e7ae998ff276e78f9427d4d8bf9b14c30f0bfc4e73b41d053a79
CRC32 E77BD751
ssdeep 24:bk1LcDGL6kmkUC/G/WuQReSZ9o29SjtOagyuluUGs8o/l//jn28Jh8KZMkWcQjod:bk1QI0kUC/GBQRh9r9SpOV6hol//LIUl
Yara None matched
VirusTotal Search for analysis
Name 6706d95a7daff53e_hibsys.wncryt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\hibsys.WNCRYT
Size 128.0MB
Processes 2632 (WannaCry.exe)
Type VISX image file
MD5 e605f5c4e80100278cf57b2a4c5270ad
SHA1 3aee548102eb9b243daad27b03b6c39a882d6bc8
SHA256 6b28b2d18521f8e5a2a2cb158a1ef3f90820f2bc3f2cfe0302a8295143ef90f0
CRC32 1C3E1B65
ssdeep 3:rn/3RXQXRABM:rnfWXRA6
Yara
  • Suspicious_Obfuscation_Script_2 - Suspicious obfuscation script (e.g. executable files)
VirusTotal Search for analysis
Name e69f8ed2ba8b1bf7_usertile30.bmp
Submit file
Filepath C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 6f90adcbf8a3254558fe0aa75e416573
SHA1 5e5baaa632e90d78297f3c5edb9c592f15c53d4d
SHA256 e69f8ed2ba8b1bf7bccd65052fb89719e1ff5178cf82b95fd302a3ae950811bb
CRC32 765A6A9F
ssdeep 768:qXX6dF9BdefFGl3JGAKWvNM7Tnefs2zOEwFI4TpFU8gkFF:eqdFrUEHPlM7zmZOO4tFvF
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name a277081668bc14f9_483.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\483.WNCRYT
Size 679.0B
Type C source, ASCII text, with CRLF line terminators
MD5 baa321aebd7ef2a8d505c75b76f50bec
SHA1 eee2ad574370dca39fad10a4e2c32a83406f0e3e
SHA256 a277081668bc14f99518b3b7fbc8c8e1b98cc89bd3d1e6ab02d864ece1209a9c
CRC32 429514B5
ssdeep 12:U5mrhNz+X5oxiEe7hWafKb5ntnIoD39oYOcFzjyaE:iEnxIVfKbpfnyaE
Yara None matched
VirusTotal Search for analysis
Name 633b665aec7e88fa_562.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\562.WNCRYT
Size 10.0B
Type ASCII text
MD5 51de1c6b554dcba9c4050fd83b9cb6e5
SHA1 0321d1db1ffe1ab7f2887cf415998cef5c9643cf
SHA256 633b665aec7e88fa05dc3bfdc79df4bd9bda7b490c06c19b3c0a0a81644602f9
CRC32 C0223473
ssdeep 3:ssun:Lu
Yara None matched
VirusTotal Search for analysis
Name ae5d3df23f019455_685.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\685.WNCRYT
Size 242.0B
Type ASCII text
MD5 e719f47462123a8e7dabadd2d362b4d8
SHA1 332e4cc96e7a01da7fb399ea14770a5c5185b9f2
SHA256 ae5d3df23f019455f3edfc3262aac2b00098881f09b9a934c0d26c0ab896700c
CRC32 7CAF802C
ssdeep 6:SlSyEtJLlpuoo6dmoVAgWFLoVY9X3vtfNrFLoVA9+3vW6Q9:4EnLzu8DFWFgaX3vtNS/3vWH9
Yara None matched
VirusTotal Search for analysis
Name a3f4d0fb8b22f51a_built-in building blocks.dotx.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\document building blocks\1042\14\built-in building blocks.dotx.wncry
Size 3.8MB
Processes 2632 (WannaCry.exe)
Type data
MD5 b85edc81f6d8ab3c4b4eb96d2cfd03ff
SHA1 d67cfdb8f4ea09f9243bda6e754f39917ebf3329
SHA256 a3f4d0fb8b22f51a9cf6ac8ff73a9f140e4a55353724b01ca92f788fe7d5266b
CRC32 9997E6CB
ssdeep 98304:1ZsSg5Y0+fhotNR9+3pVpdOGxQn22TCdMiIq1xJ4pm9RTiD:1ZsjSUbR9+3pVvXxQHTAM+8p+ED
Yara None matched
VirusTotal Search for analysis
Name c33274e5f2d3a327_floating_points.txt.wncry
Submit file
Filepath c:\python27\lib\test\floating_points.txt.wncry
Size 17.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 109b00cce6109fa804926e822745fb68
SHA1 422ebc57c4ca12abae622a7c2050e88ef8e57e65
SHA256 c33274e5f2d3a3279499eb7e30d726f44d59c233f955a25a1b84cf18b0180af6
CRC32 5EDCF113
ssdeep 384:q8lCd0I7rCHDCAc2fffmtUWqKxsGdKA/vv42S7y0Yr:q8J8rMWt2fWtNqIb/vvhr
Yara None matched
VirusTotal Search for analysis
Name 8c6b4fbb701328cd_ga_ie.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\ga_ie.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e74148f49e17ea7250ba25ee8735b9ab
SHA1 27b0e9003e53d599e1bca133df3b7b88570770ec
SHA256 8c6b4fbb701328cd7cdd0bf10a45c24d99d9ee62aad80957c8a905f221cd4a42
CRC32 8B3A3A9E
ssdeep 12:bkEnDqX35RRD6aFcTzm6QuhLQ9FD3GxuZHW+Xy4QUDW:bkWD65RxFRz6LeZ3oaHWEC
Yara None matched
VirusTotal Search for analysis
Name 817f4787ab03c437_720.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\720.WNCRYT
Size 4.0B
Type ASCII text, with no line terminators
MD5 274583a65fe6b9b9874eb891eb0acf17
SHA1 19c068ea4adbdf7bfe8729c603dcf8ba9249dac5
SHA256 817f4787ab03c4377decd864c064ec156a0b3f5dffdc70795908d37a81a556bb
CRC32 BC9CD6FD
ssdeep 3:Lin:G
Yara None matched
VirusTotal Search for analysis
Name 71eaea96319d9474_eval.h.wncry
Submit file
Filepath c:\python27\include\eval.h.wncry
Size 872.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 ab80445f488f91671f3bd0de546f0405
SHA1 5e423737d55478f72102d81c29447be3240218a0
SHA256 71eaea96319d9474f61324cb3a3d1b0dc727c9ee6b7f964067129b4f8e9ea6bd
CRC32 7F36B9C5
ssdeep 24:bktGKphBaJ97rvcsA5ou/Ho3dCLC+gfRABcS47m:bk02hBW9rvcJDItT+gKBii
Yara None matched
VirusTotal Search for analysis
Name 1aa7d83a36211aa0_409.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\409.WNCRYT
Size 69.1KB
Type ASCII text, with very long lines
MD5 410401cde3fedf63e7f2ecb254c6d2c6
SHA1 776ddcf693ed878bbfa1f95d18b5aceb085332b0
SHA256 1aa7d83a36211aa0c15caaa0db4f06c64f2c841e4dc9c4b19ea92c8f2358897d
CRC32 23EAD155
ssdeep 1536:FImLR4Ld+TgTWtHY4olO7cH+/Kw/H/jZ4a8r:3iUPoo7kw/HSr
Yara None matched
VirusTotal Search for analysis
Name 8c00afef70845004_414.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\414.WNCRYT
Size 259.6KB
Type ASCII text, with very long lines
MD5 6c2da43d9340df25909c68d47d2a5ac7
SHA1 52607636ba4790d2dfbc26dbe96e0003ed07b178
SHA256 8c00afef7084500430ebe95eb9d9ab59c0e5e0f36bba8d10209d47722800d6c2
CRC32 CC927DF8
ssdeep 3072:MJJ5TnpGKHBRKQ+t3OoHn+NbgeywLmuy4Sr78BSrJiJe54umciYjMZ4n8XLOMCWD:Mnp+lOo70muy4Sr78CsOVmhYw0mHnD
Yara
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis
Name 0254e0de05fa332d_fsv7tn1k.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\fsv7tn1k.txt.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 c5cad92fe43fa4d8051d98889101a07a
SHA1 8903d08f119212c445a337940ee56a30e86f7a24
SHA256 0254e0de05fa332d1286c8fb76f8d621eedd062e62d5abe8731b3ced60a196c0
CRC32 165E3664
ssdeep 12:bkEvQ8qGG7LhVn/1KIa6zC1Ng5CWWWAnjzC9YyXO:bkCQdGGHhNA96zENg5Cb3jzC9Y/
Yara None matched
VirusTotal Search for analysis
Name f721221e857a8598_dependency_links.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyautogui-0.9.50-py2.7.egg-info\dependency_links.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e5483dd1d613a284f85d86650f62478b
SHA1 3c97e0236691be4cbffd5a0e3cd98e4b8bdb6f8c
SHA256 f721221e857a85987273cc79226ac01b9bc4063f037379c6dea0379a76ab875a
CRC32 68434C7B
ssdeep 6:bkEl+qQ241i/rZ7CZyKIW9qznqQ+mjz/DkEwbC67exQKlH51qMZskR8C:bkEli241iTZ+ryqqn/s2TdlZ1nOkaC
Yara None matched
VirusTotal Search for analysis
Name aa486c95e4ec830d_msg_44.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_44.txt.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 3e8897075208bb2563dbe4b3fd1f7536
SHA1 69e78998d2b189a1ad1afff30db0c32806ca626c
SHA256 aa486c95e4ec830d995a9a9b6f38f8c5d396ea86e3b354b0a5eefd4ee3497f7f
CRC32 CAB9E16C
ssdeep 24:bkPHc/TFu7c7EIDua08Ai1hh+ImoKGuTpS4f2mQ61QnDRsX//hobwtGvQ8rV5fnj:bkk7FWcHDua08bnQhTdfv71QnKXxobjb
Yara None matched
VirusTotal Search for analysis
Name fdc970a820422c07_tcllogo.gif.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\demos\images\tcllogo.gif.wncry
Size 2.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e1b7a3bb9cf6a4f329d74b3ab6ae1e9c
SHA1 209abcb43ee1e3ac3e42a89809efbc88a4eb72fb
SHA256 fdc970a820422c07bf3179b1b42ef1b529fc80dc4df91e0518c56ad749726962
CRC32 9BE204F1
ssdeep 48:bksHY9AfH7PHacHSXTl17KUL5IAaQ9+083HFrgka/26oBQRWorAN0Wtg821DI2L:oL9APm3p17KUqAzW3ZgT26oBjSg0Wtql
Yara None matched
VirusTotal Search for analysis
Name ea3d2fd757e969ce_el.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\el.msg.wncry
Size 2.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 03921f66585b356840538f6e1fa6749e
SHA1 5de17d1f69b0042e70cdfa69c8822ea718254554
SHA256 ea3d2fd757e969ce24870bdb1cc730ef72f7006f24dc794b3197e5b04478d9b9
CRC32 A6DB2E98
ssdeep 48:bkrXBP1FPDOPYm5uwjxFEp3co1qMfzhRIGZK/kSZZN1raoRafkrsPQ:ox1FPDgR5BzSfzUXkAZN1GoR6JI
Yara None matched
VirusTotal Search for analysis
Name 16b66629c769036c_pluck-pcm32.wav.wncry
Submit file
Filepath c:\python27\lib\test\audiodata\pluck-pcm32.wav.wncry
Size 26.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 0d70cee557240251037b07e16e4b5929
SHA1 a8ded07ea750ecc36fdfb99403fd84a127dcb13a
SHA256 16b66629c769036cdaaba1941c4b4bad764b0d3667083de7316cbcb57c5b08e3
CRC32 9D8CC63D
ssdeep 768:WlIHdtMXs6airhFNC3jFRF54nl23YnlsiD3RuL:Q6dWXsW7NQxRs6Yl36
Yara None matched
VirusTotal Search for analysis
Name 92506a9aa3d9c858_da.msg.wncry
Submit file
Filepath c:\python27\tcl\tk8.5\msgs\da.msg.wncry
Size 4.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 a86a2e4b8a083e43689e8538d77ce60c
SHA1 dd2f415205bcb0b3890311019346b0c4e8384f11
SHA256 92506a9aa3d9c8589db07c8110d7fa1168bbc5242e3f95143fe3f18bbc20501d
CRC32 D67CC715
ssdeep 96:o3jWfD7u44sRnanJRSjL/t9tg41BjvQQxxs:wWX+PmjLl9tg41BJs
Yara None matched
VirusTotal Search for analysis
Name 5fc25c30aee76477_337.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\337.WNCRYT
Size 2.4KB
Type GIF image data, version 89a, 97 x 150
MD5 711f4e22670fc5798e4f84250c0d0eaa
SHA1 1a1582650e218b0be6ffdeffd64d27f4b9a9870f
SHA256 5fc25c30aee76477f1c4e922931cc806823df059525583ff5705705d9e913c1c
CRC32 C4CBA3A9
ssdeep 48:/Ev7JJ+3uvz/Hwbcp7igaIwjBui7qFxIIOdJXcI+Ks:M9oWz/7pZAV7qPIImJXtXs
Yara None matched
VirusTotal Search for analysis
Name 8c0fda5b30907b7b_angular.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\angular.js.wncry
Size 590.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 96113872efab53a03e98495eb96762e3
SHA1 6933e30ff76c0b0a17d5492220325e0da0334b0c
SHA256 8c0fda5b30907b7b95088252c756c4937dbebfa184f04f80e6b654a928500fe5
CRC32 D614F4B2
ssdeep 12288:fYL+YYZZ7wbb8GoAZvfipvZtzOvGYv4vCygVaK2gOJViosmcm/fpsdIqq+m:fS+3ZZcbISv6pj+GHCAwOJQzmtkm
Yara None matched
VirusTotal Search for analysis
Name d86313f560b0d39a_chrysanthemum.jpg.wncry
Submit file
Filepath c:\users\public\pictures\sample pictures\chrysanthemum.jpg.wncry
Size 859.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 1fd0fb66c73a646886ebd2acda9c137d
SHA1 d9ab76f4a7c8ac5805efe2eda8243157f5a15be7
SHA256 d86313f560b0d39acffd56def6b2a565e36b7b4399496cc7fcc07fb0d67e4233
CRC32 63DB05E0
ssdeep 24576:bhTIWVJwemeWq+Ro7bMmTTsefNkFS5rHt3A7hXStIf:qWVJwG+qHJhTtQlUW
Yara None matched
VirusTotal Search for analysis
Name ae88c1f2336d96c8_12.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\12.WNCRYT
Size 122.8KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 4a256c1ca9dc3d0b4f9c04fb2428c349
SHA1 aba74a1a5093038738a0a1b3f2af6d78c72290ba
SHA256 ae88c1f2336d96c8f4e78436ad33dd642c2a1e5ab3a93f5696496c6cc1d048f4
CRC32 9F7CC62A
ssdeep 3072:vL66zJYjJxThu668vHAGoBcXNPMo+xgLH+9:vLxVYfThu58vHLoaVHLT+9
Yara None matched
VirusTotal Search for analysis
Name f00bb7e6e570dca8_en_zw.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_zw.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 3a809bf5cab797863cf33a31b8ae7ea0
SHA1 5add7c225ad01d4eef40fb1a9732f64c335a01ca
SHA256 f00bb7e6e570dca821c894e32698363182ec861febe4d07fefd2b35bc07e9969
CRC32 53E911E2
ssdeep 12:bkEXlS0J20/sZyv4CZ9a5bTHlsSQXqM250Ch23rdtPPwoYWpf:bkwI0N/sA4CHGbTHy05Xo37BYWpf
Yara None matched
VirusTotal Search for analysis
Name 6ea114d438b00ec1_wmdefault.txt.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\pref\wmdefault.txt.wncry
Size 4.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 64574448a4ed328e21ce3462a227192b
SHA1 3abb666cf474f1348fe96570c804990b7fe77070
SHA256 6ea114d438b00ec1d63c940b2a0cb309c0197eacb9ef85f945f62ed1ee77a451
CRC32 809D98BA
ssdeep 96:o+XFfXr+FVZKW2IR/szdU6l6jYGL9JQ65:FpSfZx1/W6hNhu65
Yara None matched
VirusTotal Search for analysis
Name 954f886c582e6b20_unverified-microdesc-consensus
Submit file
Filepath C:\Users\test22\AppData\Roaming\tor\unverified-microdesc-consensus
Size 2.3MB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 1c7a4a07baaa3c8bc31888600101b84f
SHA1 e319578b8af396f5971b36f1d33a90b3a421771c
SHA256 954f886c582e6b20cf2edfc0c95631ae77fc80fa8e94521fd00c057cf54a3435
CRC32 C9C1FD0B
ssdeep 12288:yCn/7vaW0Ph8LNBv6kXryBfbNyxV9VNtSYd0fxaJBm3WA162Zdyr8Jc47ZN5+JHO:yC/LntByEufbIJ0AJBFA1629J7hfZEpO
Yara None matched
VirusTotal Search for analysis
Name 81c1f8415c6cc63b_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pillow-3.2.0.dist-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 166e3fc5fb0a64d1ebc88b9adaa136ee
SHA1 44d72ec96f347704340f0be1e7048edda6f803f2
SHA256 81c1f8415c6cc63b60b242cae558db47df41d4d71852a345bc3022beb7b9c355
CRC32 00D69715
ssdeep 6:bkEUi/Y1QcBZmbFY+ul0RQ1qyadCNQEs/+lzBEWXEir2M:bkELYGUyWCwbVRZlvr2M
Yara None matched
VirusTotal Search for analysis
Name ba5b38928d525cb9_489.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\489.WNCRYT
Size 545.0B
Type C source, ASCII text, with CRLF line terminators
MD5 d7f908790c311376ad0662206c961186
SHA1 ca3d0fc2f209037fed1afe3400459e134a7e982a
SHA256 ba5b38928d525cb90932dbef7846206a8bbbfeaf927d02cdef077ffb49ab8038
CRC32 1B726005
ssdeep 6:B02Q07ORBMKmQjQ6z3grkPw04ROMFY2Wk1yeWqD3rkUMWPw0FpROMFYmMsW1yeWd:BNinMqQr9avnwBPnqa
Yara None matched
VirusTotal Search for analysis
Name 7907f91bf30f6914_topbar_floating_button.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\topbar_floating_button.png.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 a514e1cc549e6f3fe72b0fb848756e36
SHA1 f506407051c4a8cec778cceb0f07eef7021a6792
SHA256 7907f91bf30f6914c7944ef369d67a4e24310feb6ef9c94e9e2dd0936e802e28
CRC32 42AAC00E
ssdeep 12:bkE4WawcAKqXXUhiYJvnnLlM9/S9kdGt8P:bktWVtUb/nLG9/Lgt8P
Yara None matched
VirusTotal Search for analysis
Name 7dcc4966a5c13a52_657.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\657.WNCRYT
Size 985.0B
Type ASCII text
MD5 e27feb15a6c300753506fc706955ac90
SHA1 fdfac22cc0839b29799001838765eb4a232fd279
SHA256 7dcc4966a5c13a52b6d1db62be200b9b5a1decbaccfcaf15045dd03a2c3e3faa
CRC32 CB28AC5C
ssdeep 24:4azu80P6/XTPi6/XTotXSSzTGsy+trjz4HsKI:46qWKWoX75Bb4Mv
Yara None matched
VirusTotal Search for analysis
Name a600d81260d96a43_6.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\6.WNCRYT
Size 879.9KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 503ddbe383c8c627087a63e7acaee519
SHA1 ba5330b2cee1f8918dc49bfd9177b5e6e0435a6c
SHA256 a600d81260d96a43c676dc20744a0b15267b675dff494668e6bc3318c1c9da39
CRC32 EF1A282B
ssdeep 24576:ZeBTL1uTXPveBTL1uTXPveBTL1uTXPveBTh:ZWLczvWLczvWLczvWh
Yara None matched
VirusTotal Search for analysis
Name 5586c53726a49eaf_pybanner048.gif.wncry
Submit file
Filepath c:\python27\lib\email\test\data\pybanner048.gif.wncry
Size 1.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 386d5cb92213368afdc9bc8644c89821
SHA1 32a6586c3062c7aa98582dc3a022096ec03c5c38
SHA256 5586c53726a49eafe6a01de08232165dfd6ef3a0d9b712f25a08a3d3c3bb7fec
CRC32 555AF581
ssdeep 24:bkEWJYPwWNpv5RP3BkooKt1DOz3v52XH2O2NR2fVe6XfJSmvvy4ibq662JBB:bkEWOPwWNB3XDOd2XE6rfJXBibqRmBB
Yara None matched
VirusTotal Search for analysis
Name 0a4fdcb79a7c1c6a_koala.jpg.wncry
Submit file
Filepath c:\users\public\pictures\sample pictures\koala.jpg.wncry
Size 762.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4e6f901191d82ad7c5dc8d591f1e0b45
SHA1 0e4a355377abf5c8d45e76bc9b6b76335e4b9e0f
SHA256 0a4fdcb79a7c1c6a83c51e2c246b755afed67a5cec2822021f73dbd505cdf17d
CRC32 0BBB2E76
ssdeep 12288:mSkOGWJ4jkeY2NfxZ0Ct+mdakZjQhLswVFBIuwTZA15sVUPSrZR4vD:d/GWOTYcpmC+mdDCLswFBI+sOPSTs
Yara None matched
VirusTotal Search for analysis
Name eb1e60f2662cbb96_euc_kr.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\euc_kr.txt.wncry
Size 744.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 2665aa2dbeffea1377d4492f2446c09e
SHA1 b6798314c5a67d857d570836654d044dc844f30e
SHA256 eb1e60f2662cbb962438516f5c246d6ffde80e688d8629cf555ffb0cb3d83d66
CRC32 5DC7EB99
ssdeep 12:bkEXIHuUXTD3I7d6w8jcHuoftrvBUJvz/KD3MOnTXSKJAazBTq2Fxx9PJjjdB:bkEIB6d6w8SftjiJzKIMiKJxlRxhJjjL
Yara None matched
VirusTotal Search for analysis
Name c35a0f5e3a4bc7f2_top_level.txt.wncry
Submit file
Filepath c:\python27\lib\site-packages\pyrect-0.1.4-py2.7.egg-info\top_level.txt.wncry
Size 296.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 7c87ca979abc8f5c6e131066950d4e03
SHA1 a2362d6d9aa5972b3930256388a8501da838b4a4
SHA256 c35a0f5e3a4bc7f2e025e08bb61f8f569e228533365a69ac16e4e9c8f11e340b
CRC32 90C89FC3
ssdeep 6:bkEnZ3BAGToZqw5Q+zmoXBaXvd3Il1QrHr9wTdTlHEU6iWnpNLL5:bkEnZ3BtTbyifdYl1wL9w7HEUGpNx
Yara None matched
VirusTotal Search for analysis
Name 640449b9c77015e0_it.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\it.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e1852b2b639e14437900e4360e27a002
SHA1 8b0e93516e185912cef3b2d98d9ce62d74ba69da
SHA256 640449b9c77015e0f9c934177ecbf9ba03140fc7171a85f68e959ad503cf55a5
CRC32 1D708853
ssdeep 24:bk6RFgJ/ppjabRrRXtJ0oSMN1Bxv/itbKyiIWuMR85OHZPb:bk6vgNebbdfxitbpi9rzVb
Yara None matched
VirusTotal Search for analysis
Name 7ba81107414b455f_is.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\is.msg.wncry
Size 1.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 bf64ae4e0eee2f491f506c18cbb8424c
SHA1 c8ed3578847fe2ee0d375bbee143fd44f53cf13b
SHA256 7ba81107414b455f0c9277ce29ffec444754f2239f4522268b7880eb36873b3e
CRC32 78D3C57B
ssdeep 48:bkRI14dDhvw3jSdiIwBISCFvCFBouuEjd29G:oRWGpw3gwhCgvo4dj
Yara None matched
VirusTotal Search for analysis
Name 30118bc5f9488347_551.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\551.WNCRYT
Size 508.0B
Type ASCII text
MD5 8a5c7d6d61ae87a93f5ad4025a1c612d
SHA1 fa7d944b46761e439cbe4719bb90f3f3d114d98d
SHA256 30118bc5f94883470d75ed1d312add28e0ceb4333dc49097357bb337c4a0c7dd
CRC32 26D0A72F
ssdeep 12:te4ccIOcci+0E2q0EkUgq0Wq0ddi00voq01Dq0e1:teH7Oti+yqd5gqrqyiHcqj1
Yara None matched
VirusTotal Search for analysis
Name 29690d4b38889fa9_710.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\710.WNCRYT
Size 62.0B
Type ASCII text, with CRLF line terminators
MD5 38057f163106d7cae05f6e58fb638f72
SHA1 a974aada81fe3c10057b945641972606081b54c2
SHA256 29690d4b38889fa96da66a627e6778f2f558c9aaa2f14bc10301c83c6a88cd59
CRC32 B3789661
ssdeep 3:hDKPyFX+FJfA3LFRNQaCRFjLB7v:hDyyF+fA3LZJCRF5v
Yara None matched
VirusTotal Search for analysis
Name 502b9100ad9635fa_534.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\534.WNCRYT
Size 193.0B
Type news or mail, ASCII text, with CRLF line terminators
MD5 50ea12311fae9196ed74100d8325ae1b
SHA1 84520758b54fae614d1e28c11254d8e6b2f3e071
SHA256 502b9100ad9635fafecd709d4ffcd9ffcacd997a836dc3074303709a94784442
CRC32 EE93CF99
ssdeep 3:lk3QGmVHFLlGVP4vecIVPrGxX3i6M/7RFKgf8gZ9XWMKEkeIeAtISTOBT7oZ6N93:lVbHFAVqeLqozOHgZ9XmMQ6/8m9Wy
Yara None matched
VirusTotal Search for analysis
Name 2a02da40d40c6ae5_612.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\612.WNCRYT
Size 570.0B
Type UTF-8 Unicode text, with CRLF line terminators
MD5 ff42fef8a7a8f7ad9b42e4b557b7f6db
SHA1 4e6cfa30f2e9d373b5049a3b490a2d73eb962572
SHA256 2a02da40d40c6ae5a5e21c187a3d38dfaa1bacf5f1f55721d1e0a351af36de1e
CRC32 3124015D
ssdeep 12:1m2iKxcYJCJOCsoldhG+PuxA42w8fxlST4K7FxToYNk9UbcZ:1mHKxcVJdswdh4cxlg4Wh+ScZ
Yara None matched
VirusTotal Search for analysis
Name d25b0006e660e7d0_240.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\240.WNCRYT
Size 1.4KB
Type C source, ASCII text, with CRLF line terminators
MD5 0f8343ed6fdb5ee4abc6fadf9c8c488f
SHA1 dc311cb205de5a5f49f2e0eadc59bd03e0e4b63b
SHA256 d25b0006e660e7d030f16c83214078ffd5e2bed5469b2a97feb3e82daa9468e0
CRC32 AF843516
ssdeep 24:UJYLLCAHrNiZVUUmqPDlFu1eCIt2CIFKpvsPGCD/0jk/:DbrQUUCHrKCNcg/
Yara None matched
VirusTotal Search for analysis
Name 6c3fd6c30b6e8dd3_vi.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\vi.msg.wncry
Size 1.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 2e13636d75cfafd2c09b79119b6ad24a
SHA1 6fda90e6c43c459149e55bf73284be89f753fff3
SHA256 6c3fd6c30b6e8dd3c4eed829e5b899ebfbf8e6694964ce498550d085c0132975
CRC32 34323145
ssdeep 48:bk2v3mjfi4mioVf9//HsPkTmbMwkeEF6jXWaiA12/XewBEDx7WFlX6:o2vkfiLXVftPhms6T22MED9eX6
Yara None matched
VirusTotal Search for analysis
Name d123e0b4c2614f68_690.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\690.WNCRYT
Size 752.0B
Type ASCII text
MD5 d8c6bfbfce44b6a8a038ba44cb3db550
SHA1 fbd609576e65b56eda67fd8a1801a27b43db5486
SHA256 d123e0b4c2614f680808b58cca0c140ba187494b2c8bcf8c604c7eb739c70882
CRC32 03A4CC8D
ssdeep 12:4EnLzu8qmDBHZLX+TyW4OU5yPgM9Lz+SC3WwLNMW3v6G3v3Ww+:4azu8qyFOw3WwLrvTv3Ww+
Yara None matched
VirusTotal Search for analysis
Name 096ba8c410337be6_en_be.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_be.msg.wncry
Size 600.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 1631aea080e56063d130d3642ae32bde
SHA1 085fc5dcc8d3f7d2c814c9f74582bb8921498aa4
SHA256 096ba8c410337be629cfed31973c9082536b0c64126ac598b5fd671e68a2b49c
CRC32 0C628DF1
ssdeep 12:bkEz689mqNlbps02tb1aUizdTLq6teSqTc8W+GqoDcDS:bka7Nlbps0DtheiehDlSDcDS
Yara None matched
VirusTotal Search for analysis
Name 23a94d766041bac4_blue_gradient.jpg.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows mail\stationery\blue_gradient.jpg.wncry
Size 2.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 602bc5d06829de08dd66b897daf3e064
SHA1 07d84804597b590cb4d5f0cba831a8575840c34c
SHA256 23a94d766041bac4db410cbb5db80ecd64757c010dc037e7d112f1fbc86bcbde
CRC32 911E7AD1
ssdeep 48:bk7yg23yvV0W1UD3usQdfw1efuVOlUpPdpgT0L4rdITV09dGKDRLEbXI:o7CCv+WU+sUI1efuVOuPd60L0VEYEbXI
Yara None matched
VirusTotal Search for analysis
Name 04cd9494b0ed8392_417.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\417.WNCRYT
Size 531.9KB
Type ASCII text, with very long lines
MD5 6eebed29e6a6301e92a9b8b347807f5f
SHA1 65dfb69b650560551110b33dcba50b25e5b876de
SHA256 04cd9494b0ed83924dad12202630b20d053d9e2819c8e826a386c814cc0a1697
CRC32 FCE855CB
ssdeep 6144:abyfBNC2FRdjiRXqbe5Dq31IVlMqX+wd5/CcMMJcRULt0NjyTOEzZQ+h72W3GB0n:Ft/g
Yara
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis
Name 340804f73b620686_628.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\628.WNCRYT
Size 251.0B
Type ASCII text
MD5 ecc735522806b18738512dc678d01a09
SHA1 eeec3a5a3780dba7170149c779180748eb861b86
SHA256 340804f73b620686ab698b2202191d69227e736b1652271c99f2cfef03d72296
CRC32 49695A69
ssdeep 6:SlSyEtJLlpuoo6dmosmGvNLoss6W3v6aZosmT+3vR6HK:4EnLzu8WrvNbs6W3v6aBJ3voq
Yara None matched
VirusTotal Search for analysis
Name 3f701704399ceea0_0.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\0.WNCRYT
Size 10.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 73190757ddf00d53ab0946c101884f2f
SHA1 fd4e47860fe72380da2909084374410250232ad7
SHA256 3f701704399ceea0e5a91f572f5b21125050e8512b004f1481c334c0fc194ed5
CRC32 F6E79DC2
ssdeep 3:v+yjE:v+Z
Yara None matched
VirusTotal Search for analysis
Name 83154821961bfc6d_265.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\265.WNCRYT
Size 1.3KB
Type C source, ASCII text, with CRLF line terminators
MD5 c93fef72f1d92a010afd39af0219a0a6
SHA1 949752d02cf43e5581d21fce8b330d2c7ad63e58
SHA256 83154821961bfc6df30e6250125a1eaf084c862a30a996df215dd660e6100297
CRC32 EB5A698E
ssdeep 24:+0MUhanrrI1lE2gM6CS5XphKLPIQIG8ImINPxIBIsI2fBAv2ErKs:nMUhannI1lEkuXsIQILImIN5IBIsIgBc
Yara None matched
VirusTotal Search for analysis
Name 8ce05a91a3ce5d94_thumbcache_32.db.wncry
Submit file
Filepath c:\users\test22\appdata\local\microsoft\windows\explorer\thumbcache_32.db.wncry
Size 1.0MB
Processes 2632 (WannaCry.exe)
Type data
MD5 d2734717ca6f5c718317c5da34042778
SHA1 299d7d50e6922330581b2b6c7c0446f018325bcf
SHA256 8ce05a91a3ce5d9445772965854ff09de3dcb3d86b45d86081c61249b83016a9
CRC32 B58C4A5A
ssdeep 24576:dyoaHsKYGaF5eyj7LqF9rKdOZ0Vs5bAPrwpfQ+YD6cB:FaHs3yy/xOZ046rwdqdB
Yara None matched
VirusTotal Search for analysis
Name 431086a6e037907d_26.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\26.WNCRYT
Size 273.3KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 8b33a1264c12bf014aa8ea918bc111a7
SHA1 c26cd8e17632679f6c8013863ec0006e7db9351b
SHA256 431086a6e037907db0669b53db7321a2e3156b109f5f4bb2449d9d422d7b23d5
CRC32 599CFD46
ssdeep 6144:GvaX7LFfhojiOFczoZJVGzgtqvqc3ZQ1nlmspmtrX1A3r59W3MyKgm5vaX7l:LxZCOUZTGktA7ZQDmspixy9SMynl
Yara None matched
VirusTotal Search for analysis
Name 317fb03a6b398aab_page_embed_script.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\page_embed_script.js.wncry
Size 520.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 ed6d69b9bb14b41a32c5005f106f1541
SHA1 610a251e644e2e2733152249816a43c1e2a28f0e
SHA256 317fb03a6b398aab989bf98698d75b61e37b65859d9c02ed379e4439a82e00ae
CRC32 197243DE
ssdeep 12:bkEdRJeS3QBbkQdwwnk/dBmu4TC7zSJKS3c3:bke4qQBbkZvdBHks3
Yara None matched
VirusTotal Search for analysis
Name 4a44d2999bd44996_dberr.txt.wncry
Submit file
Filepath c:\sandbox\test22\defaultbox\drive\c\windows\system32\catroot2\dberr.txt.wncry
Size 12.7KB
Processes 2632 (WannaCry.exe)
Type data
MD5 4d6b336c3ef60040e54ab8d7a6f69338
SHA1 bb6448af17071179d2ee08f5c9fe0fd5eb21569a
SHA256 4a44d2999bd44996a7041ea03137772ff9a7c03bc77f7fee35910c60c37288bb
CRC32 6DEB1F41
ssdeep 384:N18Q2e3fNrdZBWkKg76wKyFIAzOW9epsoGbv:N52e3f5TdvOVpsdr
Yara None matched
VirusTotal Search for analysis
Name c0b56ef1b9203ef2_187.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\187.WNCRYT
Size 13.7KB
Type JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1000x300, frames 3
MD5 7c10ccea112bb14df41cc3043282ef7d
SHA1 e9267a787e15493a81dfaca06b22ac90b55b92eb
SHA256 c0b56ef1b9203ef2776808c1c00046c66ecaf28df4429d857f9f3adcd48c6c64
CRC32 E5A5270A
ssdeep 384:iJpsOB12GirnjJ95E0effDJQO7ohTohSaKod4j:iQXGwjpEBDW1hTohSam
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 44877cdb57998aa4_cacert.pem.wncry
Submit file
Filepath c:\python27\lib\site-packages\pip\_vendor\certifi\cacert.pem.wncry
Size 275.8KB
Processes 2632 (WannaCry.exe)
Type data
MD5 435cd3f9f38c45e84ae68f2a42a0f247
SHA1 794f18a7db9b1d09aee86391a2e2a738380bae55
SHA256 44877cdb57998aa4226c2c80ce47a69c186129d2dc8ec1d54faa703f991c7cba
CRC32 7DF7BD79
ssdeep 6144:po9zZZ0sBoskLUY5orpgTMU2EXxFA01KdmYXbB84cGu:C9FZlKLd5U+MU240X8Gu
Yara None matched
VirusTotal Search for analysis
Name bc401889dd934c49_117.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\117.WNCRYT
Size 1.1KB
Type ASCII text
MD5 d5509abf5cbfb485c20a26fcc6b1783e
SHA1 53a298fbbf09ae2e223b041786443a3d8688c9eb
SHA256 bc401889dd934c49d10d99b471441be2b536b1722739c7b0ab7de7629680f602
CRC32 F233C8FC
ssdeep 24:4azu8CKEj4/xasSpfiTBtHQT1V/W3WNfvZv3l:46KU/0s2iTeVOiHN1
Yara None matched
VirusTotal Search for analysis
Name 369af5c2e5e008c2_279.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\279.WNCRYT
Size 7.2KB
Type C source, ASCII text, with CRLF line terminators
MD5 9826fdff59848fb8cde7a23dc2032f69
SHA1 96382519a102a020e04ee627abb36cc8db80da87
SHA256 369af5c2e5e008c2af9a7a3864337eec16a011325ad9f50eab4bc34961a224cf
CRC32 FB23FB75
ssdeep 192:VTmJqMnK6lHDy20Hz48FpV2FAkXwxkusyL2V6:VTCqMnK6lHeHz48bV2FAkXwxkuf2c
Yara None matched
VirusTotal Search for analysis
Name 6d72623152aa15af_cert9.db.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\profiles\qxo5wa6x.default-release\cert9.db.wncry
Size 224.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ef540b1d8607827355439b8265e897c2
SHA1 f638be4afbbc2cb02edbed7c9bef1d07dfbc94d1
SHA256 6d72623152aa15afd3b8b76d05b9fbda2e393cb526750502199b65ac74b7f4c2
CRC32 B59FA7DD
ssdeep 6144:gpttpvfLWLBghccMywbgCfuK/Z8PWasXEm9r+:wbyLBghccMwYBGPA0ms
Yara None matched
VirusTotal Search for analysis
Name dc2305e277df9dfb_msg_35.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_35.txt.wncry
Size 424.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 37dea5694cbfa6f0d5ac73973c3ce04d
SHA1 a7f63dc86c097397f27e58d548c2fa16b2dbc8c9
SHA256 dc2305e277df9dfb5c822c2f5107419ed66b3ce21c0115105b339abaf5db3ef8
CRC32 AA0D868E
ssdeep 12:bkEiw3MSFLEeVOHzpYR8Tyu8wl2Q+zJDkhJUEe5L3B:bkziMSKqUFb8wsQGJ4hax5L3B
Yara None matched
VirusTotal Search for analysis
Name 16ea40fed8c12bbf_701.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\701.WNCRYT
Size 58.0B
Type GIF image data, version 89a, 9 x 9
MD5 addeb98686e49e94a69cab92d54aabd6
SHA1 77a65d4e16b56c6b782d2950405ada07d09c6862
SHA256 16ea40fed8c12bbf64b072bacf6b1c8ca80ce26e08fee7860b98cc9cce44fa64
CRC32 12F7BEC0
ssdeep 3:CMlbGltxlweemen:/luep
Yara None matched
VirusTotal Search for analysis
Name e7868c80fd59d18b_632.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\632.WNCRYT
Size 279.0B
Type ASCII text
MD5 30e351d26dc3d514bc4bf4e4c1c34d6f
SHA1 fa87650f840e691643f36d78f7326e925683d0a8
SHA256 e7868c80fd59d18bb15345d29f5292856f639559cffd42ee649c16c7938bf58d
CRC32 EEFB2240
ssdeep 6:SlSyEtJLlpuoo6dmoK6qH5oKi+3vG5oKi+3v6X5oKv+3vnFDoAov:4EnLzu8vqHr3vQ3v6O3v9dy
Yara None matched
VirusTotal Search for analysis
Name 254800534aafe9ea_29.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\29.WNCRYT
Size 537.0KB
Processes 2632 (WannaCry.exe) 1080 (taskdl.exe)
Type data
MD5 047af5345c50ca99ef0226dc0734762e
SHA1 d6b16b362ca660c10a0b57e5f32d23b3cc6050cb
SHA256 254800534aafe9ea88ae3805a30d2615a1995b1a3319ffa9856252333aae99b0
CRC32 AA71A048
ssdeep 6144:lnnWHahjWbTy9cNfbXGnvBhDtkiPQvIo2wtjTnnnWHahjWbTy9cNfbXGnvBhDtkT:lFh0nfbGV/xyDFh0nfbGV/xyDF
Yara None matched
VirusTotal Search for analysis
Name aae50f3e559c8583_euc_jp-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\euc_jp-utf8.txt.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 24ef1aa3328717d38e91081415bd910e
SHA1 9c80719c22e6bd18bd24525af562387ad78d7e66
SHA256 aae50f3e559c85831a85625446be7e9834d4061df11f9d50f2b470d9c3c03e7f
CRC32 EE88B20A
ssdeep 24:bkz9Y3VlrQPulJnVaYLR2wIJQCmwN47K8/Hicz91Ki1egZh3rVD+Jj4FC6EDQyzu:bkRY3nQPuldYyR2cCTNiK8/D1K0T/Jau
Yara None matched
VirusTotal Search for analysis
Name 20ead612870c490f_pymactoolbox.h.wncry
Submit file
Filepath c:\python27\include\pymactoolbox.h.wncry
Size 8.9KB
Processes 2632 (WannaCry.exe)
Type data
MD5 b49bab21e6098190a6f308feba453e62
SHA1 9ae543807754aad97d2b9739094fc2980fd70c26
SHA256 20ead612870c490f083e0fdc2f98f2082d9ec103daaa0f849f1d2b0a7eb76fb5
CRC32 C25FBB6E
ssdeep 192:Mgk4uW24S+FFwsrgMyHHpicrfCwhR1MQu7F4vJ56oxXvOJ2f:MgxuW2+4sunQcrfxhM7I5rNvOJ2f
Yara None matched
VirusTotal Search for analysis
Name af530acd69676678_639.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\639.WNCRYT
Size 242.0B
Type ASCII text
MD5 c806ef01079e6b6b7eae5d717da2aab3
SHA1 3c553536241a5d2e95a3ba9024aab46bb87fbad9
SHA256 af530acd69676678c95b803a29a44642ed2d2f2d077cf0f47b53ff24bac03b2e
CRC32 8625D063
ssdeep 6:SlSyEtJLlpuoo6dmo8GUFLot/W3vULo8T+3v9y6:4EnLzu8KGUFN3v+K3v3
Yara None matched
VirusTotal Search for analysis
Name bad9116386343f4a_339.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\339.WNCRYT
Size 3.4KB
Type GIF image data, version 89a, 130 x 200
MD5 a5e4284d75c457f7a33587e7ce0d1d99
SHA1 fa98a0fd8910df2efb14edaec038b4e391feab3c
SHA256 bad9116386343f4a4c394bdb87146e49f674f687d52bb847bd9e8198fda382cc
CRC32 A1251D86
ssdeep 96:ROGuxkQ9mcV7RXcECEtqCa+6GK8WseNXhewFIp9ZmL4u:ROGwpVOEbqCrWsUhtIk4u
Yara None matched
VirusTotal Search for analysis
Name a28a14e3b98a1d96_en_ca.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_ca.msg.wncry
Size 568.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 7c0e37339cdd0188ffb3b157ff0afd91
SHA1 c2401adada800dcf3e9155467fb847b239c2708f
SHA256 a28a14e3b98a1d96abc4c7aa6a23a6bc9b390938e6249cde201fbe089fd4404e
CRC32 13D4B251
ssdeep 12:bkESwmGmh8+MD3Gnkf9E79JpP5PX4+VHHli76bZUtkZP3+J5:bkemGmh8/D3IkVwp94+JHlio0QP3+7
Yara None matched
VirusTotal Search for analysis
Name 5ae401dfcc970a90_394.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\394.WNCRYT
Size 188.1KB
Type TIM image, Pixel at (27035,38502) Size=35115x459
MD5 3b1ce2b6cc7272e5c2d81738361a942c
SHA1 59ededf496d1083ea53be213346ee7511c57b306
SHA256 5ae401dfcc970a9059a5ac5d771a7b8a1329ee1cd9b1824b3e02ef08690bed6c
CRC32 0CBF4783
ssdeep 1536:Rx8K0D3uhiu6w2P4/4sY2Weg8D8nI42Js5Z4667iYuDo/:Rx8K0D3uhiu6w2P4/F42Js5var
Yara None matched
VirusTotal Search for analysis
Name 40015814487b93a8_355.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\355.WNCRYT
Size 48.1KB
Type PC bitmap, Windows 3.x format, 128 x 128 x 24
MD5 b0de08b6aada24cdd3458113d175f1a7
SHA1 225797b52f320b3efb2643c55fe55ab3a5618ae9
SHA256 40015814487b93a8372f33284d45586739a4a1e9d2b7961ab8c6d4d9561d10cb
CRC32 B6AE1128
ssdeep 1536:wf7einB+z9Kqo4HSKvxPTTEQuyJRaU/rod:wTeioz9Lo4n5PTTEQPaUjW
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 32ae84c1e9e73e18_template.java.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\editplus\template.java.wncry
Size 392.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 4d0dc91bdebd05069bb700ac756b1b10
SHA1 287e504a887443f4b273391038318bc8886bffc0
SHA256 32ae84c1e9e73e18e7d532dca68e9f4ccf9a4df63f01f5bc17372d86d58fc74e
CRC32 030E12F4
ssdeep 12:bkEPJEq+1pwYoOFy4LsevJejFIA6SxnKaz:bkaJELpwYoK46AF1V
Yara None matched
VirusTotal Search for analysis
Name ad1b7b248c3a37ed_namedcolors.txt.wncry
Submit file
Filepath c:\python27\tools\pynche\namedcolors.txt.wncry
Size 6.0KB
Processes 2632 (WannaCry.exe)
Type data
MD5 f7b8f07bba963f4be9993f65e838aa8e
SHA1 39c7c652044797f734dc47eecb4ba5cdf3fdf14e
SHA256 ad1b7b248c3a37ede13a742288c52972b54d8652c90bd213db28b15dc646d19e
CRC32 97A5C662
ssdeep 96:orKWYb9EcYPpwiwnSrwCqkEUJiwPYDhnuM//rXglC8NGd25Za6qo87N2C4xTXn2y:qKWqEcYeiwnaqkvJJPYDhnuEMvGd3t23
Yara None matched
VirusTotal Search for analysis
Name 7a8a539c8b990aef_678.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\678.WNCRYT
Size 251.0B
Type ASCII text
MD5 d325adcf1f81f40d7b5d9754ae0542f3
SHA1 7a6bcd6be5f41f84b600df355cb00ecb9b4ae8c0
SHA256 7a8a539c8b990aeffea06188b98dc437fd2a6e89ff66483ef334994e73fd0ec9
CRC32 56F15666
ssdeep 6:SlSyEtJLlpuoo6dmoh6AvvNLoh633v6aZoh6Ao+3vR6HK:4EnLzu8z6AvvN6633v6aY6AF3voq
Yara None matched
VirusTotal Search for analysis
Name 84abdb49a1ae859c_modsupport.h.wncry
Submit file
Filepath c:\python27\include\modsupport.h.wncry
Size 5.3KB
Processes 2632 (WannaCry.exe)
Type data
MD5 fd365399238dd7c99244fa52cc189e4b
SHA1 6d538bd14c4f1c4985fd408cbac25f35568dac3e
SHA256 84abdb49a1ae859c270e9f75278394153ec5593ccf7b150b93fb2854b136620c
CRC32 436B2D88
ssdeep 96:o/tOsSuLODOAIHeDHneUNE0n+gKoLL2KCzhY77TcRx+XYTZEqxHAl:hEEke+Ux+gKaCFwycIZdAl
Yara None matched
VirusTotal Search for analysis
Name 8932304b04e5f0ff_mirroring_webrtc.js.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\mirroring_webrtc.js.wncry
Size 2.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 d6703f8ed934c56d496ade95b2bfac54
SHA1 4c4712b0699153591cbce0adb12eb5a70b10ca01
SHA256 8932304b04e5f0ffab83deb1cd5ae142ea2be74be7f80b92772d547d3ea88bca
CRC32 D85B68CA
ssdeep 48:bksmZwb2DFIlq5DujP6WNXFlPUIXtlMAmS9v5UJ0XpSJR7aFKN2jAME7En:oHZwb2ZIl6OP939LXnMAt9v00XpSP7OJ
Yara None matched
VirusTotal Search for analysis
Name b83cc408d505b91a_info.gif.wncry
Submit file
Filepath c:\python27\tcl\tix8.4.3\bitmaps\info.gif.wncry
Size 440.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 dd6fb461d8525cb082f3dcd03759e07a
SHA1 e32db8173689b1e3cb90cc9cea77a8e0a47f5b0b
SHA256 b83cc408d505b91a7c9b9e154cec9f4141ea11d6b33b117f7192b5c3ca02f417
CRC32 5EC11C69
ssdeep 12:bkEfDKrXQ2hpL3zbXK7gQk4CPF05WY9dBmJK2a82EcoS9:bkdXhpL33ajk4y055jxr609
Yara None matched
VirusTotal Search for analysis
Name 12407e06a1246f51_395.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\395.WNCRYT
Size 1.2KB
Type data
MD5 41797e212ad9d8a62eb54ff5549beaea
SHA1 c5fbfe185bf11ff78203aaddef64136699ec3900
SHA256 12407e06a1246f513ca5d565e3e5d18bd55375e89258afe223e09bed7e835bc2
CRC32 273A618D
ssdeep 24:T+YnJYbiGmtWD3bYJpCC4UctCMUrLnCC4Wqiiqq/:CgB6Y6eFCAqiiqq/
Yara None matched
VirusTotal Search for analysis
Name 25fda8fed6627887_osdefs.h.wncry
Submit file
Filepath c:\python27\include\osdefs.h.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 920c04b2f387a80a9f58c517ae98200e
SHA1 58ae38cd60f6088e068f5e585eeaa5c6d1e23513
SHA256 25fda8fed66278877cb22fdcd73eb6fe8ab289d1bec88dce5f7797031c97a5cb
CRC32 769D195B
ssdeep 24:bknqHMmwBd94PUGbbF/42Lrx82OU66+mDQ3sB9fWTUZjroY8sWp:bknsBw6tbFg2fWZt6+KQ369fWwjkYyp
Yara None matched
VirusTotal Search for analysis
Name 0f35ace5268db339_superbar.png
Submit file
Filepath C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
Size 38.5KB
Type PNG image data, 214 x 180, 8-bit/color RGBA, non-interlaced
MD5 45b3b7ada6575d1623bd52d029d7cf96
SHA1 ae4810a660e18d7e40594d1e8e0fe33b46a7f2a4
SHA256 0f35ace5268db33940ed18e946a9c65be4e31ec0ae31faa6e60122859c5cb5ca
CRC32 574DE2CB
ssdeep 768:935RFO1NmgxH4WD6bK72pizILEF7P4ieb0MCquyQ6trGJipd9yS/xkXoZiHZmgi3:No1NtJ4WGb/i8LOPLeAJft6trwioowKz
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name dea74ce098454120_596.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\596.WNCRYT
Size 441.0B
Type ISO-8859 text, with CRLF line terminators
MD5 b81e082e72b23e8280b58a3dcdd73696
SHA1 abdaa54e22bdc73db0c1d3ee943b23979e7bd06b
SHA256 dea74ce09845412002a748f6d7b7a4cde523458c69ff973a22c255cf343c34f6
CRC32 6D80FE93
ssdeep 12:qJegVT9GyaLy8rFCPynDrALbQuW3nDLaefpPA34Dhav:qJdT9r/6hnvALbQZ3n6ehPSuMv
Yara None matched
VirusTotal Search for analysis
Name 1d7f975654c788e2_mini-kms_activator_v1.1_office.2010.vl.eng.txt.wncry
Submit file
Filepath c:\util\mini-kms_activator_v1.1_office.2010.vl.eng.txt.wncry
Size 952.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 0d0b4faf6223540e1276c49355de4a5b
SHA1 d119466efd9fe7b8815faed9045563733807c815
SHA256 1d7f975654c788e2ff5fc944ed7db70a208f79a3ada65c5439a3c5338af2b036
CRC32 6D925C07
ssdeep 24:bkWKaghdzDPWzrCnKviWtR/SYlXz9tNsc/dySI:bkdaghpWzzx9lXJ4h
Yara None matched
VirusTotal Search for analysis
Name 9b3a8f185f42d7f7_msg_05.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_05.txt.wncry
Size 872.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 82aee4b2792df5be7f0935efdbd04f00
SHA1 b43911ca4ef63c15f81a0daf74926f091ce79b46
SHA256 9b3a8f185f42d7f71924af5fa4a38374a9bf998dc3c94dac468e65c5803cc714
CRC32 E2063DBD
ssdeep 24:bk7I4ipf9cM9HDNZ8tClg/HjA358QM72S:bkEnKpwq/HjA3C6S
Yara None matched
VirusTotal Search for analysis
Name 7573581dec27e90b_93.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\93.WNCRYT
Size 1.2KB
Type ASCII text
MD5 a741cf1a27c77cff2913076ac9ee9ddc
SHA1 de519d3a86dcf1e8f469490967afe350baeafe01
SHA256 7573581dec27e90b0c7d34057d9f4ef89727317d55f2c4e0428a47740fb1eb7a
CRC32 7E2C1202
ssdeep 24:4azu8I8VWRFFAVa8VpZzWsuEbkMe5pF9grtT9egQTqr9u5sevOevmDvi:46kR6VaIZzWsuEJnHlrg5soOomzi
Yara None matched
VirusTotal Search for analysis
Name 5d10d6d49c796591_522.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\522.WNCRYT
Size 593.0B
Type SMTP mail, ASCII text, with CRLF line terminators
MD5 89f92dd432c9018f8fa3cb6d0a50a7d2
SHA1 894c85e089a579ba1a1cf8df6d0ee4fca5c4b690
SHA256 5d10d6d49c796591fe9861989a8a9c6e8de67760989b79ba55b927500c75d9d9
CRC32 25A18110
ssdeep 12:k11JKD4JKm5FdEvtXmMQymLETah7wsIftLnKLpLETKLx:STKD4JNAXmom9utT8QTY
Yara None matched
VirusTotal Search for analysis
Name 83d03af48b8222ab_en_hk.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\en_hk.msg.wncry
Size 616.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 cc4c803ff0512628350384796d0e90a7
SHA1 7f95c2e2c456abc106a3209aeef0b4bff2aaec15
SHA256 83d03af48b8222ab47263fafed13afd471c79239be45a6490f19a10054d3cd65
CRC32 87D29F15
ssdeep 12:bkEhVjQ6icErUSFsshfnCi3T7uOSs4HJpzogVulCM9aqZscp:bkv6er5DV9T7Tc+gs0cp
Yara None matched
VirusTotal Search for analysis
Name 80fe660287e8b8fc_457.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\457.WNCRYT
Size 224.0KB
Type SQLite 3.x database, last written using SQLite version 3038003
MD5 60e0def2f8e3bfe5e0112fc31d7b2203
SHA1 a74d024b409c60e652883707872ef717278c3222
SHA256 80fe660287e8b8fcd2714efdb00c81e009245f4982cb792c4e1313b0788b596d
CRC32 A0C60468
ssdeep 384:S71zkVmvQhyn+Zoz67z+hLMM3MM0WNlM8+A9N8GQT:S7akMQMyB9CGE
Yara None matched
VirusTotal Search for analysis
Name 37a597d5782af21e_579.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\579.WNCRYT
Size 360.0B
Type ASCII text
MD5 c2c5c987e6a5694ee7d068708a60d4ed
SHA1 117980b320e1c457e18ec695d744301811fd3cd0
SHA256 37a597d5782af21e0b6090f4e79e4c25806650744192b2c529e8e56aa7858425
CRC32 AC074583
ssdeep 6:o2N0X8jBGfq0X8OYkU+fq0X8XJtfq0X8Id/q0X8xllvoq0X8KdDfq0X8UvQ3Gq0F:o2N0E2q0EkUgq0Wq0ddi00voq01Dq0e+
Yara None matched
VirusTotal Search for analysis
Name 4db5be1eb72424c2_1ac37hi2.txt.wncry
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\cookies\1ac37hi2.txt.wncry
Size 456.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 e9da01ee228969b1d49fdf1a96ec1fb2
SHA1 fe4882c34c900864c36e19d84274f8520e0a593f
SHA256 4db5be1eb72424c29dabbab16ad57376d79f1de80031a901db0b99fca16c5fd7
CRC32 F1CC5553
ssdeep 12:bkEK5kCaLV6Up2ZKGeOMvpTaqTwpL490y/mmdcnIW:bkFitkUc0GehBaL498YcIW
Yara None matched
VirusTotal Search for analysis
Name d76fa433c045ecff_icon_128.png.wncry
Submit file
Filepath c:\users\test22\appdata\local\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\icon_128.png.wncry
Size 3.6KB
Processes 2632 (WannaCry.exe)
Type data
MD5 037cfafbacc3c56c45df18651386011c
SHA1 f86f849438ffdbfe0905a8b76fd98ef2e73fb4b1
SHA256 d76fa433c045ecff56c4ebd822a2910114dd5c24143e7bf5a96ce8a4d672264f
CRC32 4F28D346
ssdeep 96:ocs1RZvwjGrDBlASI5nwGuQDzvCsZbkXIaDPpaI:fsvtwjGrNlAH1yXHwI
Yara None matched
VirusTotal Search for analysis
Name 14cf0ffc2117eea7_399.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\399.WNCRYT
Size 2.6MB
Type data
MD5 3f1a2fa51eeb90c0e497cca0bbc9a39a
SHA1 4bcb42d737414e1ca698df7bbb7d33f14a8c068c
SHA256 14cf0ffc2117eea77502cc1ab915b0df5be3f6f1810b94fcd33d1cda9dd03a8e
CRC32 38C8402E
ssdeep 24576:fb9TrHeieUowL3eh7cE7cYHuP5p7cE7cLsn7ca6:fb9X+zUowCh7cE7cquP5p7cE7cLQ7ca6
Yara
  • Antivirus - Contains references to security software
VirusTotal Search for analysis
Name 2e9b67940bc7278c_es_cl.msg.wncry
Submit file
Filepath c:\python27\tcl\tcl8.5\msgs\es_cl.msg.wncry
Size 536.0B
Processes 2632 (WannaCry.exe)
Type data
MD5 b0b5cbfbe9c2fee9009fa8e61ad04c14
SHA1 aed1117544adcc9c1504ee967266086e6a88f529
SHA256 2e9b67940bc7278cd3ea061f8aba34b342e6c6e75ba901cc1c98d3cc86ddebcf
CRC32 D91346C7
ssdeep 12:bkEYKZ2+qgxJXDF67O/uKlg/sXWOvQL5Nwwh7fnSfE48CGKd19n:bkqNlX47O9lg/sZIL5NnhzSc48CGKd19
Yara None matched
VirusTotal Search for analysis
Name db1222bc0e9d0ae3_shift_jis-utf8.txt.wncry
Submit file
Filepath c:\python27\lib\test\cjkencodings\shift_jis-utf8.txt.wncry
Size 1.4KB
Processes 2632 (WannaCry.exe)
Type data
MD5 ef5e34b42fb072d562b9b2393a70df4a
SHA1 22bac7a11a55d2325c1428f0d3916a290c4488e2
SHA256 db1222bc0e9d0ae34d03545c616ac8ab60ced86314b49a679825b8bf71ed6366
CRC32 C0BB459B
ssdeep 24:bkMOJsx+h/r5v+cDOSGUjhObu5Y14vzdsLjE8KVL6BC5CFW4AL9mfwR/ahI+5aK:bknsxu/r5vja9UtN5JvzgjE8KVL6mCrT
Yara None matched
VirusTotal Search for analysis
Name 72767217da6a55f5_nokia.pem.wncry
Submit file
Filepath c:\python27\lib\test\nokia.pem.wncry
Size 2.2KB
Processes 2632 (WannaCry.exe)
Type data
MD5 6edaf6aa6a49603c06b5c628df845e8f
SHA1 9ce16fd4916fee014fd7c12a5aea3a4ff8a8549d
SHA256 72767217da6a55f54a2120a3b95ac9c231d7dea1af1c3fb8207245cbd5ad8190
CRC32 931188D4
ssdeep 48:bkVmttBDsfPhMEqt7+g4Nrm2eySt4guRuPrq5xxmG05IvngZsJu5+:oV2jDsfut7qm8St4PuDKxxt0GUsJu4
Yara None matched
VirusTotal Search for analysis
Name efbe077e573908f2_longobject.h.wncry
Submit file
Filepath c:\python27\include\longobject.h.wncry
Size 6.1KB
Processes 2632 (WannaCry.exe)
Type data
MD5 e939879508d451ad16e3d05fd2539ea9
SHA1 601999399f8eaf40c282e5d0196f7f4a51fd878b
SHA256 efbe077e573908f22ef9e6afae77281c84e839c0bb2be3430cceb96ad454b0da
CRC32 7F1E2163
ssdeep 192:H5jMKBs9MeTkU1Pamx20kkkiTc0wvjjP3QBiNYx5:nW9MeX13xykkacP3PeieT
Yara None matched
VirusTotal Search for analysis
Name 38dca9b656241884_110.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\110.WNCRYT
Size 1.6KB
Type ASCII text
MD5 430deb41034402906156d7e23971cd2c
SHA1 0952ffbd241b5111714275f5cd8fb5545067ffec
SHA256 38dca9b656241884923c451a369b90a9f1d76f9029b2e98e04784323169c3251
CRC32 1625FB18
ssdeep 24:4azu8VcQHxbtVLKMwvtFwvQv4fTweLvDvTwS0Zu+jqgv:46RbItt4mCEebzES0njqq
Yara None matched
VirusTotal Search for analysis
Name c65629982d702665_604.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\604.WNCRYT
Size 463.0B
Type ISO-8859 text, with CRLF line terminators
MD5 9ba24dacd82833c0b803f4648c1d6bbb
SHA1 6f90146b0028c51a7f533845890165cffe82119d
SHA256 c65629982d702665159d4a13a8008b6bd17bc39cae7afe9eb89407d111cc3252
CRC32 445C4FE4
ssdeep 6:fdtHuxXJBzc/uu6eaYXjD7E4Q9jik4JAJh2gOulUrq/cmqTTaHKwR8tu6kWcoWam:nHAlK19D7Qi8JpOQcmqTypOIWPWaxjs
Yara None matched
VirusTotal Search for analysis
Name bd488c9d791abedf_126.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\126.WNCRYT
Size 1.1KB
Type ASCII text
MD5 2566bde28b17c526227634f1b4fc7047
SHA1 be6940ec9f4c5e228f043f9d46a42234a02f4a03
SHA256 bd488c9d791abedf698b66b768e2bf24251ffeaf06f53fb3746cab457710ff77
CRC32 A627FE78
ssdeep 24:4azu8PyUpd4+RfscasS9CErTByism1KSCvt1vJo6:462U/ENsqrTtVEtRx
Yara None matched
VirusTotal Search for analysis
Name b0d0f6850d3a8aa7_599.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\599.WNCRYT
Size 487.0B
Type UTF-8 Unicode text, with CRLF line terminators
MD5 a2ed0fea098241759134b81de40df9c6
SHA1 dc58987dbaf4da3edcca6631b2512bd8a5523671
SHA256 b0d0f6850d3a8aa77f054f1571d473d2a89a3b8cb86a6bdb713f0feb5c9ba738
CRC32 292E109B
ssdeep 12:5cRplXscJGmBoyhfUj8rU0yqWXjDsbONconhrv:5cRplXsoGmayfU4ChX/sbONj7
Yara None matched
VirusTotal Search for analysis
Name f16e212d5d1f6e83_663.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\663.WNCRYT
Size 279.0B
Type ASCII text
MD5 017d816d73dab852546169f3ec2d16f2
SHA1 3145bb54d9e1e4d9166186d5b43f411ce0250594
SHA256 f16e212d5d1f6e83a9fc4e56874e4c7b8f1947ee882610a73199480319efa529
CRC32 0E531063
ssdeep 6:SlSyEtJLlpuoo6dmooI9jo13vG5o13v6X5o1+3vnFDoAov:4EnLzu8eI9Q3vB3v613v9dy
Yara None matched
VirusTotal Search for analysis
Name 9d65f4a61d3e5207_msg_07.txt.wncry
Submit file
Filepath c:\python27\lib\email\test\data\msg_07.txt.wncry
Size 5.5KB
Processes 2632 (WannaCry.exe)
Type data
MD5 88e2cabaa7bd936ecd2b77ef5b820ca0
SHA1 7875a3ff774a7ac8fa834e0ad4ff5aef0cc8e6d5
SHA256 9d65f4a61d3e520761d69f420e385498af66a5b4da0e819a458339df088287ad
CRC32 F7A4D6C7
ssdeep 96:oJtrzXNWBK3tKFgAvjIrgNUuccV2lMr0gqe4McETL9Ovl/L9OrutFk8DeyjOH:SJ3kgmjIUNgcV2laJBrcECpLsitFDSYA
Yara None matched
VirusTotal Search for analysis
Name 8892b440f64cd9b8_773.WNCRYT
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\773.WNCRYT
Size 128.0MB
Type Microsoft Cabinet archive data, 264814728 bytes, 4613 files
MD5 a7a7d1d9d43f6ab165916c69d3b48682
SHA1 f9fa8d9abc145fdcc7764cb687c76f25fbb766db
SHA256 8c89ad36693198e45158bfeddd43ec976e4e3aeb974550ffd1f4764dd4698412
CRC32 31F82F3D
ssdeep 3145728:wmvEUAMWIP36TzpYY/Ofs5FsInmcrtxk8CLe/O8ksx8N9:hvE6BP36pYYKs5FsIm4k88ezksx8N9
Yara
  • CAB_file_format - CAB archive file
  • Antivirus - Contains references to security software
VirusTotal Search for analysis