s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-5d6feec1b6ceb6d25f48b80016ef2aa3de4cae6f49cc03e6bb47b2f4ebbf985a high

📛 Threat Title

WannaCry: 5d6feec1b6ceb6d25f48b80016ef2aa3de4cae6f49cc03e6bb47b2f4ebbf985a

Category: WannaCry Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 5298176 bytes. Tags: dionaea, exe, WannaCry. Reporter: pawscobbler. First seen: 2026-09-25 11:15:37.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 0cdadfa1098d845dd3b4cf92625b5f04

IOC database

Type
hash_imphash
Value
0cdadfa1098d845dd3b4cf92625b5f04
First seen
Last seen
Attached to this threat
Appears in
186 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 5d6feec1b6ceb6d25f48b80016ef2aa3de4cae6f49cc03e6bb47b2f4ebbf985a VT 55 / 75

IOC database

Type
hash_sha256
Value
5d6feec1b6ceb6d25f48b80016ef2aa3de4cae6f49cc03e6bb47b2f4ebbf985a
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
WannaCry

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 55 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.WannaCryptor.R200894
alibabacloud malicious RansomWare:Win/Wannacryptor.6d8dbf74
ALYac malicious Exploit.CVE-2017-0147
Antiy-AVL malicious Trojan[Exploit]/Win64.CVE-2017-0147
APEX malicious Malicious
Arcabit malicious Exploit.CVE-2017-0147
Avast malicious Sf:WNCryLdr-A [Trj]
AVG malicious Sf:WNCryLdr-A [Trj]
Avira malicious EXP/W32.CVE-2017-01.B
BitDefender malicious Exploit.CVE-2017-0147
Bkav malicious W32.Malware.C829D1B5
ClamAV malicious Win.Ransomware.Wanna-9769986-0
CrowdStrike malicious win/malicious_confidence_100% (D)
CTX malicious dll.exploit-kit.generic
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Encoder.11432
Elastic malicious malicious (high confidence)
Emsisoft malicious Exploit.CVE-2017-0147 (B)
ESET-NOD32 malicious Win64/Exploit.CVE-2017-0147.A trojan
F-Secure malicious Exploit.EXP/W32.CVE-2017-01.B
Fortinet malicious W64/Wanna.AK!tr
GData malicious Exploit.CVE-2017-0147
Google malicious Detected
Gridinsoft malicious Trojan.Win64.Downloader.oa!s1
huorong malicious Exploit/EquationDrug.a
Ikarus malicious Exploit.CVE-2017-0147
Jiangmin malicious Trojan.Wanna.e
K7AntiVirus malicious Trojan ( 0058feba1 )
K7GW malicious Trojan ( 0058feba1 )
Kaspersky malicious Trojan.Win32.Eb.s
Kingsoft malicious malware.kb.a.725
Malwarebytes malicious CVE20170147.Trojan.Exploit.DDS
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious ti!5D6FEEC1B6CE
Microsoft malicious Ransom:Win32/WannaCrypt!pz
MicroWorld-eScan malicious Exploit.CVE-2017-0147
NANO-Antivirus malicious Trojan.Win32.Wanna.epclsl
Panda malicious Trj/GdSda.A
Rising malicious Exploit.EternalBlue!1.AAED (CLASSIC)
Sangfor malicious Ransom.Win32.Save.WannaCry
SentinelOne malicious Static AI - Suspicious PE
Skyhigh malicious Ransom-WannaCry!DF3130A44D31
Sophos malicious Mal/Wanna-A
Symantec malicious Ransom.Wannacry
TACHYON malicious Ransom/W32.WannaCry.5298176
Tencent malicious Trojan.Win64.Wanna.a
TrellixENS malicious Ransom-WannaCry!DF3130A44D31
Varist malicious W64/S-e4f863f0!Eldorado
VBA32 malicious TrojanRansom.Win64.Wanna
VIPRE malicious Exploit.CVE-2017-0147
Webroot malicious W32.Trojan.Gen
Yandex malicious Trojan.GenAsa!DtE/ovQwFGg
Zillya malicious Trojan.Wanna.Win32.27
ZoneAlarm malicious Mal/Wanna-A

Details From VirusTotal

Basic Properties
MD5df3130a44d313198a0fada63789014f6
SHA-1144b20630fee23e20c9c6538fb867f6bc803dfe5
SHA-2565d6feec1b6ceb6d25f48b80016ef2aa3de4cae6f49cc03e6bb47b2f4ebbf985a
VHash156066655d151555bz47?z1
SSDEEP49152:jn2nAQVQVHQxBnBUPWo8c0JUZwffc+Q+kkNScWaUPWo8lOoGsVwZCGsVwZQ8pG6q:DyDVEHcUPt8c0J0wMV+lNSbaUPt8
TLSHT17A36F616A3E95624F5F77B31697A26740A7ABC95A93CD30F1280405E1DB2F80CEB1B73
File typeWin32 DLL
File type tagpedll
File extensiondll
MagicPE32+ executable (DLL) (console) x86-64, for MS Windows
File size5.1 MB
History
Creation date2017-05-11 12:20 UTC
First seen on VirusTotal2026-09-25 11:18 UTC
Last submission2026-09-25 11:18 UTC
Last analysis2026-09-25 11:18 UTC
Last modified on VirusTotal2026-09-25 23:29 UTC
Known Names
  • 3i60y2y.exe
  • 5d6feec1b6ceb6d25f48b80016ef2aa3de4cae6f49cc03e6bb47b2f4ebbf985a.exe
hash_sha1 144b20630fee23e20c9c6538fb867f6bc803dfe5 VT 55 / 75

IOC database

Type
hash_sha1
Value
144b20630fee23e20c9c6538fb867f6bc803dfe5
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 55 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.WannaCryptor.R200894
alibabacloud malicious RansomWare:Win/Wannacryptor.6d8dbf74
ALYac malicious Exploit.CVE-2017-0147
Antiy-AVL malicious Trojan[Exploit]/Win64.CVE-2017-0147
APEX malicious Malicious
Arcabit malicious Exploit.CVE-2017-0147
Avast malicious Sf:WNCryLdr-A [Trj]
AVG malicious Sf:WNCryLdr-A [Trj]
Avira malicious EXP/W32.CVE-2017-01.B
BitDefender malicious Exploit.CVE-2017-0147
Bkav malicious W32.Malware.C829D1B5
ClamAV malicious Win.Ransomware.Wanna-9769986-0
CrowdStrike malicious win/malicious_confidence_100% (D)
CTX malicious dll.exploit-kit.generic
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Encoder.11432
Elastic malicious malicious (high confidence)
Emsisoft malicious Exploit.CVE-2017-0147 (B)
ESET-NOD32 malicious Win64/Exploit.CVE-2017-0147.A trojan
F-Secure malicious Exploit.EXP/W32.CVE-2017-01.B
Fortinet malicious W64/Wanna.AK!tr
GData malicious Exploit.CVE-2017-0147
Google malicious Detected
Gridinsoft malicious Trojan.Win64.Downloader.oa!s1
huorong malicious Exploit/EquationDrug.a
Ikarus malicious Exploit.CVE-2017-0147
Jiangmin malicious Trojan.Wanna.e
K7AntiVirus malicious Trojan ( 0058feba1 )
K7GW malicious Trojan ( 0058feba1 )
Kaspersky malicious Trojan.Win32.Eb.s
Kingsoft malicious malware.kb.a.725
Malwarebytes malicious CVE20170147.Trojan.Exploit.DDS
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious ti!5D6FEEC1B6CE
Microsoft malicious Ransom:Win32/WannaCrypt!pz
MicroWorld-eScan malicious Exploit.CVE-2017-0147
NANO-Antivirus malicious Trojan.Win32.Wanna.epclsl
Panda malicious Trj/GdSda.A
Rising malicious Exploit.EternalBlue!1.AAED (CLASSIC)
Sangfor malicious Ransom.Win32.Save.WannaCry
SentinelOne malicious Static AI - Suspicious PE
Skyhigh malicious Ransom-WannaCry!DF3130A44D31
Sophos malicious Mal/Wanna-A
Symantec malicious Ransom.Wannacry
TACHYON malicious Ransom/W32.WannaCry.5298176
Tencent malicious Trojan.Win64.Wanna.a
TrellixENS malicious Ransom-WannaCry!DF3130A44D31
Varist malicious W64/S-e4f863f0!Eldorado
VBA32 malicious TrojanRansom.Win64.Wanna
VIPRE malicious Exploit.CVE-2017-0147
Webroot malicious W32.Trojan.Gen
Yandex malicious Trojan.GenAsa!DtE/ovQwFGg
Zillya malicious Trojan.Wanna.Win32.27
ZoneAlarm malicious Mal/Wanna-A

Details From VirusTotal

Basic Properties
MD5df3130a44d313198a0fada63789014f6
SHA-1144b20630fee23e20c9c6538fb867f6bc803dfe5
SHA-2565d6feec1b6ceb6d25f48b80016ef2aa3de4cae6f49cc03e6bb47b2f4ebbf985a
VHash156066655d151555bz47?z1
SSDEEP49152:jn2nAQVQVHQxBnBUPWo8c0JUZwffc+Q+kkNScWaUPWo8lOoGsVwZCGsVwZQ8pG6q:DyDVEHcUPt8c0J0wMV+lNSbaUPt8
TLSHT17A36F616A3E95624F5F77B31697A26740A7ABC95A93CD30F1280405E1DB2F80CEB1B73
File typeWin32 DLL
File type tagpedll
File extensiondll
MagicPE32+ executable (DLL) (console) x86-64, for MS Windows
File size5.1 MB
History
Creation date2017-05-11 12:20 UTC
First seen on VirusTotal2026-09-25 11:18 UTC
Last submission2026-09-25 11:18 UTC
Last analysis2026-09-25 11:18 UTC
Last modified on VirusTotal2026-09-25 23:29 UTC
Known Names
  • 3i60y2y.exe
  • 5d6feec1b6ceb6d25f48b80016ef2aa3de4cae6f49cc03e6bb47b2f4ebbf985a.exe
hash_md5 df3130a44d313198a0fada63789014f6 VT 55 / 75

IOC database

Type
hash_md5
Value
df3130a44d313198a0fada63789014f6
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 55 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.WannaCryptor.R200894
alibabacloud malicious RansomWare:Win/Wannacryptor.6d8dbf74
ALYac malicious Exploit.CVE-2017-0147
Antiy-AVL malicious Trojan[Exploit]/Win64.CVE-2017-0147
APEX malicious Malicious
Arcabit malicious Exploit.CVE-2017-0147
Avast malicious Sf:WNCryLdr-A [Trj]
AVG malicious Sf:WNCryLdr-A [Trj]
Avira malicious EXP/W32.CVE-2017-01.B
BitDefender malicious Exploit.CVE-2017-0147
Bkav malicious W32.Malware.C829D1B5
ClamAV malicious Win.Ransomware.Wanna-9769986-0
CrowdStrike malicious win/malicious_confidence_100% (D)
CTX malicious dll.exploit-kit.generic
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Encoder.11432
Elastic malicious malicious (high confidence)
Emsisoft malicious Exploit.CVE-2017-0147 (B)
ESET-NOD32 malicious Win64/Exploit.CVE-2017-0147.A trojan
F-Secure malicious Exploit.EXP/W32.CVE-2017-01.B
Fortinet malicious W64/Wanna.AK!tr
GData malicious Exploit.CVE-2017-0147
Google malicious Detected
Gridinsoft malicious Trojan.Win64.Downloader.oa!s1
huorong malicious Exploit/EquationDrug.a
Ikarus malicious Exploit.CVE-2017-0147
Jiangmin malicious Trojan.Wanna.e
K7AntiVirus malicious Trojan ( 0058feba1 )
K7GW malicious Trojan ( 0058feba1 )
Kaspersky malicious Trojan.Win32.Eb.s
Kingsoft malicious malware.kb.a.725
Malwarebytes malicious CVE20170147.Trojan.Exploit.DDS
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious ti!5D6FEEC1B6CE
Microsoft malicious Ransom:Win32/WannaCrypt!pz
MicroWorld-eScan malicious Exploit.CVE-2017-0147
NANO-Antivirus malicious Trojan.Win32.Wanna.epclsl
Panda malicious Trj/GdSda.A
Rising malicious Exploit.EternalBlue!1.AAED (CLASSIC)
Sangfor malicious Ransom.Win32.Save.WannaCry
SentinelOne malicious Static AI - Suspicious PE
Skyhigh malicious Ransom-WannaCry!DF3130A44D31
Sophos malicious Mal/Wanna-A
Symantec malicious Ransom.Wannacry
TACHYON malicious Ransom/W32.WannaCry.5298176
Tencent malicious Trojan.Win64.Wanna.a
TrellixENS malicious Ransom-WannaCry!DF3130A44D31
Varist malicious W64/S-e4f863f0!Eldorado
VBA32 malicious TrojanRansom.Win64.Wanna
VIPRE malicious Exploit.CVE-2017-0147
Webroot malicious W32.Trojan.Gen
Yandex malicious Trojan.GenAsa!DtE/ovQwFGg
Zillya malicious Trojan.Wanna.Win32.27
ZoneAlarm malicious Mal/Wanna-A

Details From VirusTotal

Basic Properties
MD5df3130a44d313198a0fada63789014f6
SHA-1144b20630fee23e20c9c6538fb867f6bc803dfe5
SHA-2565d6feec1b6ceb6d25f48b80016ef2aa3de4cae6f49cc03e6bb47b2f4ebbf985a
VHash156066655d151555bz47?z1
SSDEEP49152:jn2nAQVQVHQxBnBUPWo8c0JUZwffc+Q+kkNScWaUPWo8lOoGsVwZCGsVwZQ8pG6q:DyDVEHcUPt8c0J0wMV+lNSbaUPt8
TLSHT17A36F616A3E95624F5F77B31697A26740A7ABC95A93CD30F1280405E1DB2F80CEB1B73
File typeWin32 DLL
File type tagpedll
File extensiondll
MagicPE32+ executable (DLL) (console) x86-64, for MS Windows
File size5.1 MB
History
Creation date2017-05-11 12:20 UTC
First seen on VirusTotal2026-09-25 11:18 UTC
Last submission2026-09-25 11:18 UTC
Last analysis2026-09-25 11:18 UTC
Last modified on VirusTotal2026-09-25 23:29 UTC
Known Names
  • 3i60y2y.exe
  • 5d6feec1b6ceb6d25f48b80016ef2aa3de4cae6f49cc03e6bb47b2f4ebbf985a.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 5298176 bytes. Tags: dionaea, exe, WannaCry. Reporter: pawscobbler. First seen: 2026-09-25 11:15:37.

Remediations (10)

  • web:any.run

    WannaCry which is sometimes also called WCry or WanaCryptor is a ransomware malware, meaning that it encrypts files of its victims and demands a payment to restore the stolen information. Follow live malware statistics of this ransomware and get new reports, samples, IOCs, etc.

  • web:bazaar.abuse.ch

    WannaCry malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as WannaCry . Database Entry

  • web:en.wikipedia.org

    The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the form of bitcoin cryptocurrency. [4]

  • web:github.com

    A concise, step-by-step breakdown of WannaCry ransomware's static and dynamic behavior, complete with annotated code, automation scripts, and report-ready artifacts. - GitHub - AdamThaok/ Wannacry -malware-analysis: A concise, step-by-step breakdown of WannaCry ransomware's static and dynamic behavior, complete with annotated code, automation scripts, and report-ready artifacts.

  • web:github.com

    this repository contains the active DOS/Windows ransomware, WannaCry ⚠️ WARNING ⚠️ running this .exe file will damage your PC, use a secure burner VM / VirtualBox to test it link to download the .exe file here

  • web:www.adaptivesecurity.com

    WannaCry ransomware hit 150+ countries in a single day. How the worm spread, what it really cost, who was behind it, and what it still means for defenders.

  • web:www.dexpose.io

    Learn what WannaCry ransomware is, how the 2017 EternalBlue attack spread worldwide, its global impact, and how to detect, fix, and stop it today.

  • web:www.europol.europa.eu

    WannaCry is a dangerous combination of two malicious software components: A worm that has the ability to spread itself within networks without user interaction A ransomware variant that encrypts user files and then asks for money in order to decrypt the files. How does WannaCry spread? At the moment, the initial attack vector is being assessed.

  • web:www.ncsc.gov.uk

    'WannaCry' ransomware: guidance updates Jon L provides an update on the NCSC's guidance on the 'WannaCry' ransomware. Over the weekend, as we learnt more about the WannaCry ransomware, we published some short guides for enterprise administrators and for home users/small businesses.

  • web:www.pcrisk.com

    What is WannaCry ? Discovered by GrujaRS and belonging to the Phobos family, WannaCry (also known as WannaCryFake) is software categorized as ransomware. This malicious program encrypts files and keeps them locked unless the victim pays a ransom (purchases decryption software/tool).

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.