s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-d71abe40c3f0048d572b18d2ad93829be9dd89478b87868dae72e633dbd87ac0 high

📛 Threat Title

WannaCry: d71abe40c3f0048d572b18d2ad93829be9dd89478b87868dae72e633dbd87ac0

Category: WannaCry Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 5298176 bytes. Tags: dionaea, exe, WannaCry. Reporter: pawscobbler. First seen: 2026-09-25 09:16:29.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 0cdadfa1098d845dd3b4cf92625b5f04

IOC database

Type
hash_imphash
Value
0cdadfa1098d845dd3b4cf92625b5f04
First seen
Last seen
Attached to this threat
Appears in
186 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 d71abe40c3f0048d572b18d2ad93829be9dd89478b87868dae72e633dbd87ac0 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/d71abe40c3f0048d572b18d2ad93829be9dd89478b87868dae72e633dbd87ac0

IOC database

Type
hash_sha256
Value
d71abe40c3f0048d572b18d2ad93829be9dd89478b87868dae72e633dbd87ac0
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
WannaCry

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/d71abe40c3f0048d572b18d2ad93829be9dd89478b87868dae72e633dbd87ac0

hash_sha1 a39635d1e5dcb60b03a5673db626997112de4585 VT 57 / 74

IOC database

Type
hash_sha1
Value
a39635d1e5dcb60b03a5673db626997112de4585
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 57 of 74 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.WannaCryptor.R200894
Alibaba malicious Ransom:Win32/WannaCrypt.50a
alibabacloud malicious RansomWare:Win/Wannacryptor.6d8dbf74
ALYac malicious Trojan.Agent.DEAQ
Antiy-AVL malicious Trojan[Exploit]/Win64.CVE-2017-0147
APEX malicious Malicious
Arcabit malicious Trojan.Agent.DEAQ
Avira malicious HEUR/AGEN.1302689
Baidu malicious Win32.Worm.Rbot.a
BitDefender malicious Trojan.Agent.DEAQ
Bkav malicious W64.AIDetectMalware
CAT-QuickHeal malicious Ransom.WcryG.S28363974
ClamAV malicious Win.Ransomware.Wanna-9769986-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious dll.trojan.wanna
Cylance malicious Unsafe
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Encoder.11432
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.Agent.DEAQ (B)
ESET-NOD32 malicious Win64/Exploit.CVE-2017-0147.A trojan
F-Secure malicious Heuristic.HEUR/AGEN.1302689
Fortinet malicious W64/Wanna.AK!tr.ransom
GData malicious Trojan.Agent.DEAQ
Gridinsoft malicious Trojan.Win64.Downloader.oa!s1
huorong malicious Exploit/EquationDrug.a
Ikarus malicious Exploit.CVE-2017-0147
Jiangmin malicious Trojan.Wanna.e
K7AntiVirus malicious Trojan ( 0058feba1 )
K7GW malicious Trojan ( 0058feba1 )
Kaspersky malicious Trojan.Win32.Eb.s
Kingsoft malicious Win32.Exploit.MS17-010.cb
Lionic malicious Trojan.Win32.Wanna.ts4v
Malwarebytes malicious Generic.Malware.Gen.DDS
MaxSecure malicious Trojan.Malware.325197105.susgen
McAfeeD malicious ti!D71ABE40C3F0
Microsoft malicious Ransom:Win32/WannaCrypt!pz
MicroWorld-eScan malicious Trojan.Agent.DEAQ
Paloalto malicious generic.ml
Panda malicious Trj/GdSda.A
Rising malicious Exploit.EternalBlue!1.AAED (CLASSIC)
Sangfor malicious Ransom.Win32.Wannacrypt_0.se2
Skyhigh malicious Ransom!14F6307D042F
Sophos malicious Mal/Wanna-A
Symantec malicious ML.Attribute.HighConfidence
TACHYON malicious Ransom/W32.WannaCry.5298176
Tencent malicious Malware.Win32.Gencirc.10bb25c3
Varist malicious W64/S-e4f863f0!Eldorado
VBA32 malicious TrojanRansom.Win64.Wanna
VIPRE malicious Trojan.Agent.DEAQ
VirIT malicious Trojan.Win32.Genus.LWU
ViRobot malicious Trojan.Win.Z.Wanna.5298176.BI
Webroot malicious W32.Trojan.Gen
Yandex malicious Trojan.GenAsa!DtE/ovQwFGg
Zillya malicious Trojan.Wanna.Win32.27
ZoneAlarm malicious Mal/Wanna-A

Details From VirusTotal

Basic Properties
MD514f6307d042f8be76bd9acd0d78867f9
SHA-1a39635d1e5dcb60b03a5673db626997112de4585
SHA-256d71abe40c3f0048d572b18d2ad93829be9dd89478b87868dae72e633dbd87ac0
VHash156066655d151565bz47?z1
SSDEEP98304:DKnPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2H:DKnPe1Cxcxk3ZAEUadzR8yc4H
TLSHT1B63633D462A861FCE1410EB484B38E16F3B33C6967BA4F0F97C0867A1D53B97AB90751
File typeWin32 DLL
File type tagpedll
File extensiondll
MagicPE32+ executable (DLL) (console) x86-64, for MS Windows
File size5.1 MB
History
Creation date2017-05-11 12:20 UTC
First seen on VirusTotal2026-01-12 05:37 UTC
Last submission2026-01-12 05:37 UTC
Last analysis2026-01-20 13:12 UTC
Last modified on VirusTotal2026-09-25 11:43 UTC
Known Names
  • dlhrc.exe
  • kvjuzo.exe
hash_md5 14f6307d042f8be76bd9acd0d78867f9 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/14f6307d042f8be76bd9acd0d78867f9

IOC database

Type
hash_md5
Value
14f6307d042f8be76bd9acd0d78867f9
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/14f6307d042f8be76bd9acd0d78867f9

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 5298176 bytes. Tags: dionaea, exe, WannaCry. Reporter: pawscobbler. First seen: 2026-09-25 09:16:29.

Remediations (10)

  • web:any.run

    WannaCry which is sometimes also called WCry or WanaCryptor is a ransomware malware, meaning that it encrypts files of its victims and demands a payment to restore the stolen information. Follow live malware statistics of this ransomware and get new reports, samples, IOCs, etc.

  • web:en.wikipedia.org

    The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the form of bitcoin cryptocurrency. [4]

  • web:github.com

    A concise, step-by-step breakdown of WannaCry ransomware's static and dynamic behavior, complete with annotated code, automation scripts, and report-ready artifacts. - GitHub - AdamThaok/ Wannacry -malware-analysis: A concise, step-by-step breakdown of WannaCry ransomware's static and dynamic behavior, complete with annotated code, automation scripts, and report-ready artifacts.

  • web:github.com

    This is the Original Wannacry executable file. This is a Live Copy of the Wannacry Ransomware wich was responsable for Thousands of Infections on Windows machines.

  • web:malwaretips.com

    This guide teaches you how to remove Wanacry ransomware for free by following easy step-by-step instructions.

  • web:www.adaptivesecurity.com

    WannaCry ransomware hit 150+ countries in a single day. How the worm spread, what it really cost, who was behind it, and what it still means for defenders.

  • web:www.dexpose.io

    Learn what WannaCry ransomware is, how the 2017 EternalBlue attack spread worldwide, its global impact, and how to detect, fix, and stop it today.

  • web:www.europol.europa.eu

    WannaCry is a dangerous combination of two malicious software components: A worm that has the ability to spread itself within networks without user interaction A ransomware variant that encrypts user files and then asks for money in order to decrypt the files. How does WannaCry spread? At the moment, the initial attack vector is being assessed.

  • web:www.microsoft.com

    For more information about this ransomware (which is also known as WannaCrypt, WannaCry , WanaCrypt0r, WCrypt, or WCRY), you can read the following entries on the Windows Security blog and Microsoft Security Response Center: WannaCrypt ransomware worm targets out-of-date systems Customer Guidance for WannaCrypt attacks

  • web:www.pcrisk.com

    What is WannaCry ? Discovered by GrujaRS and belonging to the Phobos family, WannaCry (also known as WannaCryFake) is software categorized as ransomware. This malicious program encrypts files and keeps them locked unless the victim pays a ransom (purchases decryption software/tool).

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.