top title background image
flash

wannacry.bin.dll

Status: finished
Submission Time: 2022-04-20 04:35:12 +02:00
Malicious
Ransomware
Trojan
Evader
Miner
Coinhive GhostRat Mini RAT Xmrig

Comments

Tags

  • exe
  • wannacry

Details

  • Analysis ID:
    611749
  • API (Web) ID:
    979262
  • Analysis Started:
    2022-04-20 04:36:08 +02:00
  • Analysis Finished:
    2022-04-20 04:43:31 +02:00
  • MD5:
    e4836f631ee02b9dd20a567474f7ab72
  • SHA1:
    e9ca88fd62b52d0bbcaf78bbda2862c0bce39000
  • SHA256:
    ef7bac23b920c86b72c70ff6eb23504ab472e0c7d6a7c28461fd8fa846e1a4ae
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 7/35
malicious
Score: 16/27
malicious
malicious

URLs

Name Detection
http://promo.nwdenb.ru/jump.php?si
http://games-desktop.com/cgi-bin/main.cgi?__rnd__
http://stat.zvu.com/installer.html?
Click to see the 97 hidden entries
http://a.pomf.cat/
http://gamtbeel.hw591.com/hezuo/ad6html.html
http://setup.maxrevinstaller.com/setup?lcid=
http://ww.robint.us/u.js
http://www.download-servers.com/vuupc/dl.php?rr=AP
http://java.sun.com/products/autodl/j2se
http://www.consumerinput.com/
http://setup2.iminent.com/
http://tongji.bianya.cc/popup.ashx?type=0
http://54.191.185.232/
http://159.8.31.231/baset.exe
http://download1.ihyip.pw/
http://www.bubbledock.es/legal/eula/license/
http://54.193.9.202/
http://www.insead.dk/wp-content/uploads/jquery-update.php
http://d1.tripdestinfo.com/x64.ziphttp://d1.tripdestinfo.com/x32.ziphttp://d1.tripdestinfo.com/ct3.z
http://xa.xingcloud.com
http://sstatic1.histats.com/0.gif?
http://45.63.107.19/PhilaeAp05.cplcmd
http://reports.montiera.com/reports/jsRprt.srf?rid=nsis&nsisState=
http://goo.gl/
http://dl.client.baidu.com/union/getbdbrowser.php?tn=29065018_115.exe
http://www.radpdf.com
http://sub.flash-frozen.info/init/
http://www.anasayfa.im/?utm_source=
http://dl.dqwjnewkwefewamail.com/
http://www.2flyer.com/buy.html
http://joelosteel.gdn/pi.php
http://%37%32.%32%33%37.%31%37.%33%36/%63%6f%75%6e%74%65%72/%69%6e%64%65%78.%70%68%70
http://imamasim.com/modules/mod_modules/jquery-update.php
http://190.14.37.19/~thaisupp/document
http://unstiff.pw
http://91.188.11
http://53server.com/counter/index.php
http://grizzli-counter.com/id120/index.php
http://91.188.12
http://gosinaj.cynthiamartinez.com.ar/link15.hotbox
http://54.187.129.3/
http://521bbs.yi.org/ms.exec:
http://appfindr.org/terms.html
http://198.50.114.16
http://b%1.openfrost.net/sinder.php
http://91.238.134.77/
http://%s/%04d-%02d/%04d%02d%02d%02d%02d%02d.pnghttp://%s/imgres?q=b64:
http://appllicatiionew.com/download/v
http://alikaptanoglu.blogspot.com
http://54.215.150.138/
http://google.com
http://download.oneinstaller.com/installer/?dl=1
http://track.dgeneratr.com/starthelp.php?p=
http://91.238.13
http://up.cp-reffi.xyz/error.php?string=
http://services.$
http://dl.iwin.com/games/iWinGamesSetup.exe
https://www.4shared.com/downloadhelper/stat?type=%STATYPE%
http://shadu.baidu.com/index/mini_2to1_download/
http://videoplayerupdates.com/
http://download.phpnuke.org/installers/nsis/
http://a1us6j2z.recordgate.com/vnmsq40nj1q7a.php?
http://%37%32.%32%33%37.%31%37.%33%36/%63%6f%75%6e%74%65%72%31/%69%6e%64%65%78.%70%68%70
http://disk.karelia.pro/2adftYz/392.png
http://q%2eta%6fg%75.%6fr%67%2ec%6e:95
http://kupeer.com/
http://45.32.128.225/
http://finder.strangled.net/?pubid=Searching
http://os.tiviviv.com/Vittalia/
http://5.39.219.206/
http://www.fenomen-games.com/dhome.htm
http://5.39.219.
http://www.wajam.com/webenhancer/logging
http://www.freerip.com
http://ahkscript.org
http://54.215.15
http://%s/information.php?a=%s&b=%d&c=%d
http://54.187.12
http://errors.statsmyapp.com/installer-error.gif?action=wrapper
http://data.biphysics.com/r?_=
http://javafx.com
http://%s:%d/%s.aspRCPT
http://www.wikitweak.com/downloads/pp.exe?s=
https://alpha.com/epicapp/createnode?affiliateId=%s&subId=%s
http://54.193.9.
http://198.23.250.211/1908/http://192.210.195.50/1009/:
http://www.cashnback.com/termos.html
http://cdn.che.moe/ymufnn.exe
http://downloadconfirm.net/file/
http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline
http://dl.dqwjne
https://www.paypal.com/en_us/i/logo/paypal_logo.gif
http://webprotectorplus.com
http://tbapi.search.ask.com
http://tikotin.com
http://iwin.ourtoolbar.com/eula/
http://www.4shared.com/download/TZDZz2RBba/aTubeWD9.exehttp://www.4shared.com/download/-u-Zcvyfce/Sk
http://www.abetterstart.com/navigator.php
http://www.coupish.com/terms.php
http://bot.ibitlive.deC:

Dropped files

No malicious files found. See full and IOC report for all dropped files.