How to remove WannaCry.exe
- File Details
- Overview
- Analysis
WannaCry.exe
The module WannaCry.exe has been detected as Ransom.Filecoder
File Details
Product Name: |
|
Company Name: |
|
MD5: |
84c82835a5d21bbcf75a61706d8ab549 |
Size: |
3 MB |
First Published: |
2017-05-25 18:09:59 (7 years ago) |
Latest Published: |
2020-11-23 05:28:59 (4 years ago) |
Status: |
Ransom.Filecoder (on last analysis) |
|
Analysis Date: |
2020-11-23 05:28:59 (4 years ago) |
%desktop%\malware |
%commonappdata%\hcszafcun366 |
%sysdrive%\windows |
%sysdrive%\1\ransomware.wannacry |
%profile%\downloads |
%temp% |
%windir% |
%desktop%\malware pack\malware pack |
%desktop%\hcking tools |
ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa.exe |
WannaCry.exe |
tasksche.exe |
WannaCry.EXE |
qeriuwjhrf |
Taiwan |
26.3% |
|
Russia |
21.1% |
|
Brazil |
15.8% |
|
Ukraine |
10.5% |
|
India |
10.5% |
|
Romania |
5.3% |
|
France |
5.3% |
|
United States |
5.3% |
|
Windows 7 |
78.9% |
|
Windows 10 |
21.1% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000077ba |
Name |
Size of data |
MD5 |
.text |
28672 |
920e964050a1a5dd60dd00083fd541a2 |
.rdata |
24576 |
2c42611802d585e6eed68595876d1a15 |
.data |
8192 |
83506e37bd8b50cacabd480f8eb3849b |
.rsrc |
3448832 |
f99ce7dc94308f0a149a19e022e4c316 |