× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: a4704be3a77f989693188a4a505b62719ffe87718f8891ab5d3e1de1b1a57572
File name: wanna fake.exe
Detection ratio: 40 / 67
Analysis date: 2018-07-23 10:46:54 UTC ( 2 months, 4 weeks ago )
Antivirus Result Update
Ad-Aware Application.Generic.1721414 20180723
AegisLab Ransom.Fakewcry.Gen!c 20180723
AhnLab-V3 Trojan/Win32.FakeWanna.C1957755 20180723
ALYac Misc.Hoax 20180723
Antiy-AVL Trojan/Win32.BTSGeneric 20180723
Arcabit Application.Generic.D1A4446 20180723
Avast Win32:Malware-gen 20180723
AVG Win32:Malware-gen 20180723
AVware Trojan.Win32.Generic!BT 20180723
BitDefender Application.Generic.1721414 20180723
CrowdStrike Falcon (ML) malicious_confidence_70% (D) 20180530
Cybereason malicious.bb29d3 20180225
Cylance Unsafe 20180723
Cyren W32/GenPua.587163EB!Olympus 20180723
Emsisoft Application.Generic.1721414 (B) 20180723
ESET-NOD32 a variant of MSIL/Hoax.FakeFilecoder.M 20180723
F-Secure Application.Generic.1721414 20180723
GData Application.Generic.1721414 20180723
Ikarus not-a-virus.Hoax.WannaCry 20180723
K7AntiVirus Trojan ( 0050de481 ) 20180723
K7GW Trojan ( 0050de481 ) 20180723
Kaspersky Hoax.MSIL.FakeCoder.i 20180723
MAX malware (ai score=77) 20180723
McAfee Ransom-WannaCry!587163EBB29D 20180723
McAfee-GW-Edition Ransom-WannaCry!587163EBB29D 20180723
Microsoft Ransom:Win32/WannaCrypt!rfn 20180723
eScan Application.Generic.1721414 20180723
Panda Trj/GdSda.A 20180722
Rising Ransom.WannaCrypt!8.E720 (CLOUD) 20180723
SentinelOne (Static ML) static engine - malicious 20180701
Sophos AV Troj/FakeWana-A 20180723
Symantec Ransom.Wannacry 20180723
Tencent Msil.Risk.Hoax.Swkv 20180723
TrendMicro Ransom_FAKEWCRY.B 20180723
TrendMicro-HouseCall Ransom_FAKEWCRY.B 20180723
VBA32 Trojan.MSIL.gen.a.4 20180720
VIPRE Trojan.Win32.Generic!BT 20180723
ViRobot Hoax.WannaCry.578560 20180723
Webroot W32.Trojan.Gen 20180723
ZoneAlarm by Check Point Hoax.MSIL.FakeCoder.i 20180723
Alibaba 20180713
Avast-Mobile 20180723
Avira (no cloud) 20180723
Baidu 20180723
Bkav 20180723
CAT-QuickHeal 20180723
ClamAV 20180723
CMC 20180723
Comodo 20180723
DrWeb 20180723
eGambit 20180723
Endgame 20180711
F-Prot 20180723
Fortinet 20180723
Sophos ML 20180717
Jiangmin 20180723
Kingsoft 20180723
Malwarebytes 20180723
NANO-Antivirus 20180723
Palo Alto Networks (Known Signatures) 20180723
Qihoo-360 20180723
SUPERAntiSpyware 20180722
TACHYON 20180723
TheHacker 20180723
TotalDefense 20180722
Trustlook 20180723
Yandex 20180720
Zillya 20180720
Zoner 20180723
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright © 2017

Product wanna fake
Original name wanna fake.exe
Internal name wanna fake.exe
File version 1.0.0.0
Description wanna fake
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2017-05-15 12:54:53
Entry Point 0x0008B87E
Number of sections 4
.NET details
Module Version ID d4ff264a-6529-4c13-9d0b-5455f19f49c6
TypeLib ID b37bca76-cfa1-44de-a981-7d5c2a3c5fef
PE sections
PE imports
_CorExeMain
Number of PE resources by type
RT_ICON 7
RT_GROUP_ICON 1
RT_VERSION 1
RT_MANIFEST 1
Number of PE resources by language
NEUTRAL 10
PE resources
Debug information
ExifTool file metadata
SubsystemVersion
4.0

LinkerVersion
11.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.0.0.0

UninitializedDataSize
0

LanguageCode
Neutral

FileFlagsMask
0x003f

CharacterSet
Unicode

InitializedDataSize
13824

EntryPoint
0x8b87e

OriginalFileName
wanna fake.exe

MIMEType
application/octet-stream

LegalCopyright
Copyright 2017

FileVersion
1.0.0.0

TimeStamp
2017:05:15 13:54:53+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
wanna fake.exe

ProductVersion
1.0.0.0

FileDescription
wanna fake

OSVersion
4.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CodeSize
563712

ProductName
wanna fake

ProductVersionNumber
1.0.0.0

FileTypeExtension
exe

ObjectFileType
Executable application

AssemblyVersion
1.0.0.0

Compressed bundles
File identification
MD5 587163ebb29d37762be9b65b4553733a
SHA1 1688aadda5db2d63fdd296edd65a8063db1a3eec
SHA256 a4704be3a77f989693188a4a505b62719ffe87718f8891ab5d3e1de1b1a57572
ssdeep
6144:vQfvuXwa/F2wHHG/BY1oDShdi6QgEOr26QD3T:OmX37H7hA6P26Mj

authentihash e75328cf572222a36dc206f27faef1fb4e6941d73a19d9ed32b7a5ab6c736cc1
imphash f34d5f2d4577ed6d9ceec516c1f5a744
File size 565.0 KB ( 578560 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly

TrID Generic CIL Executable (.NET, Mono, etc.) (55.0%)
Win64 Executable (generic) (20.7%)
Windows screen saver (9.8%)
Win32 Dynamic Link Library (generic) (4.9%)
Win32 Executable (generic) (3.3%)
Tags
peexe assembly

VirusTotal metadata
First submission 2017-05-15 13:16:10 UTC ( 1 year, 5 months ago )
Last submission 2017-05-15 13:16:10 UTC ( 1 year, 5 months ago )
File names MS17-010.exe
wanna fake.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!