Indicator of Compromise Search
Bulk Lookup
✦ IPv4 Address ✦ Domain ✦ MD5/SHA1/SHA256 Hash ✦ URL
INDICATOR
b6c603ba9cd54717b72a4346782dc50e4e5bf5cc4b7684e92047a042d8a045e7
SHA256 ⚠ 3 PULSE HITS
↓ CSV ↓ JSON
55
/100
HIGH
CONFIDENCE LEVEL
THREAT CONFIDENCE ANALYSIS
HIGH 55/100 confidence
Strong evidence of malicious activity across multiple sources. Prioritise investigation.
CLEAN LOW MED HIGH CRIT
0 25 50 75 100
OTX
20/30
3 pulses
VIRUSTOTAL
35/35
61/73 detected
ABUSEIPDB
/25
IPv4 only
URLHAUS
0/10
NOT LISTED
General Information
Hashb6c603ba9cd54717b72a4346782dc50e4e5bf5cc4b7684e92047a042d8a045e7
File TypeFileHash-SHA256
AlienVault OTX Analysis ↗ View on OTX
3
PULSE HITS
Pulse Hits 3
Indicator Type SHA256
Threat Level
ASSOCIATED PULSES
PULSE NAMEDATE
WannaCry linked Lazarus indicators 2017-05-24
WannaCry linked Lazarus indicators 2026-03-26
WannaCry linked Lazarus indicators 2023-12-06
VirusTotal Analysis ↗ View on VirusTotal
61/73
DETECTIONS
MALICIOUS
Malicious 61
Suspicious 0
Harmless 0
Undetected 5
Reputation 0
File Name lhdfrgui.exe
File Type Win32 EXE
File Size 3636.0 KB
TOP DETECTIONS
VENDORRESULT
ALYac Trojan.Ransom.WannaCryptor
APEX Malicious
AVG Sf:WNCryLdr-A [Trj]
Acronis suspicious
Ad-Aware Trojan.Ransom.WannaCryptor.H
AhnLab-V3 Trojan/Win32.WannaCryptor.R200572
Alibaba Ransom:Win32/WannaCry.1
Antiy-AVL Trojan/Generic.ASMalwS.20277B2
Avast Sf:WNCryLdr-A [Trj]
Avira TR/Ransom.Gen
URLhaus (abuse.ch) ↗ View on URLhaus
✓ NOT LISTED No malicious activity found in URLhaus database.