← Reports

Ransomware · Ransomworm · Worm

WannaCry - invoice_greenanimals.pdf.exe

Author
Moise Medici
Updated
15 Feb 2026 · Completed
Difficulty
Medium
Platform
Windows
Capabilities
Command and Control C2 CommunicationCommand Execution via Powershell Cmd BashFile EncryptionPersistence Mechanisms
Tags
C++WannaCryptor

Question 18

The first time the machine was infected, the content of f.wnry was a list of .rtf files previously containing the VSCode license. After restoring a snapshot and reinfecting the system the content is:

C:\Users\REM\Desktop\Malware\Day6\officeDocs\edit1-invoice.zip.WNCRY
C:\Users\REM\AppData\Local\Programs\Python\Python39\Tools\pynche\webcolors.txt.WNCRY
C:\Users\REM\Pictures\REM_Desktop-1.jpg.WNCRY
C:\$Recycle.Bin\S-1-5-21-1866265027-1870850910-1579135973-1000\$R4ITUGO\VMware Tools\vm-support.vbs.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRY
C:\Users\REM\.vscode\extensions\ms-vscode.powershell-2023.1.0\examples\PathProcessingNoWildcards.ps1.WNCRY
C:\Users\REM\.vscode\extensions\ms-vscode.powershell-2023.1.0\modules\PowerShellEditorServices\Start-EditorServices.ps1.WNCRY
C:\Users\REM\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\base\worker\workerMain.js.WNCRY
C:\Users\REM\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\workbench\contrib\output\common\outputLinkComputer.js.WNCRY
C:\Users\REM\AppData\Local\Programs\Python\Python39\include\ceval.h.WNCRY

In fact, they are. The Decryptor UI allows decrypting some files as “proof” that they can be restored, to make the victim more inclined to pay the ransom.

The Decrypt dialog listing the files the operators will restore for free as proof that decryption works.
Fig. 28: The Decrypt dialog listing the files the operators will restore for free as proof that decryption works.