Ransomware · Ransomworm · Worm
WannaCry - invoice_greenanimals.pdf.exe
- Author
- Moise Medici
- Updated
- 15 Feb 2026 · Completed
- Difficulty
- Medium
- Platform
- Capabilities
- Tags
Question 18
The first time the machine was infected, the content of f.wnry was a list of .rtf files previously containing the VSCode license. After restoring a snapshot and reinfecting the system the content is:
C:\Users\REM\Desktop\Malware\Day6\officeDocs\edit1-invoice.zip.WNCRYC:\Users\REM\AppData\Local\Programs\Python\Python39\Tools\pynche\webcolors.txt.WNCRYC:\Users\REM\Pictures\REM_Desktop-1.jpg.WNCRYC:\$Recycle.Bin\S-1-5-21-1866265027-1870850910-1579135973-1000\$R4ITUGO\VMware Tools\vm-support.vbs.WNCRYC:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRYC:\Users\REM\.vscode\extensions\ms-vscode.powershell-2023.1.0\examples\PathProcessingNoWildcards.ps1.WNCRYC:\Users\REM\.vscode\extensions\ms-vscode.powershell-2023.1.0\modules\PowerShellEditorServices\Start-EditorServices.ps1.WNCRYC:\Users\REM\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\base\worker\workerMain.js.WNCRYC:\Users\REM\AppData\Local\Programs\Microsoft VS Code\resources\app\out\vs\workbench\contrib\output\common\outputLinkComputer.js.WNCRYC:\Users\REM\AppData\Local\Programs\Python\Python39\include\ceval.h.WNCRYIn fact, they are. The Decryptor UI allows decrypting some files as “proof” that they can be restored, to make the victim more inclined to pay the ransom.