malwarelearn
Home Learn Reports Tools Tags About
← Reports

Ransomware · Ransomworm · Worm

WannaCry - invoice_greenanimals.pdf.exe

Author
Moise Medici
Updated
15 Feb 2026 · Completed
Difficulty
Medium
Platform
Windows
Capabilities
Command and Control C2 CommunicationCommand Execution via Powershell Cmd BashFile EncryptionPersistence Mechanisms
Tags
C++WannaCryptor

Windows 7

Section 21 of 27: Windows 7
← Question 8 and Question 11 SMB Network Analysis →
Q1Is the sample showing any potential malicious behaviour?Q2If yes, what are the potential capabilities it has?Q3Which information can we find to proceed in the next phase of the analysis?Q4Where is the resource being dropped? And what is the SHA256 of the file? Is it launcher.dll?Q5Which service is getting created?Q6What is the domain being used for?Q7What is C:\%s\qeriuwjhrf?Q8What is C:\WINDOWS\mssecsvc.exe?Q9What registry keys are written?Q10Bonus: Given that it is a WannaCry sample, can we get the kill switch key?Q11What is launcher.dll?Q12What is the password to decrypt the zip file?Q13What is the .bat file 122221764070810.bat?Q14What is the .vbs file m.vbs?Q15Since tasksche.exe is spawning taskse.exe and taskdl.exe, what are their responsibilities?Q16What are the wnry files about?Q17What is kbdlv.dll?Q18What is the purpose of f.wnry?

○ open✓ answered– not raised yet

On this page

File InfoExecutive SummaryDiagramQuestions ListBasic Static AnalysisBasic Dynamic AnalysisQuestion 5Question 4Question 9Question 15Advanced AnalysisQuestion 15Question 6 and Question 10Question 7Other Open QuestionsQuestion 12Question 16Question 17, Question 13 and Question 14Question 18Question 8 and Question 11Windows 7SMB Network Analysis`mssecsvc.exe`Indicators of CompromiseFile Format to EncryptFull Import Address TableAppendix

Type to search every report and article.