Ransomware · Ransomworm · Worm
WannaCry - invoice_greenanimals.pdf.exe
- Author
- Moise Medici
- Updated
- 15 Feb 2026 · Completed
- Difficulty
- Medium
- Platform
- Capabilities
- Tags
mssecsvc.exe
While getting the Windows 7 client exploited, there was curiosity about whether mssecsvc.exe was present in the Windows 7 machine, and it was actually found in C:\Windows as expected. It seems very similar to the original sample, even though the SHA256 hashes are different. However, they both have the same tasksche.exe resource attached, and a lot of similar strings, like:
mssecsvc2.0Microsoft Security Center (2.0) Service%s -m securityC:\%s\qeriuwjhrftasksche.exeCloseHandleCreateFileACreateProcessAhttp://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
tasksche.exeicacls . /grant Everyone:F /T /C /Qattrib +h .WNcry@2ol7
msg/m_filipino.wnrymsg/m_finnish.wnry~msg/m_french.wnrySo this is probably where the sample copies to when the Eternalblue exploit is successful and continues the infection on the new machine.