← Reports

Ransomware · Ransomworm · Worm

WannaCry - invoice_greenanimals.pdf.exe

Author
Moise Medici
Updated
15 Feb 2026 · Completed
Difficulty
Medium
Platform
Windows
Capabilities
Command and Control C2 CommunicationCommand Execution via Powershell Cmd BashFile EncryptionPersistence Mechanisms
Tags
C++WannaCryptor

Indicators of Compromise

Network

  • www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com Kill-switch domain, requested over DNS and HTTP.
  • ~3,000 IP addresses SMB propagation targets, too many to list usefully here.

Files

  • @Please_Read_Me@.txt user desktop
  • @WanaDecryptor@.exe user desktop
  • C:\Windows\tasksche.exe
  • C:\ProgramData\jzaobqby070 directory name may differ per execution or system

Services

  • mssecsvc2.0 display name: Microsoft Security Center (2.0) Service
  • pafhcsxxsfdrw600

Bitcoin address

  • 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94

Hashes · SHA-256

  • b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25 @WanaDecryptor@.exe
  • ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa C:\Windows\tasksche.exe and C:\ProgramData\pafhcsxxsfdrw600\tasksche.exe
  • 4a468603fdcb7a2eb5770705898cf9ef37aade532a7964642ecd705a74794b79 C:\ProgramData\pafhcsxxsfdrw600\taskdl.exe
  • 2ca2d550e603d74dedda03156023135b38da3630cb014e3d00b1263358c5f00d C:\ProgramData\pafhcsxxsfdrw600\taskse.exe
  • 1be0b96d502c268cb40da97a16952d89674a9329cb60bac81a96e01cf7356830 kbdlv.dll
  • 9411c59a83c8c32a925d53a902bef168ebe5b403a88ab4d8dfe807fd7435dd9e launcher.dll
  • 24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c C:\Windows\mssecsvc.exe

Appendix