← Reports

Ransomware · Ransomworm · Worm

WannaCry - invoice_greenanimals.pdf.exe

Author
Moise Medici
Updated
15 Feb 2026 · Completed
Difficulty
Medium
Platform
Windows
Capabilities
Command and Control C2 CommunicationCommand Execution via Powershell Cmd BashFile EncryptionPersistence Mechanisms
Tags
C++WannaCryptor

Diagram

The following diagram summarizes the files that are extracted, generated, or loaded in memory:

The files extracted, generated or loaded in memory by the sample, from the dropped tasksche.exe down to the .wnry payloads.
Fig. 1: The files extracted, generated or loaded in memory by the sample, from the dropped tasksche.exe down to the .wnry payloads.