Question 1: Is the sample showing any potential malicious behaviour?
Question 2: If yes, what are the potential capabilities it has?
Question 3: Which information can we find to proceed in the next phase of the analysis?
Question 4: Where is the resource being dropped? And what is the SHA256 of the file? Is it launcher.dll?
Question 5: Which service is getting created?
Question 6: What is the domain being used for?
Question 7: What is C:\%s\qeriuwjhrf?
Question 8: What is C:\WINDOWS\mssecsvc.exe?
Question 9: What registry keys are written?
Question 10: Bonus: Given that it is a WannaCry sample, can we get the kill switch key?
Question 11: What is launcher.dll?
Question 12: What is the password to decrypt the zip file?
Question 13: What is the .bat file 122221764070810.bat?
Question 14: What is the .vbs file m.vbs?
Question 15: Since tasksche.exe is spawning taskse.exe and taskdl.exe, what are their responsibilities?
Question 16: What are the wnry files about?
Question 17: What is kbdlv.dll?
Question 18: What is the purpose of f.wnry?