WannaCry installs a copy of the decryptor, @WanaDecryptor@.exe, in each folder along with a ransom note. This technique stages and writes a PneumaEX agent and corresponding .lnk file.
View Command
To view this TTPs command, you must be logged in with a professional or enterprise license.