- Distribution Method : Unknown
- MD5 : 827329ecc2b4d3436e9d89d6345dbb6d
- Major Detection Name : Ransom.Satan (Malwarebytes), Ransom.Satan (Norton)
- Encrypted File Pattern : .satan
- Malicious File Creation Location :
- C:\ST_V2
- C:\ST_V2\KSession
- C:\ST_V2\TConfig
- C:\Notice.exe
- Payment Instruction File : ReadMe_@.TXT
- Major Characteristics :
- Offline Encryption
- DBGer Ransomware series
- Chinese, English, and Korean users targeted
- Block processes execution (fdhost.exe, fdlauncher.exe, mysqld.exe, nmesrvc.exe, sqlagent.exe, sqlservr.exe etc.)
List