- Distribution Method : Unknown
- MD5 : 93b0e83334836a4a811fef354d31fdb5
- Major Detection Name : Ransom:Win32/Genasom (Microsoft), Ransom_RAPID.THEBAAH (Trend Micro)
- Encrypted File Pattern : <Random Number Filename>.<5 Digit Big Letter Random Extension>
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\<Random>\<Random>.exe
- C:\Users\%UserName%\AppData\Roaming\<Random>\ReadMe.txt
- Payment Instrucition File : DECRYPT.<Encryption Extension>.txt / ReadMe.txt
- Major Characteristics : Offline Encryption
List