- Distribution Method : Unknown
- MD5 : 1489f140fa72592951b602ed4c246807
- Major Detection Name : Ransom:MSIL/Shezkrypt.A (Microsoft), Ransom_IMPS.THCBGAH (Trend Micro)
- Encrypted File Pattern : .sorry
- Malicious File Creation Location : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\How Recovery Files.txt
- Payment Instruction File : How Recovery Files.txt
- Major Characteristics :
- Offline Encryption
- Hidden-Tear open source based ransomware
- Disable system restore (vssadmin delete shadows /all /quiet)
List