- Distribution Method : Unknown
- MD5 : 9e7578c00e039b6b6537543be53efb50
- Major Detection Name : Trojan.Ransom.CryptoMix (ALYac), Ransom:Win32/Genasom (Microsoft)
- Encrypted File Pattern : <Random Filename>.BACKUP
- Malicious File Creation Location : C:\ProgramData\<Random>.exe
- Payment Instruction File : _HELP_INSTRUCTION.TXT
- Major Characteristics :
- Offline Encryption
- CryptFile2 / CryptoShield / HydraCrypt / Mole / Revenge / Zeta Ransomware series
List