Cryakl Ransomware (email-hola@all-ransomware.info.ver-CL 1.5.1.0.id-<Random>-<Random>.fname-<Original Filename>.<Original Extension>.doubleoffset)
2018. 06. 29. 6,893
Distribution Method : Remote access through Remote Desktop Protocol(RDP) or Terminal Services MD5 : 428d5484e385bc862cca92511596f0c9 Major Detection Name : Ransom:Win32/Cryakl.A (Microsoft), Trojan.Win32.S.Ransom.185344 (ViRobot) Encrypted File Pattern : email-hola@all-ransomware.info.ver-CL 1.5.1.0.id-<Random>-<Random>.fname-<Original Filename>.<Original Extension>.doubleoffset Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Temp\<Random>.exe Payment Instruction File : README.txt Major Characteristics : - Offline Encryption - Neutralizes system recovery by adding to task schedular: VssDataRestore, which executes command vssadmin delete shadows /all /quiet
List