- Distribution Method : Unknown
- MD5 : 1e60050db59e3d977d2a928fff3d34a6
- Major Detection Name : Trojan.Ransom.Iron (ALYac), a variant of Win32/Filecoder.NHS (ESET)
- Encrypted File Pattern : .encry
- Payment Instruction File : !HELP_YOUR_FILES.HTML
- Major Characteristics :
- Offline Encryption
- Maktub Locker Ransomware series
- Block processes execution (emagent.exe, fdlauncher.exe, mysqld.exe, nmesrvc.exe, sqlwriter.exe, tnslsnr.exe etc.)
List