- Distribution Method : Unknown
- MD5 : b047a4ab1726fe7414484493c60d5870
- Major Detection Name : Generic.Ransom.Everbe.90A281DE (BitDefender), Ransom_PAIN.THECOAH (Trend Micro)
- Encrypted File Pattern : .[pain@cock.lu].pain
- Payment Instruction File : !=How_recovery_files=!.txt
- Major Characteristics :
- Offline Encryption
- Embrace / Everbe Ransomware series
- Block processes execution (MsDtsSrvr.exe, ntdbsmgr.exe, oracle.exe, sqlserv.exe, sqlservr.exe, sqlwriter.exe etc.)
- Disable system restore (vssadmin delete shadows /all /quiet)
List