- Distribution Method : Unknown
- MD5 : f86291e994c2e9cb0bb9650d362ee625
- Major Detection Name : Ransom.MrDec (Malwarebytes), Ransom_MRDEC.A (Trend Micro)
- Encrypted File Pattern : .<Original Extension> [ID]<Random>[ID]
- Malicious File Creation Location :
- C:\Windows\clerlog.bat
- C:\Windows\wincmd.exe
- C:\Decoding help.hta
- Payment Instruction File : Decoding help.hta
- Major Characteristics :
- Offline Encryption
- DXXD / LockCrypt Ransomware series
- Encryption starts after killing all process except listed in whitelist processes
- Turns off User Access Control (UAC)
- Disable system restore (vssadmin delete shadows /all)
- Deletes event log
List