- Distribution Method : Unknown
- MD5 : 923abfc4d809f3c055920cc8f30356a3
- Major Detection Name : Trojan.RansomKD.5767299 (BitDefender), Ransom:Win32/Genasom (Microsoft)
- Encrypted File Pattern : .OXR
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\Temp\File Decryptor.exe
- C:\Users\%UserName%\AppData\Local\Temp\sysadmin.txt
- C:\Users\%UserName%\Desktop\File Decryptor.exe
- Payment Instruction File : instructions.txt
- Major Characteristics :
- Offline Encryption
- Hidden-Tear open source based ransomware
- Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\wallpaper.bmp)
List