- Distribution Method : Unknown
- MD5 : fdadc123d5739afac19247e4d9418eae
- Major Detection Name : MSIL/Filecoder.Crypt12.A (ESET), Ransom:MSIL/Natiris.A (Microsoft)
- Encrypted File Pattern : .<Original Extension>=<Random>=mortalis_certamen@aol.com.crypt12
- Major Characteristics :
- Offline Encryption
- Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\wallpaper.bmp)
List