- Distribution Method : Unknown
- MD5 : a499a1d530c8f034ecf7ce009377f92f
- Major Detection Name : Ransom:Win32/Vcrypt (Microsoft), Ransom_DVIDCRYPT.A (Trend Micro)
- Encrypted File Pattern : .david
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\get_my_files.txt
- Payment Instruction File : get_my_files.txt
- Major Characteristics : Offline Encryption
List