- Distribution Method : Unknown
- MD5 : ff9dc25128897a3f1a4659422b6f0ada
- Major Detection Name : Ransom:Win32/Genasom (Microsoft), Ransom_CYRON.A (Trend Micro)
- Encrypted File Pattern : .CYRON
- Major Characteristics :
- Offline Encryption
- Disable and Blocks Windows Explorer (taskkill.exe /F /IM explorer.exe)
- Disable and Blocks Task Manager (Taskmgr.exe)
- When click on "Shut Down" button, shutsdown windows automatically. (cmd.exe /k shutdown -s -t 1)
List