- Distribution Method : Unknown
- MD5 : a7c7de1cab698e9cbef2fd14bdd2f8ea
- Encrypted File Pattern : .missing
- Malicious File Creation Location : C:\Program Files (x86)\Windows NT\explorer.exe
- Payment Instruction File : <Original Filename>.<Original Extension>.Contact_Data_Recovery.txt
- Major Characteristics :
- Offline Encryption
- ApocalypseVM Ransomware series
- Disable system restore (vssadmin delete shadows /all /quiet)
List