Cryakl Ransomware (email-iizomer@aol.com.ver-CL 1.2.0.0.id-<Random>-<M>@<D>@<Y> <H>@<M>@<S> <AM/PM><Random>.randomname-<Random>.<Random>.cbf
2018. 09. 04. 4,726
Distribution Method : Unknown MD5 : 181999dc674df8b103a6aefb02a354e9 Major Detection Name : Trojan.Encoder.567 (Dr.Web), Trojan:Win32/Bitrep.A (Microsoft) Encrypted File Pattern : email-iizomer@aol.com.ver-CL 1.2.0.0.id-<Random>-<Month>@<Day>@<Year> <Hour>@<Minute>@<Second> <AM/PM><Random>.randomname-<Random>.<Random>.cbf Malicious File Creation Location : - C:\Program Files (x86)\service.exe - C:\Program Files (x86)\- - C:\Program Files (x86)\-\flash info - C:\Program Files (x86)\-\flash info\service.exe - C:\Program Files (x86)\-\flash info\Uninstall.exe - C:\Program Files (x86)\-\flash info\Uninstall.ini - C:\Users\%UserName%\AppData\Local\Temp\desk.jpg - C:\Users\%UserName%\AppData\Local\Temp\service.exe Major Characteristics : - Offline Encryption - The Russian users targeted - Installed and disguised as program "Flash info 1.1.2", then encrypts files - Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\desk.bmp)
List