- Distribution Method : Unknown
- MD5 : 8a3a86299769d23a964372d0f9c94f97
- Major Detection Name : Ransom-ApolloCry!8A3A86299769 (McAfee), Ransom:Win32/Apollo.A (Microsoft)
- Encrypted File Pattern : .locked
- Payment Instruction File : DOSYALARI-KURTAR 0.txt / DOSYALARI-KURTAR 1.txt / DOSYALARI-KURTAR 2.txt / DOSYALARI-KURTAR 0.url / DOSYALARI-KURTAR 1.url / DOSYALARI-KURTAR 2.url
- Major Characteristics :
- Offline Encryption
- The Turkish users targeted
- Use an invalid Microsoft Digital Signatures
- Changes desktop background(C:\desktodsadasdasp.bmp)
- Includes web browser (Chrome, Firefox) login information collection
List