- Distribution Method : Unknown
- MD5 : 5a843982bb525573b3b65c16801cefef
- Major Detection Name : Ransom:Win32/Genasom (Microsoft), Ransom.Enciphered (Norton)
- Encrypted File Pattern : .fff
- Payment Instrucition File : READTHISHIT.txt
- Major Characteristics :
- Offline Encryption
- Disable system restore (vssadmin.exe delete shadows /all /quiet)
List