- Distribution Method : Unknown
- MD5 : 0293b9b0ba24a023fc66df72de73b703
- Major Detection Name : Gen:Heur.Ransom.HiddenTears.1 (BitDefender), Ransom:MSIL/Ryzerlo.A (Microsoft)
- Encrypted File Pattern : .locked
- Malicious File Creation Location :
- C:\%UserName%
- C:\%UserName%\Rand123
- C:\%UserName%\Rand123\local.exe - Payment Instruction File : READ_ME.txt
- Major Characteristics :
- Offline Encryption
- Balbaz / Brazilian / CryBrazil / Cryp70n1c Army / EyLamo / Magic / Technicy Ransomware series
- Hidden-Tear open source based ransomware
- Changes desktop background (C:\%UserName%\ransom.jpg)
List