- Distribution Method : Automatic infection using exploit by visiting website
- MD5 : 6c0001f0d13afb949458b8e320092d09
- Major Detection Name : Trojan/Win32.Savefiles.C2701916 (AhnLab V3), Ransom:Win32/Chaicha (Microsoft)
- Encrypted File Pattern : .SAVEfiles
- Malicious File Creation Location :
- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\!!!SAVE_FILES_INFO!!!.txt
- C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\!!!SAVE_FILES_INFO!!!.txt
- Payment Instruction File : !!!SAVE_FILES_INFO!!!.txt
- Major Characteristics :
- Offline Encryption
- KeyPass Ransomware series
- Excludes Windows and web browser (Google, Internet Explorer, Firefox) folders
List