- Distribution Method : Unknown
- MD5 : 8f7307e55256b74f6847bffb93fa51fd
- Major Detection Name : Gen:Heur.Ransom.HiddenTears.1 (BitDefender), Ransom.HiddenTear!g1 (Norton)
- Encrypted File Pattern : .technicy
- Malicious File Creation Location :
- C:\%UserName%
- C:\%UserName%\Rand123
- C:\%UserName%\Rand123\local.exe
- Payment Instruction File : czytaj.txt
- Major Characteristics :
- Offline Encryption
- Balbaz / Brazilian / CryBrazil / Cryp70n1c Army / EyLamo / Magic / Skull HT Ransomware series
- Hidden-Tear open source based ransomware
- The Polish users targeted
- Changes desktop background (C:\%UserName%\technicy.png)
List