- Distribution Method : Unknown
- MD5 : 7a4d1c3f034cc8af39271123286403dd
- Major Detection Name : Trojan.Ransom.Everbe (ALYac), Ransom_EVERVBE.THHBCAH (Trend Micro)
- Encrypted File Pattern : .[divine@cock.lu].divine
- Payment Instruction File : !=How_to_decrypt_files=!.txt
- Major Characteristics :
- Offline Encryption
- Embrace / PainLocker Ransomware series
- Block processes execution (ntdbsmgr.exe, oracle.exe, sqlserv.exe, sqlservr.exe, sqlwriter.exe etc.)
- Disable system restore (vssadmin delete shadows /all /quiet)
List