- Distribution Method : Unknown
- MD5 : 571d39c9d14668e3e8f438d80e64ed50
- Major Detection Name : Ransom:MSIL/Ryzerlo.B (Microsoft), Ransom.HiddenTear!g1 (Norton)
- Encrypted File Pattern : .beer
- Malicious File Creation Location :
- C:\%UserName%
- C:\%UserName%\@Chromium.exe
- C:\Users\%UserName%\Desktop\@FILE-DECRYPTER.exe
- C:\Users\%UserName%\Desktop\@FILES-HELP-<Computer Name>.txt
- Payment Instruction File : @FILES-HELP-<Computer Name>.txt
- Major Characteristics :
- Offline Encryption
- Hidden-Tear Open Source based Ransomware
- Changes desktop background (C:\%UserName%\Chrome.jpg)
List