- Distribution Method : Unknown
- MD5 : d6d7aedb721146d961c4c634ab5f72c3
- Encrypted File Pattern : .<1-Digit English Small Letter><2-Digit Number><2-Digit English Small Letter><2-Digit Number>@LOCKED
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\<12-Digit English Small Letter>.txt
- Payment Instruction File : <12-Digit English Small Letter>.txt
- Major Characteristics :
- Offline Encryption
- Kozy.Jozy / Naampa / Unlckr Ransomware series
- The English and Russian users targeted
List