- Distribution Method : Unknown
- MD5 : 98a9d3fe8f64e5d34d143ed5a6b73eb0
- Major Detection Name : Ransom.Ufukt (Malwarebytes), Ransom_ITBOOK.THIAHAH (Trend Micro)
- Encrypted File Pattern : .fucked
- Payment Instruction File : READ__IT.txt
- Major Characteristics :
- Offline Encryption
- Hidden-Tear Open Source based Ransomware
- Jigsaw Ransomware impostor
- Changes desktop background (C:\Users\%UserName%\AppData\Roaming\ranx.jpg)
- Automatically delete encrypted files every hour
List