- Distribution Method : Unknown
- MD5 : d1c2f79125818f1e7ea16784acf63712
- Major Detection Name : Generic.Ransom.WCryG.B6E79C46 (BitDefender), Ransom:MSIL/BlackHeart!MTB (Microsoft)
- Encrypted File Pattern : .locked
- Payment Instruction File : #解密我的文件#.txt / #DECRYPT MY FILES#.txt
- Major Characteristics :
- Offline Encryption
- The Chinese and English users targeted
- Disable system restore (vssadmin.exe delete shadows /all /quiet)
- After encryption, connects to website (https://2no.co/239Ys5) and displays message with image (5b88484028ab1.png)
List