- Distribution Method : Unknown
- MD5 : 0f5111d54b52e0fb95c2ae430463d286
- Major Detection Name : a variant of Win32/Kryptik.GICF (ESET), Ransom_CRYPTOMIX.J (Trend Micro)
- Encrypted File Pattern : <Random Filename>.SYS
- Malicious File Creation Location :
- C:\ProgramData\<Random>.exe
- C:\ProgramData\<Random>.SYS
- C:\Users\%UserName%\Desktop\_HELP_INSTRUCTION.TXT
- Payment Instruction File : _HELP_INSTRUCTION.TXT
- Major Characteristics :
- Offline Encryption
- CryptFile2 / CryptoShield / HydraCrypt / Mole / Revenge / Zeta Ransomware series
List