- Distribution Method : Unknown
- MD5 : e99cabc8fd754562e48e5d1e89951fb7
- Major Detection Name : Generic.Ransom.WannaSmile.29FBAF1D (BitDefender), Ransom-ZCrypt!E99CABC8FD75 (McAfee)
- Encrypted File Pattern : .WSmile
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\How to decrypt files.html
- C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WannaSmile.lnk
- C:\Users\%UserName%\AppData\Roaming\public.key
- C:\Users\%UserName%\AppData\Roaming\WannaSmile.exe
- \\autorun.inf
- \\system.exe
- Payment Instruction File : How to decrypt files.html
- Major Characteristics :
- Offline Encryption
- zCrypt Ransomware series
- The Persian users targeted
- Adds ransomware executable to USB Drive (\\autorun.inf, \\system.exe)
- Changes desktop background (C:\Users\%UserName%\Desktop\4.png)
List