- Distribution Method : Unknown
- MD5 : 60ce57a7112dc9c5f1967b3115df9332
- Major Detection Name : Trojan.Encoder.26898 (Dr.Web), a variant of MSIL/Kryptik.PFR (ESET)
- Encrypted File Pattern : .locked
- Malicious File Creation Location :
- C:\Users\%UserName%\SystemKey.txt
- C:\Users\%UserName%\table.exe
- C:\Users\%UserName%\winsys.txt
- C:\Users\%UserName%\winsys2.txt
- C:\Users\%UserName%\winsys3.txt
- Payment Instruction File : ODSZYFRFUJ_PLIKI_TERAZ.txt
- Major Characteristics :
- Offline Encryption
- Hidden-Tear open source based ransomware
- The Polish users targeted
- Disable and Blocks Task Manager (DisableTaskmgr)
List