- Distribution Method : Unknown
- MD5 : 5a43d2db5c8cc3b8ec273aa470ccc931
- Major Detection Name : a variant of Win32/Filecoder.Outsider.B (ESET), Ransom.Win32.OUTSIDER.THABAOAH (Trend Micro)
- Encrypted File Pattern : .protected
- Payment Instruction File : HOW_TO_RESTORE_FILES.txt
- Major Characteristics :
- Offline Encryption
- Block processes execution (nan.exe, null.exe)
- Disable system restore (vssadmin.exe delete shadows /all /quiet)
List