- Distribution Method : Unknown
- MD5 : c68b5f446d47d00b04d7af6260c591bd
- Major Detection Name : Trojan.Ransom.Blind (ALYac), Ransom_BLIND.THBAFH (Trend Micro)
- Encrypted File Pattern : .[blind@airmail.cc].blind2
- Payment Instrucition File : How_Decrypt_Files.txt
- Major Characteristics :
- Offline Encryption
- Block processes execution (oracle.exe, sqlservr.exe)
- Disable system restore (vssadmin.exe Delete Shadows /All /Quiet)
List