- Distribution Method : Unknown
- MD5 : d4a0c9c356835b66150d76f7f4fda215
- Major Detection Name : Trojan.Ransom.GarrantyDecrypt (ALYac), Ransom.XARCryptor (Malwarebytes)
- Encrypted File Pattern : .cammora
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\_uninstalling_.png
- Payment Instruction File : #RECOVERY_FILES#.txt
- Major Characteristics :
- Offline Encryption
- Outsider Ransomware series
- Disable system restore (vssadmin.exe delete shadows /all /quiet)
List