- Distribution Method : Unknown
- MD5 : 815598d2d0486f60e50dd6406c145cca
- Major Detection Name : Generic.Ransom.GarrantDecrypt.6578F575 (BitDefender), Ransom_GARRANTYCRYPT.THAABIAH (Trend Micro)
- Encrypted File Pattern : .decryptgarranty
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\_uninstalling_.png
- Payment Instruction File : #RECOVERY_FILES#.txt
- Major Characteristics :
- Offline Encryption
- Outsider Ransomware series
- Disable system restore (vssadmin.exe delete shadows /all /quiet)
List