- Distribution Method : Unknown
- MD5 : 369898dbec256e458bfe6c7cf78ff842
- Major Detection Name : a variant of Win64/Filecoder.Y (ESET), Ransom-O (McAfee)
- Encrypted File Pattern : .seed
- Payment Instruction File : !#_How_to_decrypt_files_#!.txt
- Major Characteristics :
- Offline Encryption
- Embrace / PainLocker Ransomware series
- Use a "Project NSRM Ltd" Digital Signatures
- Block processes execution (MsDtsSrvr.exe, ntdbsmgr.exe, oracle.exe, sqlserv.exe, sqlservr.exe, sqlwriter.exe etc.)
- Disable system restore (vssadmin delete shadows /all /quiet)
List