- Distribution Method : Unknown
- MD5 : df5f6dd725fc67b25dde32946f8a2930
- Major Detection Name : Ransom.Godra (Malwarebytes), Troj/Ransom-EUA (Sophos)
- Encrypted File Pattern : .godra
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Temp\KAKO OTKLJUČATI VAŠE DATOTEKE.log
- Payment Instruction File : KAKO OTKLJUČATI VAŠE DATOTEKE.log
- Major Characteristics :
- Offline Encryption
- The Bosanski and Hrvatski users targeted.
- Disguised as execution of running PDF document (%Temp%\Prijedlog_za_ovrhu_urbr_220-2017.pdf / 12 Bytes)
List