- Distribution Method : Mail attachment file (.docm)
- MD5 : 0c7e59536a7be4a446bbe8b4f22e5880
- Major Detection Name : Trojan.Ransom.LooCipher.A (GData), Trojan-Ransom.Win32.Loo.a (Kaspersky)
- Encrypted File Pattern : .lcphr
- Payment Instruction File :
- C:\Users\%UserName%\Desktop\@Please_Read_Me.txt
- C:\Users\%UserName%\Desktop\c2056.ini
- Payment Instruction File : @Please_Read_Me.txt
- Major Characteristics :
- Offline Encryption
- Changes desktop background (C:\Users\%UserName%\Desktop\@LooCipher_wallpaper.bmp)
List