- Distribution Method : Unknown
- MD5 : f3e593f06bec5ee4bcfd2e2b5fa4926f
- Major Detection Name : Trojan-Ransom.Win32.Shade.pyk (Kaspersky), Ransom:Win32/Troldesh.A (Microsoft)
- Encrypted File Pattern : <Random Filename>.<Random>.crypted000007 / .crypted000078
- Malicious File Creation Location :
- C:\ProgramData\Windows
- C:\ProgramData\Windows\csrss.exe
- Payment Instruction File : README1.txt ~ README10.txt
- Payment Instruction File :
- Offline Encryption
- Troldesh Ransomware series
- Use a "NNPPQTYSRVWDCFFNYK" Digital Signatures
- The English and Russian users targeted
- Disable system restore (vssadmin.exe Delete Shadows /All /Quiet)
- Changes desktop background (C:\Users\%UserName%\AppData\Roaming\<Random>.bmp)
List