- Distribution Method : Unknown
- MD5 : 27def0c68ee542333a8a99995429273a
- Major Detection Name : Gen:Variant.Ransom.Xorist.82 (BitDefender), A Variant Of Win32/GenKryptik.CXPE (ESET)
- Encrypted File Pattern : <Original Filename>.<Original Extension>.<1 Space Blank>
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Temp\0Uocyxv8V4p4rX9.exe
- Payment Instruction File : HOW TO DECRYPT FILES.txt
- Major Characteristics :
- Offline Encryption
- Boom / Xorist-Frozen Ransomware series
- File encryption using system file "C:\Windows\SysWOW64\attrib.exe"
List