- Distribution Method : Unknown
- MD5 : cf00c5806fd9be5886fe65735244bf1e
- Major Detection Name : Python/Filecoder.CE (ESET), Ransom.Win32.CRYPREN.THFAAAI (Trend Micro)
- Encrypted File Pattern : .[Unlock11@protonmail.com].enc
- Payment Instruction File : ReadMeToDecrypte.txt
- Major Characteristics :
- Offline Encryption
- Python-based Ransomware
- Changes desktop background (C:\Users\%UserName%\Pictures\WindowsBackground.png)
List