- Distribution Method : Unknown
- MD5 : 58284d741ed273587e91d59b75d1bfbe
- Major Detection Name : Troj/Jigsaw-K (Sophos), Ransom_JIGSAW.SM (Trend Micro)
- Encrypted File Pattern : .locked
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\Adobe (x86)
- C:\Users\%UserName%\AppData\Local\Adobe (x86)\AcroRd32.exe
- C:\Users\%UserName%\AppData\Roaming\firefox install Folder
- C:\Users\%UserName%\AppData\Roaming\firefox install Folder\Address.txt
- C:\Users\%UserName%\AppData\Roaming\firefox install Folder\dr
- C:\Users\%UserName%\AppData\Roaming\firefox install Folder\EncryptedFileList.txt
- C:\Users\%UserName%\AppData\Roaming\Google (x86)
- C:\Users\%UserName%\AppData\Roaming\Google (x86)\Chrome32.exe
- Major Characteristics :
- Offline Encryption
- Ramsey Ransomware series
- Create a fake ".NET Framework Initialization Error" message
- Developed by a Korean
- Automatically delete encrypted files every hour
List