- Distribution Method : Unknown
- MD5 : e7fd75937a55416e9740489431dcaae0
- Major Detection Name : Ransom.Russenger (Malwarebytes), Ransom_RUSSENGER.THBBOAH (Trend Micro)
- Encrypted File Pattern : .messenger-<Random>
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Инструкция по дешифровке.txt
- Payment Instruction File : Инструкция по дешифровке.txt
- Major Characteristics :
- Offline Encryption
- The Russian users targeted.
List