- Distribution Method : Unknown
- MD5 : 66e68c8dceb001aa9d0ece7b22d4fdf5
- Major Detection Name : Trojan.Ransom.JSWorm (ALYac), Win32:CrypterX-gen [Trj] (Avast)
- Encrypted File Pattern : .[ID-<Random>][symmetries@tutamail.com].JSWRM
- Malicious File Creation Location :
- C:\ProgramData\JSWRM-DECRYPT.hta
- C:\ProgramData\key.<Random>.JSWRM
- Payment Instruction File : JSWRM-DECRYPT.hta
- Major Characteristics :
- Offline Encryption
- Block processes execution (dns.exe, sqlserver.exe, sqlwriter.exe, store.exe)
- Disable system restore (vssadmin.exe delete shadows /all /quiet, bcdedit /set {default} bootstatuspolicy ignoreallfailures -y, bcdedit /set {default} recoveryenabled No -y, wbadmin delete catalog -quiet, wmic shadowcopy delete -y)
List