- Distribution Method : Automatic infection using exploit by visiting website
- MD5 : 9d904025f031fd529891ee032e3c7813
- Major Detection Name : Trojan.Ransom.AnteFrigus (ALYac), Win32:RansomX-gen [Ransom] (AVG)
- Encrypted File Pattern : .qrja / <Original Filename>.<Original Extension>
- Malicious File Creation Location :
- C:\Instraction
- C:\Instraction\qrja-readme.txt
- C:\qweasd
- C:\qweasd\test.txt
- C:\Users\%UserName%\AppData\Local\Temp\rad<Random>.tmp.exe
- Payment Instruction File : qrja-readme.txt
- Major Characteristics :
- Offline Encryption
- Sodinokibi Ransomware series
List