- Distribution Method : Unknown
- MD5 : c168073d11a16ffb676af578b6102bfe
- Major Detection Name: MSIL/Filecoder.Jigsaw.B (ESET), Ransom:MSIL/JigsawLocker.A (Microsoft)
- Encrypted File Pattern : .hush
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\Microsoft\RAVCpl64.exe
- C:\Users\%UserName%\AppData\Roaming\Microsoft\RealtekDrive.exe
- Major Characteristics : 오프라인 암호화(Offline Encryption), ".NET Framework Initialization Error" 가짜 오류 메시지 생성, 1시간 단위로 암호화된 파일 자동 삭제