- Distribution Method : Unknown
- MD5 : 1917d834fc947979ccc849ae74b60ce9
- Major Detection Name : Trojan.Ransom.CryptoJoker (ALYac), a variant of MSIL/Filecoder.CryptoJoker.C (ESET)
- Encrypted File Pattern : .fully.cryptojoker / .partially.cryptojoker
- Payment Instruction File : CryptoJoker Recovery Information.txt
- Major Characteristics :
- Offline Encryption
- CryptoNar / ExecutionerPlus / JokerHourse Ransomware series
- Encrypts ".md, .txt" files and renames file with extension ".fully.cryptojoker", while all other extension files are encrypted with extension ".partially.cryptojoker", where partial 1,024 bytes of files are encrypted.
List