- Distribution Method : Unknown
- MD5 : 7e86eaf181882a8163d156f1493699ca
- Major Detection Name : Trojan.Ransom.Embrace (ALYac), Ransom_EMBRACE.THEBIAH (Trend Micro)
- Encrypted File Pattern : .[embrace@airmail.cc].embrace
- Payment Instruction File : !=How_recovery_files=!.txt
- Major Characteristics :
- Offline Encryption
- Everbe / PainLocker Ransomware series
- Block processes execution (MsDtsSrvr.exe, ntdbsmgr.exe, oracle.exe, sqlserv.exe, sqlservr.exe, sqlwriter.exe etc.)
- Disable system restore (vssadmin delete shadows /all /quiet)
List