- Distribution Method : Mail attachment file
- MD5 : c7f42fe870949f3f3eeaba983892c47d
- Major Detection Name : Trojan.Ransom.Nemty (ALYac), Trojan.Win32.Nemty.199168 (ViRobot)
- Encrypted File Pattern : .NEMTY_<7-Digit Random>
- Payment Instruction File : NEMTY_<7-Digit Random>-DECRYPT.txt
- Major Characteristics :
- Offline Encryption
- Nefilim Ransomware series
- Checking IP address (api.db-ip.com)
- Disable system restore (bcdedit /set {default} bootstatuspolicy ignoreallfailures, bcdedit /set {default} recoveryenabled no, wbadmin delete catalog -quiet, wmic shadowcopy delete)
- Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\god.jpg)
List