- Distribution Method : Disguised as an Adobe crack file
- MD5 : cce4a845984bb1eefdda1f7608ee4277
- Major Detection Name : Trojan.Ransom.Persephone (ALYac), Trojan-Ransom.Win32.Encoder.her (Kaspersky)
- Encrypted File Pattern : .persephone
- Malicious File Creation Location : C:\Users\%UserName%\Desktop\READ.txt
- Payment Instruction File : READ.txt
- Major Characteristics :
- Offline Encryption
- Waldo Ransomware series
List