- Distribution Method : Remote access through Remote Desktop Protocol(RDP) or Terminal Services
- MD5 : aa654cedb092670eabd81fd21ef0a7f4
- Major Detection Name : Trojan.Ransom.BigBobRoss (ALYac), Ransom.Win32.DMR.A (Trend Micro)
- Encrypted File Pattern : [id=<Random>]<Original Filename>.<Original Extension>.DMR64
- Malicious File Creation Location : C:\\!!! READ THIS !!!.hta
- Payment Instruction File : !!! READ THIS !!!.hta
- Major Characteristics :
- Offline Encryption
- BigBobRoss / Clown Ransomware series
List