- Distribution Method : Disguised as a crack file
- MD5 : e3f1bf864da10b1f8b10a5f368bc563f
- Major Detection Name : Trojan.Ransom.Waldo (ALYac), Ransom.Win64.WALDOW.A (Trend Micro)
- Encrypted File Pattern : <Original Filename>.<Original Extension>
- Malicious File Creation Location : C:\Users\%UserName%\Desktop\READ_ME.txt
- Payment Instruction File : READ_ME.txt
- Major Characteristics :
- Offline Encryption
- Persephone Ransomware series
- Data corruption method
List