- Distribution Method : Unknown
- MD5 : 3beb3d466bcc0977ec2dd66d72ab6bb3
- Major Detection Name : Trojan/Win32.Nemty.C4089140 (AhnLab V3), Ransom.Nefilim (Malwarebytes)
- Encrypted File Pattern : .NEPHILIM
- Payment Instruction File : NEPHILIM-DECRYPT.txt
- Major Characteristics :
- Offline Encryption
- Nemty / Pluto Ransomware series
- Use a "Red GmbH" Digital Signatures
- Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\god.jpg)
List