- Distribution Method : Unknown
- MD5 : 2d725061d4892da0938416f3d3da3c57
- Encrypted File Pattern : .<6-Digit Random Extension>
- Malicious File Creation Location : C:\Users\%UserName%\Desktop\<Encryption Extension>-Readme.txt
- Payment Instruction File : <Encryption Extension>-Readme.txt
- Major Characteristics :
- Offline Encryption
- Block processes execution (encsvc.exe, excel.exe, mspub.exe, sqbcoreservice.exe, store.exe, thunderbird.exe etc.)
List