- Distribution Method : Fake KMS Activator
- MD5 : cd9cfecbe009c9099a3f40e3118e7fbc
- Major Detection Name : RiskWare.KMS (Malwarebytes), Ransom:MSIL/Ramsil.SK!MTB (Microsoft)
- Encrypted File Pattern : <Original Filename>.<Original Extension>
- Payment Instruction File : README.txt
- Major Characteristics :
- Offline Encryption
- The Chinese and English users are targeted.
List