- Distribution Method : Unknown
- MD5 : 3d1cc4ef33bad0e39c757fce317ef82a
- Major Detection Name : a variant of Win32/Filecoder.Snake.A (ESET), Ransom.Ekans (Malwarebytes)
- Encrypted File Pattern : <Original Filename>.<Original Extension> → .<Original Extension><5-Digit English Random>
- Payment Instruction File : Fix-Your-Files.txt
- Major Characteristics :
- Offline Encryption
- Block processes execution (avgui.exe, mbamtray.exe, msftesql.exe, ocssd.exe, onenote.exe, sqlwriter.exe etc.)
List