- Distribution Method : Unknown
- MD5 : fa7bc80be251a4ab8f68be18149b50f1
- Major Detection Name : Generic.Ransom.Balaclava.A0922C1A (BitDefender), Ransom.Win32.BALACLAVA.B (Trend Micro)
- Encrypted File Pattern : .KEY0004
- Payment Instruction File : HOW_TO_RECOVERY_FILES.txt
- Major Characteristics :
- Offline Encrytion
- Recovery Partition (A:\) and EFI System Partition (B:\) drives are activate.
List