- Distribution Method : Unknown
- MD5 : d44a9b93b52652c702884d1c958c7ad2
- Major Detection Name : MSIL.Trojan-Ransom.Shiva.A (GData), Ransom.HiddenTear (Malwarebytes)
- Encrypted File Pattern : .<6-Digit Random Extension>
- Payment Instruction File : READ_IT.html
- Major Characteristics :
- SHIVA Open Source based Ransomware
- Encrypt target files with 6 alphanumeric extensions
- Disable system restore (vssadmin delete shadows /all /quiet, wmic shadowcopy delete, bcdedit /set {default} bootstatuspolicy ignoreallfailures, bcdedit /set {default} recoveryenabled no, wbadmin delete catalog -quiet)
- Changes desktop background (C:\Users\%UserName%\Desktop\bg.png)
List