- Distribution Method : Remote access through Remote Desktop Protocol(RDP) or Terminal Services
- MD5 : afa5ff4852209f479f11f151d29bbde5
- Encrypted File Pattern : .[<Random>].[paybtcforkeys@aol.com].makop
- Payment Instruction File : readme-warning.txt
- Major Characteristics :
- Offline Encryption
- Disable system restore (vssadmin delete shadows /all /quiet, wbadmin delete catalog -quiet, wmic shadowcopy delete)
List