- Distribution Method : Unknown
- MD5 : 62d53ba6f00e830bee85b0cd6a207546
- Major Detection Name : Ransom.Panther (Malwarebytes), Ransom.Win32.PANTHER.A (Trend Micro)
- Encrypted File Pattern : .panther
- Malicious File Creation Location : C:\Users\%UserName%\Desktop\LOCKED_README.txt
- Payment Instruction File : LOCKED_README.txt
- Major Characteristics :
- Offline Encryption
- The Chinese users are targeted.
- Disable system restore (vssadmin delete shadows /all /quiet, wmic shadowcopy delete /nointeractive)
- Changes desktop background (C:\Users\%UserName%\Desktop\LOCKED_README.bmp)
List