- Distribution Method : Unknown
- MD5 : 68cf2070d8fb4963211cfa4f2daa72e5
- Major Detection Name : Trojan/Win32.KillDisk.C1737779 (AhnLab V3), Trojan.Disakil (Norton)
- Encrypted File Pattern : <Original Filename>.<Original Extension>
- Major Characteristics :
- Offline Encryption
- Block processes execution (avpui.exe, egui.exe, ekrn.exe, mfevtps.exe, msascui.exe, msmpeng.exe etc.)
- Deletes event log (wevtutil clear-log Application, wevtutil clear-log Security, wevtutil clear-log Setup, wevtutil clear-log System)
List