- Distribution Method : Unknown
- MD5 : d7d38fe6f2e94f0d0210a9e15ef45e4e
- Major Detection Name : Generic.Ransom.CloudSword.405FE2D0 (BitDefender), Ransom_WARRIOR.THHOGAH (Trend Micro)
- Encrypted File Pattern : Encrypted<Number>.THBEC
- Malicious File Creation Location :
- C:\RansomWarrior 1.0
- C:\RansomWarrior 1.0\Date_Happened.THBEC
- C:\RansomWarrior 1.0\DEX.THBEC
- C:\RansomWarrior 1.0\FileNamesCrypted.THBEC
- C:\RansomWarrior 1.0\FreeFileNamesCrypted.THBEC
- C:\RansomWarrior 1.0\Happened.THBEC
- C:\RansomWarrior 1.0\KeyCrypt.THBEC
- C:\RansomWarrior 1.0\Number_Of_Encrypted_Files.THBEC
- C:\RansomWarrior 1.0\TEX.THBEC
- Major Characteristics : Offline Encryption
List