- MD5 : d7d38fe6f2e94f0d0210a9e15ef45e4e
- 주요 탐지명 : Generic.Ransom.CloudSword.405FE2D0 (BitDefender), Ransom_WARRIOR.THHOGAH (Trend Micro)
- 파일 암호화 패턴 : Encrypted<숫자>.THBEC
- 악성 파일 생성 위치 :
- C:\RansomWarrior 1.0
- C:\RansomWarrior 1.0\Date_Happened.THBEC
- C:\RansomWarrior 1.0\DEX.THBEC
- C:\RansomWarrior 1.0\FileNamesCrypted.THBEC
- C:\RansomWarrior 1.0\FreeFileNamesCrypted.THBEC
- C:\RansomWarrior 1.0\Happened.THBEC
- C:\RansomWarrior 1.0\KeyCrypt.THBEC
- C:\RansomWarrior 1.0\Number_Of_Encrypted_Files.THBEC
- C:\RansomWarrior 1.0\TEX.THBEC
- 주요 특징 : 오프라인 암호화(Offline Encryption)
목록