- Distribution Method : Unknown
- MD5 : 5b003545b7728b85f03d8b210cd6711b
- Major Detection Name : DeepScan:Generic.Ransom.Hiddentear.A.B011982D (BitDefender), Ransom.MSIL.PROTVS.SM (Trend Micro)
- Encrypted File Pattern : .happy
- Payment Instruction File : HIT BY RANSOMWARE.txt
- Major Characteristics :
- Offline Encryption
- Disable and Blocks Registry Editor (DisableRegistryTools), Command Prompt (DisableCMD) and Task Manager (DisableTaskMgr)
- Disable system restore (WMIC.exe shadowcopy delete)
- Send the information to cnoa3@mail.ee (System, FileZilla, Chrome and Screen Shot)
- Take a desktop screen shot (C:\Users\%UserName%\AppData\Local\screen.jpg)
List