- Distribution Method : Unknown
- MD5 : 59fe74c68bbc9e76affdf9f337fb81df
- Major Detection Name : Ransom.ChernoLocker (Malwarebytes), Ransom:Win32/Genasom (Microsoft)
- Encrypted File Pattern : .<Original Extension>(.CHERNOLOCKER)
- Major Characteristics :
- Offline Encryption
- Python-based Ransomware
- Create a fake ".NET Framework Initialization Error" message
List