- Distribution Method : Unknown
- MD5 : d87fcd8d2bf450b0056a151e9a116f72
- Major Detection Name : Trojan.PowerShell.Ransom.E (BitDefender), Ransom-SunCrypt (McAfee)
- Encrypted File Pattern : .<64-Digit Random Extension>
- Payment Instruction File : YOUR_FILES_ARE_ENCRYPTED.HTML
- Major Characteristics :
- Offline Encryption
- File encryption using Windows PowerShell (C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe)
List