- Distribution Method : Unknown
- MD5 : 92be7e0bade538fa5bd3f4e71cb6586e
- Major Detection Name : Generic.Ransom.Thanatos.044F4B44 (BitDefender), Ransom:Win32/Tosthin.A (Microsoft)
- Encrypted File Pattern : .PICO
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\<15-Digit Number>
- C:\Users\%UserName%\AppData\Roaming\<15-Digit Number>\<10-Digit Number>.exe
- C:\Users\%UserName%\Desktop\README.txt
- Payment Instruction File : README.txt
- Major Characteristics :
- Offline Encryption
- Pico Ransomware series
- Requests payment in BTC / ETH crypto currency
List