- Distribution Method : Unknown
- MD5 : afa900026ca007fd85bb88fc22bd1697
- Major Detection Name : Ransom:MSIL/Ryzerlo.A (Microsoft), Ransom_EBOLA.THJBEAH (Trend Micro)
- Encrypted File Pattern : .101
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\000payload.exe
- C:\Users\%UserName%\Documents\pass.decrypt
- Payment Instruction File : READ_ME.txt
- Major Characteristics :
- Offline Encryption
- Hidden-Tear open source based ransomware
- Changes desktop background (C:\Users\%UserName%\AppData\Roaming\wallpaper.bmp)
List