- Distribution Method : Unknown
- MD5 : 5990a32cddde5978959321237f9b0ee1
- Major Detection Name : Trojan-Ransom.Win32.Gen.xsb (Kaspersky), Ransom:MSIL/W3CryptoLocker.SK!MTB (Microsoft)
- Encrypted File Pattern : .xls
- Payment Instruction File : Read_Me.txt
- Major Characteristics :
- Offline Encryption
- Recovery Partition (M:\) and EFI System Partition (N:\) drives are activate.
- Terminate of many processes except system processes.
List