- Distribution Method : Unknown
- MD5 : 4a3593bef0f80767ab05720c869d91e7
- Major Detection Name : Trojan/Win32.FileCoder.C2898833 (AhnLab V3), Ransom.Win32.FORMA.THABABAH (Trend Micro)
- Encrypted File Pattern : .locked
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\Temp\1.Bat
- C:\Users\%UserName%\AppData\Local\Temp\2.bat
- C:\Users\%UserName%\AppData\Local\Temp\3.bat
- C:\Users\%UserName%\AppData\Local\Temp\4.bat
- C:\Users\%UserName%\AppData\Local\Temp\admin.exe
- C:\Users\%UserName%\AppData\Local\Temp\AdobeAcrobatReader.exe
- C:\Users\%UserName%\AppData\Local\Temp\FORM.exe
- C:\Users\%UserName%\AppData\Local\Temp\FORMA.exe
- C:\Users\%UserName%\AppData\Local\Temp\invisible.vbs
- C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\syswin32.lnk
- C:\Users\%UserName%\Desktop\ODSZYFRFUJ_PLIKI_TERAZ.txt
- C:\Users\%UserName%\SystemKey.txt
- C:\Users\%UserName%\table.exe
- Payment Instruction File : ODSZYFRFUJ_PLIKI_TERAZ.txt
- Major Characteristics :
- Offline Encryption
- The Polish users are targeted.
- Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\wallpaper3.bmp)
List