- Distribution Method : Unknown
- MD5 : 25c923bcfda1c7d97fb1b48b8b6e6ad4
- Major Detection Name : Gen:Heur.Ransom.HiddenTears.1 (BitDefender), Ransom.HiddenTear (Malwarebytes)
- Encrypted File Pattern : .OOFNIK
- Malicious File Creation Location : C:\Users\%UserName%\files.txt
- Major Characteristics :
- Offline Encryption
- Arescrypt open source based ransomware
- Create a fake "Error: Operating system incompatible. Exiting." message
- Encryption guide using Text-to-Speech (TTS) function
List