- Distribution Method : Unknown
- MD5 : a48e7a8e6a12dc097171d3bcd0df32ee
- Major Detection Name : Ransom.FileCryptor (Malwarebytes), Ransom:MSIL/CryptoLocker.DH!MTB (Microsoft)
- Encrypted File Pattern : ._enc
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\metadata._dontencrypt
- C:\Windows\System32\Tasks\Decryptor
- Major Characteristics :
- Offline Encryption
- Encryption guide using Text-to-Speech (TTS) function
- Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\wallpaper.bmp)
List