- Distribution Method : Unknown
- MD5 : edc39d6c6198e24db56f29dfbb988cd8
- Major Detection Name : Trojan.Ransom.Everbe (ALYac), Gen:Variant.Ransom.EvilLocker.1 (BitDefender)
- Encrypted File Pattern : .[youhaveonechance@cock.li].lightning
- Payment Instruction File : !=How_to_decrypt_files=!.txt
- Major Characteristics :
- Offline Encryption
- Embrace / Evil Locker / PainLocker Ransomware series
- Block processes execution (MsDtsSrvr.exe, ntdbsmgr.exe, oracle.exe, sqlserv.exe, sqlservr.exe, sqlwriter.exe etc.)
- Disable system restore (vssadmin delete shadows /all /quiet)
List