- Distribution Method : Unknown
- MD5 : a5f6b6e95ef8a26081259813ca18e17b
- Major Detection Name : Trojan/Win.BlackKingdom.C4387095 (AhnLab V3), Trojan-Ransom.Python.Blackin.n (Kaspersky)
- Encrypted File Pattern : <Original Filename>.<Original Extension> → .<4~7-Digit Random Extension>
- Payment Instruction File : decrypt_file.TxT
- Major Characteristics :
- Offline Encryption
- Python-based Ransomware
- Stop service (*sql*)
List