- Distribution Method : Unknown
- MD5 : 1780f3a86beceb242aa81afecf6d1c01
- Major Detection Name : W32/Nemty.A!tr.ransom (Fortinet), Ransom.Nemty (Malwarebytes)
- Encrypted File Pattern : ._NEMTY_<7-Digit Random>_
- Payment Instruction File : _NEMTY_<7-Digit Random>_-DECRYPT.txt
- Major Characteristics :
- Nefilim / Pluto Ransomware series
- Disable system restore (vssadmin.exe delete shadows /all /quiet, bcdedit /set {default} bootstatuspolicy ignoreallfailures, bcdedit /set {default} recoveryenabled no, wbadmin delete catalog -quiet, wmic shadowcopy delete)
List