- Distribution Method : Unknown
- MD5 : 28945b625617cfdcc444b428de0a7a00
- Major Detection Name : Trojan.Ransom.BitPaymer.C (BitDefender), Win32.Trojan-Ransom.Bitpaymer.B (GData)
- Encrypted File Pattern : .locked
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\<Random Foldername>
- C:\Users\%UserName%\AppData\Local\<Random Foldername>\<Random>.exe
- C:\Users\%UserName%\AppData\Local\<Random>:exe
- Payment Instruction File : <Original Filename>.<Original Extension>.readme_txt
- Major Characteristics :
- Offline Encryption
- Streamer Ransomware series
- Creates executable ADS (Alternate Data Stream) file and file encryption.
List