- Distribution Method : Unknown
- MD5 : 2119dd9b5018f0ce7f9806f69a580e6d
- Major Detection Name : Ransomware/Win.Homemade.R436368 (AhnLab V3), Ransom:MSIL/Cryptolocker.PAD!MTB (Microsoft)
- Encrypted File Pattern : .henry217
- Payment Instruction File : readme.txt
- Major Characteristics : Offline Encryption
List