- Distribution Method : Unknown
- MD5 : 3ec87c7dc81bcfb96f14f2d28568d610
- Major Detection Name : MSIL/CryptoJoker.D!tr.ransom (Fortinet), Ransom.CryptoJoker (Malwarebytes)
- Encrypted File Pattern : .fully.nocry / .partially.nocry
- Payment Instruction File : CryptoJoker Recovery Information.txt
- Major Characteristics :
- Offline Encryption
- CryptoNar / ExecutionerPlus / JokerHourse Ransomware series
- Encrypts ".md, .txt" files and renames file with extension ".fully.nocry", while all other extension files are encrypted with extension ".partially.nocry", where partial 1,024 bytes of files are encrypted.
List