- Distribution Method : Unknown
- MD5 : af7d3a7d91108056c79599f50b0f52a2
- Major Detection Name : Trojan.Ransom.HiddenTear (ALYac), Ransom.HiddenTear!g1 (Norton)
- Encrypted File Pattern : .locked
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\Microsoft\Windows\winsec.exe (Hidden Attribute)
- C:\Users\%UserName%\Desktop\Desbloquear.exe
- Major Characteristics :
- Offline Encryption
- Hidden-Tear open source based ransomware
- The Portugese users targeted
List