- Distribution Method : Automatic infection using exploit by visiting website
- MD5 : 9dd52ccbd52ef67e490fd85320f4a043
- Major Detection Name : Trojan/Win32.Cerber.R200901 (AhnLab V3), Trojan-Ransom.Win32.Zerber.ecrd (Kaspersky)
- Encrypted File Pattern : <Random Filename>.<4 Digits Random Extension>
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Temp\<Random>.exe
- Payment Instruction File : _R_E_A_D___T_H_I_S___<Random>_.hta / _R_E_A_D___T_H_I_S___<Random>_.txt
- Major Characteristics :
- Offline Encryption
- Target files encrypted starting from offset 0x700
- Encryption targets user created folder in C drive root, My Documents, Desktop, additional partitions, USB Drives
- Generates payment instrucition files in 13 languages including Korean and English
- Changes desktop background(C:\Users\%UserName%\AppData\Local\Temp\tmp<Random>.bmp)
List