- Distribution Method : Unknown
- MD5 : 4c3d2b354dc34073370424c7a34306bf
- Major Detection Name : Dropped:Generic.Ransom.Purge.25286C2F (BitDefender), Ransom:Win32/Pulobe (Microsoft)
- Encrypted File Pattern : <Random Filename>.1
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\tvindt.exe
- C:\Users\%UserName%\How To Recover Encrypted Files.hta
- Payment Instruction File : How To Recover Encrypted Files.hta
- Major Characteristics :
- Offline Encryption
- Hidden-Tear Ransomware based Open Source
List