- Distribution Method : Unknown
- MD5 : 8bcc88145d53266597d53bce983666c8
- Major Detection Name : a variant of MSIL/Filecoder.Jigsaw.C (ESET), Ransom:MSIL/JigsawLocker.B (Microsoft)
- Encrypted File Pattern : .lost
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\Flash\AdobeFlash32.exe
- C:\Users\%UserName%\AppData\Roaming\Adb\AdobeFlash.exe
- Major Characteristics :
- Offline Encryption
- Automatically delete encrypted files every hour
List