- Distribution Method : Unknown
- MD5 : 34636ac34d6ed369974d45e68d9902ea
- Major Detection Name : Trojan.Ransom.DMALocker (ALYac), Ransom:Win32/DMALocker.B (Microsoft)
- Encrypted File Pattern : No Change
- Malicious File Creation Location :
- C:\ProgramData\cryptinfo.txt
- C:\ProgramData\date_1.txt
- C:\ProgramData\decrypting.txt
- C:\ProgramData\start.txt
- C:\ProgramData\svchosd.exe
- Payment Instruction File : cryptinfo.txt
- Major Characteristics :
- Offline Encryption
- Add !Encrypt!## signature to the encrypted file
List