- Distribution Method : Unknown
- MD5 : 74483659212cab1803639c0054841b78
- Major Detection Name : Ransom.CryptoWire (Malwarebytes), Ransom_CRYPTOWIRE.F117CU (Trend Micro)
- Encrypted File Pattern : <Original Filename>.encrypted.<Original Extension>
- Malicious File Creation Location :
- C:\Program Files (x86)\Common Files\<Random>.exe
- C:\Program Files (x86)\Common Files\log.txt
- Major Characteristics :
- Offline Encryption
- Owl / UltraLocker Ransomware series
- AutoIt-based Ransomware
- The Portuguese users targeted
List