- Distribution Method : Unknown
- MD5 : 1ec5bc061e462476ee8fa9b25284f063
- Major Detection Name : Ransom.CryptoHasYou (Malwarebytes), Ransom_FAKEGLOBE.F117DS (Trend Micro)
- Encrypted File Pattern : <Random Filename>.FIXI
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\csrss.exe
- Payment Instruction File : HOW TO DECRYPT FILES.TXT
- Major Characteristics :
- Offline Encryption
- Delphi-based Ransomware
List