- Distribution Method : Unknown
- MD5 : e9357fd55e0bf9400bda2d8dad5be370
- Major Detection Name : a variant of Win32/Filecoder.Philadelphia.G (ESET), Ransom:Win32/Stampado.A (Microsoft)
- Encrypted File Pattern : <Random Filename>.locked
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\scvhost.exe
- C:\Users\%UserName%\Desktop\Recover my files.exe
- Payment Instruction File : How to recover my files.txt
- Major Characteristics :
- Offline Encryption
- Philadelphia / Stampado Ransomware series
- AutoIt-based Ransomware
List