- Distribution Method : Unknown
- MD5 : 7935cc4be643019d4836e09691343b90
- Major Detection Name : a variant of MSIL/Filecoder.GS (ESET), Ransom:Win32/FileCryptor (Microsoft)
- Encrypted File Pattern : .BLOCKED
- Payment Instruction File : CrystalCrypt_Recover_Instructions.png / CrystalCrypt_Recover_Instructions.txt
- Major Characteristics : Changes desktop background (C:\Users\%UserName%\Desktop\CrystalCrypt_Recover_Instructions.png)
List