- Distribution Method : Unknown
- MD5 : 31abeecbd78ae9a517d98d518507928b
- Major Detection Name : Ransom.HiddenTear (Malwarebytes), Ransom_HiddenTearRESTORE.A (Trend Micro)
- Encrypted File Pattern : .r3store
- Payment Instruction File : READ_IT.txt
- Major Characteristics :
- Offline Encryption
- Hidden-Tear Open Source based Ransomware
- Disable Task Manager (Taskmgr.exe / DisableTaskMgr)
List