- Distribution Method : Unknown
- MD5 : e18690ec72ee623d30beed4700cd8359
- Major Detection Name : Troj/HTRansom-B (Sophos), Ransom_CRYPTEAR.SM (Trend Micro)
- Encrypted File Pattern : .locked
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\Temp\GRUXER.EXE
- C:\Users\%UserName%\AppData\Local\Temp\HIDDEN-TEAR - COPY (2).EXE
- C:\Users\%UserName%\AppData\Local\Temp\HIDDEN-TEAR - COPY (3).EXE
- C:\Users\%UserName%\AppData\Local\Temp\HIDDEN-TEAR - COPY (4).EXE
- C:\Users\%UserName%\AppData\Local\Temp\HIDDEN-TEAR - COPY (5).EXE
- C:\Users\%UserName%\AppData\Local\Temp\HIDDEN-TEAR - COPY.EXE
- C:\Users\%UserName%\AppData\Local\Temp\HIDDEN-TEAR.EXE
- Major Characteristics : Hidden-Tear Open Source based Ransomware
List