- Distribution Method : Automatic infection using exploit by visiting website
- MD5 : e7412ad8301456f3f4e32ab2d2c6f3f7
- Major Detection Name : Trojan.Ransom.Princess (ALYac), Ransom.Spora (Norton)
- Encrypted File Pattern : .<4~6 Digits Random Extension>
- Payment Instruction File : __USE_TO_REPAIR_<Encryption Extension>.html / __USE_TO_REPAIR_<Encryption Extension>.txt / __USE_TO_REPAIR_<Encryption Extension>.url
- Major Characteristics : Payment support in 12 languages including Korean and English
List