Check out our video library AppCheck defending against newest ransomware, automatic recovery and real-time backup.
Distribution Method : Unknown
MD5 : d243d5a1f24de0b823d3ba72f26e008b
Major Detection Name :Ransom.Oxar (Malwarebytes), Ransom_HiddenTearOxar.F117H8 (Trend Micro)
Encrypted File Pattern : .PEDO
Payment Instruction File : 1 What happens with my files.txt / instructions.txt
Major Characteristics :
- Offline Encryption - Transmit system information to specific FTP server - Encryption guide using Text-to-Speech (TTS) function - Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\wallpaper.bmp)