- Distribution Method : Unknown
- MD5 : c6bc3babce34728d6b99f0296eb231fc
- Major Detection Name : Trojan.Ransom.Naampa (ALYac), Ransom:Win32/Genasom (Microsoft)
- Encrypted File Pattern : .crptd
- Payment Instruction File : !----README----!.jpg
- Major Characteristics :
- Offline Encryption
- Kozy.Jozy / Unlckr / Unlock92 Ransomware series
- The Russian users targeted
- Disable system restore (vssadmin.exe Delete Shadows /All /Quiet)
List