- Distribution Method : Unknown
- MD5 : 401c7defd9815701931765c4e8b8d8f9
- Major Detection Name : Ransom-Paradise!401C7DEFD981 (McAfee), Ransom_PARADISE.A (Trend Micro)
- Encrypted File Pattern : <Original Filename>.<Original Extension>id-<Random>.[info@decrypt.ws].paradise
- Malicious File Creation Location : C:\Users\%UserName%\Desktop\DecriptionInfo.auth
- Payment Instruction File : #DECRYPT MY FILES#.txt
- Major Characteristics :
- Offline Encryption
- Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\desk.bmp)
List