- Distribution Method : Mail attachment (.vbs)
- MD5 : 3b5698b90dd761d8a2d085859164a540
- Major Detection Name : Trojan-Ransom.Win32.Locky.zip (Kaspersky), Ransom.Lukitus (Norton)
- Encrypted File Pattern : <Random>-<Random>-<Random>-<Random>-<Random>.ykcol
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Temp\PsArSUVWXNj.exe
- Payment Instruction File : ykcol.htm / ykcol-<Random>.htm
- Major Characteristics :
- Offline Encryption
- Jaff Ransomware series
- Changes desktop background (C:\Users\%UserName%\Desktop\ykcol.bmp)
List