- Distribution Method : Unknown
- MD5 : f7d5730417f81d7ce6f8b231dbd333e4
- Major Detection Name : Ransom.Winlock (Malwarebytes), Ransom.MSIL.COBRALOCKER.B (Trend Micro)
- Encrypted File Pattern : <Original Filename>.<Original Extension>
- Major Characteristics :
- Offline Encryption
- DaVinci Ransomware series
- The Russian users are targeted.
- Disable and Blocks Registry Editor (DisableRegistryTools) and Task Manager (DisableTaskMgr)
List