- Distribution Method : Unknown
- MD5 : a034f79273e3f61d34eeadf38f12dee2
- Major Detection Name : Trojan.HelloXD.A (BitDefender), Win64.Trojan-Ransom.HelloXD.A (GData)
- Encrypted File Pattern : .hello
- Payment Instruction File : Hello.txt
- Major Characteristics :
- Offline Encryption
- Disable and Blocks Task Manager (TaskMgr.exe)
- Block processes execution (dbsnmp.exe, isqlplussvc.exe, oracle.exe, ProcessHacker.exe, procexp64.exe, Wireshark.exe etc.)
- Stop multi services (AcrSch2Svc, BackupExecJobEngine, ccSetMgr, DefWatch, RTVscan, VeeamDeploymentService etc.)
- Disable system restore (vssadmin.exe delete shadows /all /quiet)
List