- Distribution Method : Unknown
- MD5 : a186f6b7ec6d3b6a31b7158082b9a0fa
- Major Detection Name : TR/Encoder.wolua (Avira), W32/Bule.A!tr.ransom (Fortinet)
- Encrypted File Pattern : .blue
- Payment Instruction File : restore_file.txt
- Major Characteristics :
- Offline Encryption
- Disable system restore (wmic SHADOWCOPY DELETE)
List