- Distribution Method : Unknown
- MD5 : 529cc4e6948899c0b4f3026769538bc4
- Major Detection Name : Ransom_WINBAM.A (Trend Micro)
- Encrypted File Pattern : .<5 Digits Random Extension>
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Apps\2.0\<Random>.<Random>\<Random>.<Random>\winb..tion_4494e99f6d26667e_0001.0000_<Random>\WinBamboozle.exe
- Payment Instruction File : _README.txt
- Major Characteristics :
- Offline Encryption
- Use an invalid "DESKTOP-D0GEAVG\batis" Digital Signatures
List