- Distribution Method : Unknown
- MD5 : f4e56e1c32dfa723bcc87f5da12599cb
- Major Detection Name : TR/LockScreen.vtoxz (Avira), Ransom_SHINIGAMI.A (Trend Micro)
- Encrypted File Pattern : <Random Filename>.shinigami
- Major Characteristics :
- Offline Encryption
- Use the DES encryption algorithm
- Change the default values of the registry entry "HKEY_CLASSES_ROOT\mscfile\shell\open\command" and a ransomware execution using Event Viewer (eventvwr.exe)
- Disable Task Manager (Taskmgr.exe)
List