- Distribution Method : Unknown
- MD5 : 4f81bb03fd467d6e406dd22b84e7c095
- Major Detection Name : Trojan/Win32.Ransom.C2165435 (AhnLab V3), Ransom:Win32/HiddenTear.gen (Microsoft)
- Encrypted File Pattern : .allcry
- Malicious File Creation Location :
- C:\allcry.exe
- C:\Windows\System32\winsrv.exe
- Payment Instruction File : readme.txt
- Major Characteristics : The English, Chinese and Korean users targeted
List