- Distribution Method : Unknown
- MD5 : 6cb4e946c2271d28a4dee167f274bb80
- Major Detection Name : Ransom:MSIL/DnWipe.A (Microsoft), Ransom.MSIL.RUCRYPT.YXCCD (Trend Micro)
- Encrypted File Pattern : <Original Filename>.<Original Extension>
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Полномасштабное_кибервторжение.txt
- Payment Instruction File : Полномасштабное_кибервторжение.txt
- Major Characteristics :
- Offline Encryption
- Data corruption method
- The Russian language users are targeted.
- There is a propagation feature that creates a Россия-Украина_Война-Обновление.doc.exe file on a USB/network drive.
List