- Distribution Method : Automatic infection using exploit by visiting website
- MD5 : 18e38663bc8ef270c0eeddae91eb1bb8
- Major Detection Name : Ransomware-GEO!18E38663BC8E (McAfee), Ransom_CERBER.SMALY0 (Trend Micro)
- Encrypted File Pattern : <Random>-<Random>-<Random>-<Random>-<Random>.asasin
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\<Random>\index[<Number>].htm
- Payment Instruction File : asasin.htm / asasin-<Random>.htm
- Major Characteristics :
- Offline Encryption
- Jaff Ransomware series
- Changes desktop background (C:\Users\%UserName%\Desktop\asasin.bmp)
List