- Distribution Method : Unknown
- MD5 : 4482844622c6cc5027927a856e8bad57
- Major Detection Name : Generic.Ransom.LockCrypt.3.E46B7FBD (BitDefender), Ransom:Win32/Velar.PA!MTB (Microsoft)
- Encrypted File Pattern : .Velar
- Payment Instruction File : readme.txt
- Major Characteristics :
- Offline Encryption
- Embrace / Evil Locker / PainLocker / Upper Ransomware series
- Block processes execution (fdlauncher.exe, firefoxconfig.exe, MsDtsSrvr.exe, mysqld-nt.exe, ocssd.exe, sqlwriter.exe etc.)
- Stop multi services (MSSQL, MSSQLFDLauncher, MSSQLSERVER, SQLSERVERAGENT, SQLWriter, vmms etc.)
- Disable system restore (vssadmin delete shadows /all /quiet)
List