- Distribution Method : Unknown
- MD5 : 011f60dd481f03c21a429f0ef91d4cef
- Major Detection Name : Ransom:Win64/IndustrialSpy.A (Microsoft), Ransom.Win64.INDUSTRIALSPY.THFOHBB (Trend Micro)
- Encrypted File Pattern : <Original Filename>.<Original Extension>
- Payment Instruction File : readme.htm
- Major Characteristics :
- Offline Encryption
- Disable system restore (vssadmin.exe delete shadows /all /quiet)
List