- Distribution Method : Unknown
- MD5 : f48a1057059028a65f2ec37e90d4deec
- Major Detection Name : Ransom:Win32/FileCrypt!mclg (Microsoft), Ransom.Win32.PAYTODECRYPT.THFOFBB (Trend Micro)
- Encrypted File Pattern : .PAY2DECRYPTRLD<Random>
- Payment Instruction File : Pay2Decrypt<1~100>.txt
- Major Characteristics :
- Offline Encryption
- Disable and Blocks Registry Editor (DisableRegistryTools), Command Prompt (DisableCMD), Windows Run Command in Start menu (NoRun) and Task Manager (DisableTaskmgr)
List