- Distribution Method : Unknown
- MD5 : a74b250b4028d5397cc09f627bb589ab
- Major Detection Name : Ransom.HiddenTear!g1 (Norton), Ransom_CRYPTEAR.N (Trend Micro)
- Encrypted File Pattern : .explorer
- Payment Instruction File : READ_IT.txt
- Major Characteristics :
- Hidden-Tear Open Source based Ransomware
- Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\wallpaper.bmp)
List