- Distribution Method : Unknown
- MD5 : 975e9aeef03f48d0439dc059e5184854
- Encrypted File Pattern : .WFA_RANSOM
- Malicious File Creation Location :
- C:\Temp\Payload
- C:\Temp\Payload\Alert_Note
- C:\Temp\Payload\Launcher_Code
- C:\Temp\Payload\Wallpaper
- Major Characteristics : Changes desktop background (C:\Temp\Payload\Wallpaper\wallpaper.jpg)
List