- Distribution Method : Unknown
- MD5 : 9c5f5cd0cee2065605e0d114555086e3
- Major Detection Name : Trojan/Win32.Globeimposter.R204657 (AhnLab V3), Ransom_FAKEGLOBE.T (Trend Micro)
- Encrypted File Pattern : .oni
- Payment Instruction File : !!!README!!!.html
- Major Characteristics :
- Offline Encryption
- Fake Globe / PSCrypt Ransomware series
- The Japanese users targeted
- Disable system restore (vssadmin.exe Delete Shadows /All /Quiet)
List