- Distribution Method : Unknown
- MD5 : 06518590d25945c439c56c99d486bc2c
- Major Detection Name : Trojan.Ransom.BUS (BitDefender), Trojan-Ransom.Win32.Purgen.rd (Kaspersky)
- Encrypted File Pattern : .restorefile@india.com
- Payment Instruction File : how_to_decrypt_files.html
- Major Characteristics :
- Offline Encryption
- Fake Globe / PSCrypt Ransomware series
- Disable system restore (vssadmin.exe Delete Shadows /All /Quiet)
List