- Distribution Method : Unknown
- MD5 : 15b48703d6ad8a520dc1abbface419f5
- Major Detection Name : a variant of Win32/Filecoder.NMO (ESET), Ransom_KCAUF.A (Trend Micro)
- Encrypted File Pattern : <Number>.<Original Filename>.<Original Extension>
- Major Characteristics :
- Offline Encryption
- Modifying the MBR + File encryption
- Target document content is overwritten to "WAHHH!!!! YOU HAVE BEEN FUACKED!!"
- Target picture files changed to disgusting picture
List