- Distribution Method : Remote access through Remote Desktop Protocol(RDP) or Terminal Services
- MD5 : 27d857e12b9be5d43f935b8cc86eaabf
- Major Detection Name : Linux/Erebus.487166 (AhnLab V3), Ransom:Linux/Erebus.A (Microsoft)
- Encrypted File Pattern : <Random Filename>.ecrypt
- Payment Instruction File : _DECRYPT_FILE.html / _DECRYPT_FILE.txt / index.html
- Major Characteristics : Offline Encryption
List