- Distribution Method : Unknown
- MD5 : b4db30a8307ad69f7615b7fb7ae29822
- Major Detection Name : a variant of Win32/Filecoder.Crypt888.B (ESET), Ransom.Crypt888 (Malwarebytes)
- Encrypted File Pattern : Lock.<Original Filename>.<Original Extension>
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Temp\8x8x8
- Major Characteristics :
- Offline Encryption
- Crypt888 / Encephalitis / GrodexCrypt / MicroCop Ransomware series
- AutoIt scripts based Ransomware
- Developed by a Korean
- Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\wl.jpg)
List