- Distribution Method : Unknown
- MD5 : 310342183f3632361ced85fdf54b6370
- Major Detection Name : Generic.Ransom.MMM.BF38A96C (BitDefender), Ransom.TripleM (Malwarebytes)
- Encrypted File Pattern : .triple_m
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\bcedit.bat
- C:\Users\%UserName%\AppData\Roaming\reco.bat
- C:\Users\%UserName%\AppData\Roaming\temp_1.bat
- Payment Instruction File : RESTORE_triple_m__FILES.html
- Major Characteristics :
- Offline Encryption
- MMM Ransomware series
- Disable system restore (vssadmin delete shadows /all /quiet, bcedit.exe /set {default} recovery enabled no, bcedit.exe /set {default} bootstatuspolicy ignoreallfailures)
List