PrincessLocker Ransomware (.<4~6 Digits Random Extension> / =_THIS_TO_FIX_<Encryption Extension>.html)
2018. 03. 08. 5,386
Distribution Method : Unknown MD5 : 93cb0053e883fb262f9f795f327152f8 Major Detection Name : Trojan.Ransom.Princess (ALYac) Encrypted File Pattern : .<4~6 Digits Random Extension> Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Temp\<Random>.exe Payment Instruction File : =_THIS_TO_FIX_<Encryption Extension>.html / =_THIS_TO_FIX_<Encryption Extension>.txt / =_THIS_TO_FIX_<Encryption Extension>.url Major Characteristics : - Offline Encryption - Changes desktop background (C:\Users\%UserName%\Pictures\img.png) - Payment support in 12 languages including English and Korean
List