- Distribution Method : Unknown
- MD5 : e28fac9e5887044dbde5ee365946f796
- Major Detection Name : Trojan-Ransom.Win32.Spora.fcr (Kaspersky), Trojan.Win32.S.RansomAES.131584 (ViRobot)
- Encrypted File Pattern : .RansomAES
- Payment Instruction File : READ ME.txt
- Major Characteristics :
- Offline Encryption
- Developed by a Korean
- Disable system restore (vssadmin.exe delete shadows /all /quiet)
List