- Distribution Method : Unknown
- MD5 : 493edc98d300ffbfe3fb8d87e970f84f
- Major Detection Name : Ransom.RobinHood (Malwarebytes), Ransom.HiddenTear!g1 (Norton)
- Encrypted File Pattern : .Robinhood
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\Temp\luncher.exe
- C:\Users\%UserName%\AppData\Local\Temp\Microsoft.Win32.TaskScheduler.dll
- C:\Users\%UserName%\AppData\Local\Temp\updater.exe
- C:\Users\%UserName%\Desktop\ROBINHOOD-TIMER.exe
- C:\Windows\System32\Tasks\MicrosoftServices
- Payment Instruction File : READ_IT.txt
- Major Characteristics :
- Deletes encrypted files after 72 hours expires
- Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\wallpaper1.bmp)
List