- Distribution Method : Unknown
- MD5 : 8aa00ee509a649619794fc1390319293
- Major Detection Name : Generic.Ransom.Paradise.B17967CF (BitDefender), a variant of MSIL/Filecoder.Paradise.B (ESET)
- Encrypted File Pattern : .<Original Extension>[id-<Random>].[paradise@all-ransomware.info].paradise
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\DP
- C:\Users\%UserName%\AppData\Roaming\DP\DP_Main.exe
- C:\Users\%UserName%\Desktop\DecryptionInfo.auth
- C:\Users\%UserName%\Documents\DecryptionInfo.auth
- Payment Instruction File : #DECRYPT MY FILES#.html
- Major Characteristics :
- Offline Encryption
- Delete system services (sc delete VSS)
List