- Distribution Method : Unknown
 
 - MD5 : 2ec5c776051a435ad2fd2cc5aa21d730
 
 - Major Detection Name : Ransom.HiddenTear (Malwarebytes), Ransom:Win32/HiddenTear.gen (Microsoft)
 
 - Encrypted File Pattern : .RASTAKHIZ
 
 - Malicious File Creation Location :
 - C:\rastakhiz
 - C:\rastakhiz\rastakh1z.exe
 - C:\Users\%UserName%\AppData\Local\RASTAKHIZ_Decrypt0r
 - C:\Users\%UserName%\AppData\Roaming\DoNotDelete.RASTAKHIZ
 - C:\Users\%UserName%\Desktop\Rastakhiz Decrypt0r.exe
 - D:\Sr.rastakhiz 
 - Payment Instruction File : #R3@D_M3#.txt
 
 - Major Characteristics :
 - Offline Encryption
 - Hidden-Tear Open Source based Ransomware 
 
					List