- Distribution Method : Unknown
 
 - MD5 : 60ce57a7112dc9c5f1967b3115df9332
 
 - Major Detection Name : Trojan.Encoder.26898 (Dr.Web), a variant of MSIL/Kryptik.PFR (ESET)
 
 - Encrypted File Pattern : .locked
 
 - Malicious File Creation Location :
 - C:\Users\%UserName%\SystemKey.txt
 - C:\Users\%UserName%\table.exe
 - C:\Users\%UserName%\winsys.txt
 - C:\Users\%UserName%\winsys2.txt
 - C:\Users\%UserName%\winsys3.txt 
 - Payment Instruction File : ODSZYFRFUJ_PLIKI_TERAZ.txt
 
 - Major Characteristics :
 - Offline Encryption
 - Hidden-Tear open source based ransomware
 - The Polish users targeted
 - Disable and Blocks Task Manager (DisableTaskmgr) 
 
					List