- Distribution Method : Unknown
 
 - MD5 : 1f667218368fe8caadc8d1c469f73233
 
 - Major Detection Name : TR/Ransom.nhcet (Avira), MSIL.Trojan-Ransom.Dishwasher.A (GData)
 
 - Encrypted File Pattern : .clean
 
 - Malicious File Creation Location :
 - C:\Users\%UserName%\AppData\Local\Temp\<Random>.exe
 - C:\Users\%UserName%\AppData\Local\Temp\dump.keys 
 - Major Characteristics :
 - Offline Encryption
 - Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\bg.jpg) 
 
					List