- Distribution Method : Unknown
 
 - MD5 : 0b6a218c200892275bee061f24a3f9fb
 
 - Major Detection Name : Trojan.Ransom.Maoloa.A (BitDefender), Ransom.GlobeImposter (Malwarebytes)
 
 - Encrypted File Pattern : .systems32x
 
 - Payment Instruction File : HOW TO BACK YOUR FILES.TXT
 
 - Major Characteristics :
 - Offline Encryption
 - Fake Globe / PSCrypt Ransomware series
 - Disable system restore (vssadmin.exe Delete Shadows / All / Quiet)
 - Initializing the Terminal Server Client Registry (reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f, reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f, reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers") 
 
					List