- Distribution Method : Unknown
 
 - MD5 : e9454a2ff16897e177d8a11083850ec7
 
 - Major Detection Name : Ransom.Mespinoza (Malwarebytes), Ransom:Win32/Filecoder.PD!MTB (Microsoft)
 
 - Encrypted File Pattern : .pysa
 
 - Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Temp\update.bat
 
 - Payment Instruction File : Readme.README
 
 - Major Characteristics :
 - Offline Encryption
 - Display a ransomware message on the Windows logon screen 
 
					List