- Distribution Method : Remote access through Remote Desktop Protocol(RDP) or Terminal Services
- MD5 : c560e5896e8f91a8eccba440874f7d8e
- Major Detection Name : W32/Phobos.E!tr.ransom (Fortinet), Ransom.Makop (Malwarebytes)
- Encrypted File Pattern : .[<Random>].[hopeandhonest@smime.ninja].makop
- Malicious File Creation Location : C:\Users\%UserName%\Desktop\readme-warning.txt
- Payment Instruction File : readme-warning.txt
- Major Characteristics :
- Offline Encryption
- Block processes execution (agntsrvc.exe, encsvc.exe, mysqld.exe, outlook.exe, steam.exe, xfssvccon.exe etc.)
- Disable system restore (vssadmin delete shadows /all /quiet, wbadmin delete catalog -quiet, wmic shadowcopy delete)
List