- Distribution Method : Unknown
 
 - MD5 : e9db7fe38dfea5668c74d6f192ae847b
 
 - Major Detection Name : Trojan.Ransom.Xorist (ALYac), Gen:Variant.Ransom.Xorist.82 (BitDefender)
 
 - Encrypted File Pattern : .Mcafee
 
 - Malicious File Creation Location :
 - C:\Users\%UserName%\AppData\Local\Temp\6q8C4uwvw4oY157.exe
 - C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HOW TO DECRYPT FILES.txt 
 - Payment Instruction File : HOW TO DECRYPT FILES.txt
 
 - Major Characteristics :
 - Offline Encryption
 - Boom / Xorist-Frozen Ransomware series
 - The Spanish users are targeted.
 - File encryption using "C:\WINDOWS\SysWOW64\WerFault.exe"
 - Change the encrypted file (.Mcafee) icon (HKEY_CLASSES_ROOT\OPIGMTRBNPCVPFS) 
 
					List