- Distribution Method : Unknown
 
 - MD5 : 156f5fe50359df649c91773300dfe9b7
 
 - Major Detection Name : Trojan/Win32.Matrix.C2428826 (AhnLab V3), W32/Matrix.2FFD!tr.ransom (Fortinet)
 
 - Encrypted File Pattern : <Original Filename>.<Original Extension> → <Random>-<Random>.[RestoreFile@qq.com]
 
 - Malicious File Creation Location :
 - C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\<Random>.lnk
 - C:\Users\%UserName%\AppData\Roaming\#What_Wrong_With_Files#.rtf
 - C:\Users\%UserName%\AppData\Roaming\<Random>.cmd 
 - Payment Instruction File : #What_Wrong_With_Files#.rtf / <2-Digit Random>#What_Wrong_With_Files#.rtf
 
 - Major Characteristics :
 - Offline Encryption
 - Interrupt file recovery using cipher.exe /w:<Drive Letter>:
 - Changes desktop background (C:\Users\%UserName%\AppData\Roaming\<Random>.jpg) 
 
					リスト