- Distribution Method : Mail attachment (.js)
 
 - MD5 : bc2c23ba44364ba04736b19a4482c8c7
 
 - Major Detection Name : Ransom/W32.GlobeImposter.263248 (nProtect), Ransom.GlobeImposter (Norton)
 
 - Encrypted File Pattern : .ocean
 
 - Malicious File Creation Location : C:\Users\Public\<Random>.exe
 
 - Payment Instruction File : !back_files!.html
 
 - Major Characteristics :
     - Offline Encryption
     - Fake Globe / PSCrypt Ransomware series
     - Use a valid "Media Lid" Digital Signatures
     - Disable system restore (vssadmin.exe Delete Shadows /All /Quiet) 
 
					List