- Distribution Method : Unknown
 
 - MD5 : 905070d52b4f8744f62f3ee5060acec0
 
 - Major Detection Name : Trojan-Ransom.Win32.Xorist.ln (Kaspersky), Ransom:Win32/Sorikrypt.A (Microsoft)
 
 - Encrypted File Pattern : .xdata
 
 - Malicious File Creation Location :
     - C:\Users\%UserName%\AppData\Local\Temp\79jMZcMyoaWHn61.exe
     - C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ÊÀÊ ÐÀÑØÈÔÐÎÂÀÒÜ ÔÀÉËÛ.txt 
 - Payment Instruction File : ÊÀÊ ÐÀÑØÈÔÐÎÂÀÒÜ ÔÀÉËÛ.txt
 
 - Major Characteristics :
     - Offline Encryption
     - Xdata Ransomware imitation
     - The Russian users targeted 
 
					リスト