Major Detection Name :Ransom.Oxar (Malwarebytes), Ransom_HiddenTearOxar.F117H8 (Trend Micro)
Encrypted File Pattern : .PEDO
Payment Instruction File : 1 What happens with my files.txt / instructions.txt
Major Characteristics :
- Offline Encryption - Transmit system information to specific FTP server - Encryption guide using Text-to-Speech (TTS) function - Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\wallpaper.bmp)