- Distribution Method : Unknown
- MD5 : 84a77244add79137d35b757f1e71bd72
- Encrypted File Pattern : .DECRYPT_NOW!
- Malicious File Creation Location :
 - C:\Users\%UserName%\AppData\Local\Drpbx
 - C:\Users\%UserName%\AppData\Local\Drpbx\PDF.exe
 - C:\Users\%UserName%\AppData\Roaming\Frfx
 - C:\Users\%UserName%\AppData\Roaming\Frfx\PDF2.exe
 - C:\Users\%UserName%\AppData\Roaming\System32Work
 - C:\Users\%UserName%\AppData\Roaming\System32Work\Address.txt
 - C:\Users\%UserName%\AppData\Roaming\System32Work\dr
 - C:\Users\%UserName%\AppData\Roaming\System32Work\EncryptedFileList.txt
- Major Characteristics :
 - Offline Encryption
 - Ramsey Ransomware series
 - Create a fake ".NET Framework Initialization Error" message.
 - Automatically delete encrypted files every hour.
List