- Distribution Method : Unknown
- MD5 : 9a7c0adedc4c68760e49274700218507
- Major Detection Name : Ransom:Win64/Gunra.A (Microsoft), Ransom.Win64.GUNRA.THEOFBE (Trend Micro)
- Encrypted File Pattern : .ENCRT
- Message File : R3ADM3.txt
- Major Characteristics :
- Offline Encryption
- Conti Ransomware series
- Disable system restore(C:\Windows\System32\wbem\WMIC.exe shadowcopy where "ID='{GUID}'" delete)
List