- Distribution Method : Unknown
- MD5 : 32b3fc07b9ced39b8767335dcd06dc9a
- Encrypted File Pattern : .<Original Extension>[infected_7x@proton.me].Cry
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Local\Temp\RarSFX0\pass.exe
- Message File : <Original Filename>.<Original Extension>.txt / Decryption_Log.txt / Read_Me.txt / إقرأني.txt
- Major Characteristics : Offline Encryption
List