- Distribution Method : Unknown
- MD5 : 15b1147bcc846fe5dd750a3b02b8e552
- Major Detection Name : Ransomware/Win.RA.C5428176 (AhnLab V3), Ransom:Win32/Filecoder.SWA!MTB (Microsoft)
- Encrypted File Pattern : .GAGUP
- Message File : How To Restore Your Files.txt
- Major Characteristics :
- Offline Encryption
- Abyss Locker / AstraLocker / Babuk Locker / ChiChi Locker / Dark Angels Team / DARKY LOCK / Delta Plus / Pandora / RA World / Rook Ransomware series.
- Recovery Partition (M:\) + EFI System Partition (N:\) drives are activate.
- Disable system restore. (vssadmin.exe delete shadows /all /quiet)
List