- Distribution Method : Unknown
- MD5 : afd5d656a42a746e95926ef07933f054
- Major Detection Name : Ransomware/Win.Royal.C5246153 (AhnLab V3), Win64/Filecoder.Royal.A trojan (ESET)
- Encrypted File Pattern : .royal
- Message File : README.TXT
- Major Characteristics :
- Offline Encryption
- BlackSuit / Zeon Ransomware series
- Disable system restore (vssadmin.exe delete shadows /all /quiet)
List