- Distribution Method : Unknown
- MD5 : a292fee8d8db83711e72c06d6f82562d
- Major Detection Name : Ransom:Win32/Basta.PE!MTB (Microsoft), Ransom.Win32.BLACKBASTA.THBBHBC (Trend Micro)
- Encrypted File Pattern : .vokou2s5g
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Local\Temp\fkdjsadasd.ico
- C:\instructions_read_me.txt
- Message File : instructions_read_me.txt
- Major Characteristics :
- Offline Encryption
- Disable system restore (vssadmin.exe delete shadows /all /quiet)
- Change encrypted file (.vokou2s5g) icon. (HKEY_CLASSES_ROOT\.vokou2s5g)
List