- Distribution Method : Unknown
- MD5 : 80317e3194d8f7fd495b0bf06cae2295
- Major Detection Name : Python/Filecoder.AH (ESET), Ransom_STRIKED.A (Trend Micro)
- Encrypted File Pattern : <Original Filename>.<Original Extension>#rap@mortalkombat.top#id#<Number>
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\README_DECRYPT.html
- Payment Instruction File : README_DECRYPT.html
- Major Characteristics :
- Offline Encryption
- Python-based Ransomware
- Disable Task Manager (Taskmgr.exe)
List