525, Gangnam-daero, Seocho-gu, Seoul, Republic of Korea l Tel :822-3448-0880 l Fax : 822-3448-0804 l Email : jsshim@truecut.co.kr
Copyright (C) 2015 TrueCut Security, Inc. All Right Reserved.
Title | Today's ransomware - odin | ||||
---|---|---|---|---|---|
Name | Operator | Date | 2016-09-27 | View | 1045 |
File | Today ransomware_20160927.pdf | ||||
It is a windows script file and call a rundll32 process. So, it seem to be a Locky subspecies. However, extension of files were changed to "odin" not "zepto". C & C server IP is in Russia. It was blocked by TrojanCut. |