Bird_banner_small4
Trojan.MSIL.FinalLock.A
TSL ID TSL20170418-02
Severity Moderate
Description

Trojan.MSIL.FinalLock.A is a ransomware Trojan that targets the Windows platform. This malware identifies itself to a remote server to receive encryption key. The malware encrypts files on the infected machine and demands a payment in the form of Bitcoins digital currency to get the files decrypted.

Affected Products
  • Microsoft Windows All Versions
File Hashes
MD5:
  • 72899CA14975AD7B90F051660B410673
SHA1:
  • F8D2B00879AA446DDC4AACA1C7A43AAC498F7996
Identifiers
Sophos
  • MAL/FINALLOCK-A
TrendMicro
ALYac
  • TROJAN.RANSOM.GX40LOCKER
AVG
  • ATROS5.AHPY
BitDefender
  • GENERIC.RANSOM.CLOUDSWORD.A9C8E1F7
Bkav
  • W32.CLODE07.TROJAN.A215
ESET
  • MSIL/FILECODER.FR
Fortinet
  • MSIL/TROJANDROPPER.AH!TR
Ikarus
  • TROJAN-PWS.SUSPECTCRC
Jiangmin
  • TROJAN/GENERIC.KQXZ
Tencent
  • WIN32.TROJAN.GENERIC.AGLD
VBA32
  • TROJAN.MSIL.GEN.13
Yandex
  • TROJAN.FILECODER!TH7ZYB7LLPY
References https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Mal~FinalLock-A/detailed-analysis.aspx
http://www.virusradar.com/en/MSIL_Filecoder.FR/description
Related Threats