The worm stores all its files inside a directory named RECYCLER.BIN, and it drops a desktop.ini file that makes Windows treat this folder as an actual Recycle Bin. This means deleted files from the user’s real hard drive appear there, further masking the worm’s presence. Inside RECYCLER.BIN, the malware targets documents including .doc, .docx, .xls, .xlsx, .ppt, .pptx, and .pdf files, encrypts them, and saves them with base64-encoded file names for exfiltration.
no records found