Avast FileRepMetagen [Malware] AVG FileRepMetagen [Malware] Avira (no cloud) Malwarebytes Ransom.Jigsaw McAfee-GW-Edition BehavesLike.Win32.Ransomware.dc Microsoft Trojan:Win32/Occamy.C When executed this ransomware has NO C2 it uses an e-mail address with directions as pictured below: 2020-05-01 16:19:09.841147 IP 192.168.86.1.53 > 192.168.86.25.59527: 12228 1/0/0 A 41.97.11.131 (59)E..W..@.@.if..V…V..5…C.p/…………service-updater.hopto.org…………..;..)a..2020-05-01 16:19:09.841596 IP 192.168.86.25.50977 > 41.97.11.131.80: Flags [S], seq 1891890631, win 8192, options [mss 1460,nop,wscale 2,nop,nop,sackOK], length 0E..4f^@…H…V.)a…!.Pp……… ..s…………..2020-05-01 16:19:10.021362 IP 41.97.11.131.80 > 192.168.86.25.50977: Flags [S.], seq 2051894246, ack 1891890632, win 8192, options [mss 1340,nop,wscale 8,nop,nop,sackOK], length 0E..4Q.@.*..p)a….V..P.!zMk.p….. ……..<…….. 2020-05-01 16:19:10.021569 IP 192.168.86.25.50977 > 41.97.11.131.80: Flags [.], ack 1, win 16415, length 0E..(f_@…H…V.)a…!.Pp…zMk.P.@………..2020-05-01 16:19:10.022040 IP 192.168.86.25.50977 > 41.97.11.131.80: […]