Trojan-Ransom.Win32.Scraper encrypts the victims documents and demands a ransom ($300 or greater) to decrypt them. Trojan uses the Tor network to contact its owners something that is apparently becoming a norm for the new generation of ransomware and the proxy server polipo.com is used to send payment details to the C&C server. Trojan is written in assembler, which is unusual for this type of malware. Trojan often lands on users computers via the Andromeda botnet. Trojan encrypts its data section with a 256-bit AES key.”]
Source: https://securelist.com/a-flawed-ransomware-encryptor/69481/