According to information from Slow Mist District, a popular enterprise financial software has been attacked by a ransomware virus. The virus will demand a ransom of 0.2 BTC (approximately US$4,100) from the victim. The ransom address is bc1q22xcf2667tjq9ug0fgsmxmfm2kmz32lwtn4m7v. SlowMist MistTrack analyzed the ransom address and found that up to now, two users have paid the ransom of 0.2 BTC and 0.1 BTC, respectively withdrawing from Binance and Gate.io to pay the ransom. After receiving the extortion funds, the hackers began to transfer funds on the same day, of which 0.2 BTC was transferred, and some of the funds were transferred to Binance, the malicious address 3CCV3 and the suspected malicious address 37jAA. As of now, about the remaining 0.2 BTC is still scattered in different addresses, and there is no further transfer. According to intelligence correlation, the malicious address 3CCV3 also received funds from the malicious address bc1qhj of the Glupteba botnet. According to the bitcoinwhoswho report, the malicious address 3CCV3 is the address of a Ponzi scheme named BTC Global, and the suspected malicious address 37jAA is also related to the user being phished related.