The TorrentLocker (Crypt0L0cker) appeared on the ransomware stage in August 2014 but it reached its peak in distribution in early to middle 2015. It had some major spreading campaigns mostly targeting the Netherlands, Italy and Australia. However, it didn’t take much time before other pieces of ransomware like TeslaCrypt and CryptoWall to overtop and replace it.
This TorrentLocker version displays a ransom note in Italian with detailed instructions on how the victims should complete the payment.
As it looks like, this particular sample in oriented in infecting Italian users but there is a high chance that other campaigns are targeting other countries as well.