- Distribution Method : Unknown
- MD5 : c35506bd3fedad57e7f1ea975ebcaec5
- Major Detection Name : Trojan.Ransom.CryptConsole (ALYac), Ransom_SEQUR.THDBGAH (Trend Micro)
- Encrypted File Pattern : sequre@tuta.io_<Random>
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HOW DECRIPT FILES.hta
- Payment Instruction File : HOW DECRIPT FILES.hta
- Major Characteristics : Offline Encryption
List