- Distribution Method : Unknown
- MD5 : 54b5234ec4b3682648cf528039bec59f
- Major Detection Name : Ransom/W32.Desu.260608 (TACHYON), Ransom_ANIMUS.THGBCAH (Trend Micro)
- Encrypted File Pattern : .desu
- Payment Instruction File : @_DECRYPT_@.txt / @_DECRYPT2_@.txt / @_DECRYPT3_@.txt
- Major Characteristics :
- Offline Encryption
- AnimusLocker Ransomware series
- Modifying the Master Boot Record (MBR) + File encryption
- After completion of encryption, windows reboots automatically (C:\Windows\System32\shutdown.exe /r /t 00)
List