- Distribution Method : Unknown
- MD5 : 3971ee59070489c06711996811282461
- Major Detection Name : Generic.Ransom.BTCWare.F11B680C (BitDefender), Ransom:Win32/Higuniel.A (Microsoft)
- Encrypted File Pattern : .[dongeswas@tutanota.com].Tornado
- Payment Instruction File : key.txt
- Major Characteristics :
- Offline Encryption
- desuCrypt Open Source based Ransomware
- Disable system restore (vssadmin.exe Delete Shadows /All /Quiet)
List