- Distribution Method : Unknown
- MD5 : f9c660b5fd3a0f1327e33cc9ad5d6aa1
- Major Detection Name : Ransom:Win32/Genasom (Microsoft), Ransom.TeslaCrypt (Norton)
- Encrypted File Pattern : <Random Filename>.RSA2048
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\trust.exe
- C:\Users\%UserName%\Read Me Please.hta
- Payment Instruction File : Read Me Please.hta
- Major Characteristics : Offline Encryption
List