- Distribution Method : Unknown
- MD5 : 4ba2e1d4cf7a86753f9f8174b3bc74c8
- Major Detection Name : Trojan.Ransom.DEATHRansom (ALYac), Ransom.Win32.DEATHRANSOM.C (Trend Micro)
- Encrypted File Pattern : <Original Filename>.<Original Extension>
- Malicious File Creation Location :
- C:\ProgramData\99MH9CJ494.exe
- C:\ntos.database
- Payment Instruction File : read_me.txt
- Major Characteristics : Offline Encryption
List