AvosLocker
ID: a9b99ffd-59e0-58e4-bf8c-b632b878ffda
STIX ID: report--a9b99ffd-59e0-58e4-bf8c-b632b878ffda
Feed Name: Zscaler Security Research Blog
This report provides a detailed technical analysis of the AvosLocker ransomware (observed since 2021), describing its configurable command-line options, pre-encryption cleanup (process termination, shadow copy and event log deletion, boot policy changes), multi-threaded AES-CBC encryption with RSA-2048-wrapped keys appended to files, file/ folder exclusion lists, observable IOCs (mutex, extensions .avos/.avos2/.avoslinux, ransom note names), and both Windows and Linux/ESXi behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
