A Deep-dive Analysis of VENOMOUS Ransomware
ID: 8cfb394e-d20a-57f8-86ed-791a42e44860
STIX ID: report--8cfb394e-d20a-57f8-86ed-791a42e44860
Feed Name: Cyble Blog
Cyble Research Labs provides a technical analysis of VENOMOUS ransomware: a Python x64 console application that encrypts files using AES-256 (per-file IV), appends a .VENOMOUS/.venomnous extension, attempts to stop mssql/MySQL processes to impact databases, and drops a ransom note (SORRY-FOR-FILES.txt) that points victims to a Tor site and Telegram contact; the report includes extracted/decompiled source code, observed behaviours, IOCs (SHA256 hash, onion URL, Telegram ID), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
