A Deep-dive Analysis of the AvosLocker Ransomware
ID: ec8b38d0-e0e5-5c0c-bb72-e31bb41260f7
STIX ID: report--ec8b38d0-e0e5-5c0c-bb72-e31bb41260f7
Feed Name: Cyble Blog
Threat Score
This report from Cyble Research Lab analyzes the AvosLocker ransomware: a Windows console-based C/C++ ransomware that encrypts files (appending .avos), targets network shares, uses AES-256, employs techniques such as Restart Manager and process termination, creates GET_YOUR_FILES_BACK.txt ransom notes pointing to an onion site, and includes IOCs (a SHA-256 hash and a mutex name) plus recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
