SYMBOLCOMMON_NAMEaka. SYNONYMS
elf.avoslocker (Back to overview)

Avoslocker


There is no description at this point.

References
2022-09-28vmwareGiovanni Vigna
ESXi-Targeting Ransomware: The Threats That Are After Your Virtual Machines (Part 1)
Avoslocker Babuk Black Basta BlackCat BlackMatter Conti DarkSide HelloKitty Hive LockBit Luna RansomEXX RedAlert Ransomware REvil
2022-04-07BlackberryThe BlackBerry Research & Intelligence Team
Threat Thursday: AvosLocker Prompts Advisory from FBI and FinCEN
Avoslocker AvosLocker
2022-03-17IC3FBI, FINCEN, U.S. Department of the Treasury
Indicators of Compromise Associated with AvosLocker Ransomware
Avoslocker AvosLocker
2022-03-06QualysGhanshyam More
AvosLocker Ransomware Behavior Examined on Windows & Linux
Avoslocker AvosLocker
2022-03-02LexfoLexfo
AvosLocker Ransomware Linux Version Analysis
Avoslocker
2022-02-25vmwareSudhir Devkar, Threat Analysis Unit
AvosLocker – Modern Linux Ransomware Threats
Avoslocker
2022-01-17CybleincCyble
AvosLocker Ransomware Linux Version Targets VMware ESXi Servers
Avoslocker AvosLocker
Yara Rules
[TLP:WHITE] elf_avoslocker_w0 (20220322 | AvosLocker Ransomware)
rule elf_avoslocker_w0 {
	meta:
		description = "AvosLocker Ransomware"
		author = "VMware Threat Research"
		exemplar_hashes = "7c935dcd672c4854495f41008120288e8e1c144089f1f06a23bd0a0f52a544b1"
		source = "https://blogs.vmware.com/security/2022/02/avoslocker-modern-linux-ransomware-threats.html"
        malpedia_rule_date = "20220322"
        malpedia_hash = ""
		malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.avoslocker"
		malpedia_version = "20220322"
		malpedia_license = "CC BY-NC-SA 4.0"
		malpedia_sharing = "TLP:WHITE"
	strings:
		$s1 = "avoslinux" wide ascii nocase
		$s2 = "README_FOR_RESTORE" wide ascii nocase
		$s3 = "Killing ESXi VMs" wide ascii nocase
	condition:
		uint32(0) == 0x464C457F and filesize > 1MB and filesize < 3MB and
		all of ($s*)
}
Download all Yara Rules