FOZA Virus Ransomware [.foza Files] Remove and Decrypt
Tags
country: | Australia Netherlands Germany France Greece India Italy Spain Poland Portugal United Kingdom United States Of America |
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Data Direct Email Account - T1087.003 Malware - T1587.001 Malware - T1588.001 Phishing - T1660 Phishing - T1566 Software - T1592.002 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | eaea479f-b780-4af0-ac57-6518afd13519 |
Fingerprint | 875218492527aed9 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | April 24, 2023, 5:45 p.m. |
Added to db | April 25, 2023, 12:14 a.m. |
Last updated | Nov. 12, 2024, 3:58 a.m. |
Headline | FOZA Virus Ransomware [.foza Files] Remove and Decrypt |
Title | FOZA Virus Ransomware [.foza Files] Remove and Decrypt |
Detected Hints/Tags/Attributes | 79/3/8 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 163 | ✔ | — | https://media.cert.europa.eu/rss?type=category&id=Malware&language=en&duplicates=false | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 29 | stopcrypt.km |
|
Details | Domain | 544 | sensorstechforum.com |
|
Details | File | 40 | _readme.txt |
|
Details | File | 51 | picture.jpg |
|
Details | Windows Registry Key | 493 | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run |
|
Details | Windows Registry Key | 582 | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
|
Details | Windows Registry Key | 470 | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce |
|
Details | Windows Registry Key | 480 | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce |