Azov Ransomware Works as Data Wiper
Azov ransomware is a new variant of file-encrypting malware, which despite its name functions more like a destructive data wiper due to the nature of its ransom note.
Azov does nothing too fancy as a ransomware or in terms of encryption. It will scramble files and append the ".azov" extension to them. Once encryption is finished, the ransomware drops its ransom demands inside a plain text file named "RESTORE_FILES.txt".
The ransom note is dropped inside every directory where files are encrypted. The note is written mostly in English but it is a massive mess in terms of content. The text seeks to imply that it was written by strong pro-Ukrainian actors, but at the same time, the note opens with "Hello, my name is hasherezade. I am the polish security expert".
The ransom note also attempts to frame a number of popular security researchers as parties behind the malware. Of course, you cannot expect the well-known names in the list to actually be involved in a piece of malware that bears the name of a Ukrainian paramilitary regiment with supposed ties to neo-Nazi ultra-nationalism. This means even if a victim would attempt to contact the Azov ransomware authors, they have no way to do it, as the only contacts given are the handles of said security researchers, so in essence, any files encrypted by Azov are impossible to recover.
The full ransom note used by the Azov ransomware goes as follows:
!Azov ransomware!
Hello, my name is hasherezade.
I am the polish security expert.
To recover your files contact us in twitter:
@hasherezade
@VK_Intel
@demonslay335
@malwrhunterteam
@bleepincomputer
Слава Україні #Вцебудеукраїна
[Why did you do this to my files?]
I had to do this to bring your attention to the problem
Do not be so ignorant as we were ignoring Crimea seizure for years.
The reason the west doesn't help enough Ukraine.
Their only help is weapons, but no movements towards the peace!
Stop the war, go to the streets!
Since when that Z-army will be near to my Polska country.
The only outcome is nuclear war.
Change the future now!
Help Ukraine, come to the streets!
We want our children to live in the peaceful world.
#ВцебудеУкраїна
------------------------------------------------
Biden doesn't want help Ukraine.
You people of United States, come to the streets, make revolution!
Keep America great!
------------------------------------------------
Germany plays against their own people!
Du! Ein mann aus Deutschland, kom doch, komm raus!
Das ist aber eine Katastrophe, was Biden zu ihnen gemacht hat.
Wie war das schoen, wenn Merkel war da?
------------------------------------------------
#TaiwanIsChina








