What is the OBZ Ransomware?

OBZ is a type of ransomware that is the same as the U2K and MME ransomware variants.

The program encrypts files and changes their filenames to include ".OBZ", for example, renaming a file called "1.jpg" to "1.jpg.OBZ".

After this process is completed, a ransom note named "ReadMe.txt" is created. OBZ's process in Windows Task Manager shows up with the name "Traffic Light" (this name may change with different attack campaigns). The message within the ransom note states that the affected data can only be restored by paying a ransom; various contact details are provided for victims to reach out to the attackers.

The full ransom note reads as follows:


Attention!

All your files, documents, photos, databases and other important files are encrypted

The only method of recovering files is to purchase an unique decryptor. Only we can give you this decryptor and only we can recover your files.

The server with your decryptor is in a closed network TOR. You can get there by the following ways:

--------------------------------------------------

1. Download Tor browser - hxxps://www.torproject.org/
2. Install Tor browser
3. Open Tor Browser
4. Open link in TOR browser: hxxp://obzuqvr5424kkc4unbq2p2i67ny3zngce3tbdr37nicjqesgqcgomfqd.onion/?101VWOPRTUL
5. and open ticket

--------------------------------------------------

Alternate communication channel here: hxxps://yip.su/2QstD5

How To Detect, Stop, and Remove OBZ Ransomware From Your Computer

December 7, 2022
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.