What is the OBZ Ransomware?
OBZ is a type of ransomware that is the same as the U2K and MME ransomware variants.
The program encrypts files and changes their filenames to include ".OBZ", for example, renaming a file called "1.jpg" to "1.jpg.OBZ".
After this process is completed, a ransom note named "ReadMe.txt" is created. OBZ's process in Windows Task Manager shows up with the name "Traffic Light" (this name may change with different attack campaigns). The message within the ransom note states that the affected data can only be restored by paying a ransom; various contact details are provided for victims to reach out to the attackers.
The full ransom note reads as follows:
Attention!
All your files, documents, photos, databases and other important files are encrypted
The only method of recovering files is to purchase an unique decryptor. Only we can give you this decryptor and only we can recover your files.
The server with your decryptor is in a closed network TOR. You can get there by the following ways:
--------------------------------------------------
1. Download Tor browser - hxxps://www.torproject.org/
2. Install Tor browser
3. Open Tor Browser
4. Open link in TOR browser: hxxp://obzuqvr5424kkc4unbq2p2i67ny3zngce3tbdr37nicjqesgqcgomfqd.onion/?101VWOPRTUL
5. and open ticket
--------------------------------------------------
Alternate communication channel here: hxxps://yip.su/2QstD5









