Incaseformat Virus

Suggestions on Detection and Prevention of the Incaseformat Virus

January 20, 2021

Overview

On January 13, 2021, NSFOCUS’s emergency response team received feedback on the incaseformat virus from a host of customers in the government, healthcare, education, and telecom sectors. According to analysis, we found that this virus mainly infected hosts installed with financial management application systems. Also, we observed that all other files than system partition files are deleted from infected hosts and that this virus is named incaseformat because an empty file with the name incaseformat.log exists in the root directory of the partition where the deleted files are stored.

(more…)

Search

Subscribe to the NSFOCUS Blog