Technical analysis of CryptoMix/CryptFile2 ransomware
ID: 3549a0f1-7c2f-5793-87b3-32115173dd7a
STIX ID: report--3549a0f1-7c2f-5793-87b3-32115173dd7a
Feed Name: CERT Polska
This report analyzes the CryptoMix (formerly CryptFile2) ransomware: its distribution via the Rig exploit kit, unusual high ransom demands and email-based payment process, primitive XOR packing, AES-256-CBC encryption derived from an RSA key (implemented symmetrically and without an IV), registry persistence, and removal of shadow copies. The analysis documents cryptographic flaws that permit decryption for some vulnerable variants, provides sample hashes/IOCs, and offers contact information for assistance decrypting affected files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
