logo

New Torrentlocker variant active in the Netherlands

ID: 05114650-7740-5256-9550-b3a628db9559

STIX ID: report--05114650-7740-5256-9550-b3a628db9559

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2014-10-15

Date Updated: 2026-04-27

Author: Fox It

...
...

**Executive summary:** A Netherlands-focused spam campaign starting 13 October 2014 used PostNL-themed phishing emails and compromised WordPress pages to redirect victims to fake tracking sites that delivered a ZIP containing the TorrentLocker (cryptolocker) payload; infected hosts generate encryption keys, encrypt files and present a ransom demand (~€400). The report provides network and host IOCs (malicious redirect pages, postnl-track domains, C2 domains server4love.ru and octoberpics.ru, IPs 46.161.30.20/16 and fake PostNL IPs), host indicators (dropped C:\WINDOWS[a-z]{8}.exe, registry startup entry, a second explorer.exe process), and step-by-step containment and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.