New Torrentlocker variant active in the Netherlands
ID: 05114650-7740-5256-9550-b3a628db9559
STIX ID: report--05114650-7740-5256-9550-b3a628db9559
Feed Name: Fox-IT blog
**Executive summary:** A Netherlands-focused spam campaign starting 13 October 2014 used PostNL-themed phishing emails and compromised WordPress pages to redirect victims to fake tracking sites that delivered a ZIP containing the TorrentLocker (cryptolocker) payload; infected hosts generate encryption keys, encrypt files and present a ransom demand (~€400). The report provides network and host IOCs (malicious redirect pages, postnl-track domains, C2 domains server4love.ru and octoberpics.ru, IPs 46.161.30.20/16 and fake PostNL IPs), host indicators (dropped C:\WINDOWS[a-z]{8}.exe, registry startup entry, a second explorer.exe process), and step-by-step containment and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
