XDocCrypt/Dorifel – Document encrypting and network spreading virus
ID: 0aec0b25-b20d-5e00-909a-fea4076fa0dc
STIX ID: report--0aec0b25-b20d-5e00-909a-fea4076fa0dc
Feed Name: Fox-IT blog
Threat Score
This report analyzes an outbreak of a Delphi-based file-encrypting malware distributed by a Citadel/ZeuS variant that converts Office documents into executables, propagates via network shares, and caused approximately 2,200 infections (predominantly in the Netherlands); it documents RC4-based encryption (with a recoverable key/separator), provides IOCs (two C2 IPs and file markers), and offers decryption/recovery guidance and references to vendor detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
