logo

XDocCrypt/Dorifel – Document encrypting and network spreading virus

ID: 0aec0b25-b20d-5e00-909a-fea4076fa0dc

STIX ID: report--0aec0b25-b20d-5e00-909a-fea4076fa0dc

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2012-08-09

Date Updated: 2026-04-27

...
...

This report analyzes an outbreak of a Delphi-based file-encrypting malware distributed by a Citadel/ZeuS variant that converts Office documents into executables, propagates via network shares, and caused approximately 2,200 infections (predominantly in the Netherlands); it documents RC4-based encryption (with a recoverable key/separator), provides IOCs (two C2 IPs and file markers), and offers decryption/recovery guidance and references to vendor detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.