Ziggo ransomware phishing campaign still increasing in size
ID: 71a2efa0-bb0d-586c-b361-86a37d9c14c5
STIX ID: report--71a2efa0-bb0d-586c-b361-86a37d9c14c5
Feed Name: Fox-IT blog
Fox-IT SOC observed an active TorrentLocker ransomware campaign (October 2016) distributing via fake Ziggo invoice phishing e-mails that lead victims to download a ZIP containing JavaScript which downloads the ransomware; infected systems have files encrypted with a ".enc" extension. The report provides IoCs (malicious domains, an IP, SSL certificate details), notes that the malware steals address books to expand propagation, and describes network behavior (initial SSL C2 then Tor) and ongoing takedown/mitigation efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
