logo

Website of security certification provider spreading ransomware

ID: 72e84c2f-858f-518c-8388-bd5b56c616b1

STIX ID: report--72e84c2f-858f-518c-8388-bd5b56c616b1

Feed Name: Fox-IT blog

Threat Score
72/100

Date Published: 2016-03-24

Date Updated: 2026-04-27

...
...

Fox-IT observed a malicious redirect on the EC-Council iClass site that, under specific conditions (Internet Explorer user-agent, search-engine referrer, non-blocked geolocation), redirected visitors to the Angler exploit kit which delivered a Bedep loader and ultimately TeslaCrypt ransomware; the post includes payload details and multiple C2 IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.