CryptoWire ransomware not dead
ID: a55aa77a-8194-5c68-bc50-66d04eb7cba9
STIX ID: report--a55aa77a-8194-5c68-bc50-66d04eb7cba9
Feed Name: Blaze's Security Blog
Threat Score
The report analyzes a recent CryptoWire ransomware sample, describing its ransom note, targeted file extensions, AES encryption mechanism, use of .encrypted. file markers, shadow copy deletion via vssadmin and BCDEdit changes, and persistence through a scheduled task; it also lists the attacker’s contact email and provides a decryption key specific to this variant.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
