CryptoWall 3.0 Campaign Still Kicking
ID: 429b96de-a593-5d83-9034-1d9eb8c5f2a4
STIX ID: report--429b96de-a593-5d83-9034-1d9eb8c5f2a4
Feed Name: Zscaler Security Research Blog
This report documents a CryptoWall 3.0 ransomware campaign that spreads via spam, compromised websites, and exploit kits by delivering executables masquerading as JPEGs (URL pattern /images/one.jpg or two.jpg). Infected systems have files encrypted with asymmetric cryptography, deleted original samples, and are left with HELP_DECRYPT.[PNG|HTML|TXT|URL] instructions directing victims to a TOR-based Decryption Service; the malware beacons to multiple global C2 domains with POST requests using a consistent URI pattern and uses specific nameservers and sample domains that are listed as indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
