Signed CryptoWall 3.0 Variant Delivered Via MediaFire
ID: 9e4630b4-4703-5d3f-a86c-3fcd3fa1f23b
STIX ID: report--9e4630b4-4703-5d3f-a86c-3fcd3fa1f23b
Feed Name: Zscaler Security Research Blog
This report describes an active CryptoWall 3.0 ('crypt4') ransomware campaign distributing signed executables via malicious CHM attachments and MediaFire; it analyzes the infection chain (persistence via AppData and Startup, registry Run entry, deletion of original), RC4-encrypted C2 registration and key exchange, use of Tor domains for decryption instructions, compromised WordPress sites for C2 hosting, observed IOCs (filenames, paths, registry key), and notes a typical $500 ransom with a one-file free decryption offer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
