Crypto-Ransomware Running Rampant
ID: c8da519d-1ca3-5562-b438-839c6509c4f8
STIX ID: report--c8da519d-1ca3-5562-b438-839c6509c4f8
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes a 2014 CryptoLocker ransomware campaign delivered via phishing/malvertising that infects users with a disguised executable, encrypts user files (targeting common user folders), establishes persistence, and phones home to hard-coded and DGA-driven C2 servers (notably 46.161.30.19/20 and domains like usygoseqowapadoh.com and octoberpics.ru); it includes technical details, IOCs, and recommended mitigations (backups, file-type controls).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
