2015-11-23 - ANGLER EK FROM 51.255.25[.]10 SENDS CRYPTOWALL 3.0 RANSOMWARE
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSSOCIATED FILES:
- 2015-11-23-Angler-EK-sends-CryptoWall-3.0-ransomware-traffic.pcap.zip 760.0 kB (760,015 bytes)
- 2015-11-23-Angler-EK-and-CryptoWall-3.0-ransomware-files.zip 325.3 kB (325,297 bytes)
IMAGES
Shown above: Pcap of the traffic filtered in Wireshark.
Shown above: Decrypt instructions showing the malware is CryptoWall 3.0.
Click here to return to the main page.