2019-10-15 - MALSPAM PUSHING SHADE (TROLDESH) RANSOMWARE

ASSOCIATED FILES:

NOTES:

 

IMAGES


Shown above:  Example of malspam pushing Shade (Troldesh) ransomware and the attached PDF file with link to a zip archive.

 


Shown above:  Contents of the downloaded zip archive.

 


Shown above:  Infection traffic when running the extracted JS file.

 


Shown above:  Desktop of an infected Windows host.

 


Shown above:  More info from the infected Windows host.

 


Shown above:  URL for the decryption instructions in a Tor browser.

 


Shown above:  Shade ransomware made persistent on the infected Windows host.

 

Click here to return to the main page.