Difference between revisions of ""Crypto Ransomware" CTB-Locker (Critroni.A) on the rise"

From Botnets.fr
Jump to navigation Jump to search
 
m (Text replacement - "Campaign1=" to "Campaign=")
 
(2 intermediate revisions by the same user not shown)
Line 6: Line 6:
|Type=Blogpost
|Type=Blogpost
|Video=
|Video=
|Link=http://malware.dontneedcoffee.com/2014/07/ctb-locker.html malware.dontneedcoffee.com
|Link=http://malware.dontneedcoffee.com/2014/07/ctb-locker.html
|Author=Kafeine,  
|Author=Kafeine,  
|NomRevue=Malware don't need Coffee
|NomRevue=Malware don't need Coffee
Line 17: Line 17:
|Malware=,  
|Malware=,  
|ExploitKit=,  
|ExploitKit=,  
|Campaign1=
|Campaign=
|Campaign2=
|Campaign2=
|Campaign3=
|Campaign3=

Latest revision as of 22:32, 31 July 2015

(Publication) Google search: [1]

"Crypto Ransomware" CTB-Locker (Critroni.A) on the rise
Botnet Critroni
Malware
Botnet/malware group
Exploit kits
Services
Feature
Distribution vector
Target
Origin
Campaign
Operation/Working group
Vulnerability
CCProtocol
Date 2014 / 2014-07-18
Editor/Conference Kafeine
Link http://malware.dontneedcoffee.com/2014/07/ctb-locker.html (Archive copy)
Author Kafeine
Type Blogpost

Abstract

Advertised since middle of june on Underground, CTB-Locker (Curve-Tor-Bitcoin Locker) is flagged Critroni.A by Microsoft. It seems at second half of june it was mainly used against russians, now it seems more widely used.

Bibtex

 @misc{Lua error: Cannot create process: proc_open(/dev/null): failed to open stream: Operation not permitted2014BFR1403,
   editor = {Kafeine},
   author = {Kafeine},
   title = {"Crypto Ransomware" CTB-Locker (Critroni.A) on the rise},
   date = {18},
   month = Jul,
   year = {2014},
   howpublished = {\url{http://malware.dontneedcoffee.com/2014/07/ctb-locker.html}},
 }