Difference between revisions of "CTB-Locker"

From Botnets.fr
Jump to navigation Jump to search
m (Text replacement - "TOR" to "Tor")
Line 1: Line 1:
{{Botnet
{{Botnet
|Introduction=CTB for "Curve-TOR-Bitcoin"
|Introduction=CTB for "Curve-Tor-Bitcoin"
|Alias=Critroni,
|Alias=Critroni,
|Target=Microsoft Windows
|Target=Microsoft Windows
|Vector=Angler, Spam,
|Vector=Angler, Spam,
|UserAgent=Unknown
|UserAgent=Unknown
|CCProtocol=TOR, Bitcoin payment, Elliptic curve encryption,
|CCProtocol=Tor, Bitcoin payment, Elliptic curve encryption,
|Status=Unknown
|Status=Unknown
|BeginYear=2014
|BeginYear=2014

Revision as of 18:19, 3 August 2015

(Botnet) Link to the old Wiki page : [1] / Google search: [2]

CTB-Locker
Alias Critroni
Group Ransomware
Parent
Sibling
Family
Relations Variants:

Sibling of:
Parent of:
Distribution of:
Campaigns:

Target Microsoft Windows
Origin
Distribution vector Angler, Spam
UserAgent Unknown
CCProtocol Tor (Distributed-centralized), Bitcoin payment (), Elliptic curve encryption ()
Activity 2014 / Unknown
Status Unknown
Language
Programming language
Operation/Working group

Introduction

CTB for "Curve-Tor-Bitcoin"

Features

Associated images

Checksums / AV databases

Publications

 AuthorEditorYear
"Crypto Ransomware" CTB-Locker (Critroni.A) on the riseKafeineKafeine2014
CTB-Locker is back: the web server editionIdo NaorKaspersky Securelist2016
Critroni crypto ransomware seen using Tor for command and controlDennis FisherKaspersky lab2014
Kaspersky security bulletin 2015. Overall statistics for 2015Maria Garnaeva
Jornt van der Wiel
Denis Makrushin
Anton Ivanov
Yury Namestnikov
Kaspersky Securelist2015
Le dropper de CTB-LockerChristophe Rieunier2015
New crypto-ransomware emerge in the wildEduardo Altares IITrend Micro2014
Your files are encrypted with a “Windows 10 Upgrade”TALOSCISCO2015