Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 0 hostnames
CryptoWall is a ransomware family referenced in the provided content as one of the major cryptomalware strains active during the mid-2010s.
Profile source: Mallory opens in a new tabCryptoWall
CryptoWall is a ransomware family referenced in the provided content as one of the major cryptomalware strains active during the mid-2010s. It is described as a copycat family in relation to CryptoLocker, but also as a major ransomware threat in its own right and part of the global surge in cryptomalware observed from mid-2014 onward. The content associates CryptoWall with file-encrypting ransomware activity and notes that, like CryptoLocker, it used unique Tor hidden service Bitcoin payment domains. CryptoWall is cited alongside other prominent ransomware families including CryptoDefense, Locky, Cerber, TeslaCrypt, CTB-Locker, GandCrab, and Magniber.
The content links CryptoWall to exploit-kit-driven delivery, specifically stating that Magnitude Exploit Kit has been known to drop CryptoWall, along with Locky, Cerber, Magniber, and GandCrab. It is also referenced in broader reporting on ransomware botnet/controller activity and malware trends. No specific threat actor is directly attributed as the developer or operator of CryptoWall in the provided material, but the malware is mentioned in contexts involving large-scale ransomware distribution ecosystems.
High-confidence behavioral details in the content are limited, but CryptoWall is consistently characterized as ransomware/cryptomalware that encrypts victim data and demands Bitcoin payment via Tor-based infrastructure. No specific industries, platforms, hashes, domains, wallet addresses, or other unique indicators of compromise are provided for CryptoWall itself in the supplied content.
C2 tracking
Derp observations, rolling seven-day window
Samples
2e2e035ece4accdee838ecaacdc263fa526939597954d18d1320d73c8bf810c2 2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.