Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

CryptoWall

63
Global rank
80 infographic chevron month
Month rank
70 infographic chevron week
Week rank

CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.

Ransomware
Type
Unknown
Origin
1 January, 2014
First seen
14 September, 2026
Last seen

How to analyze CryptoWall with ANY.RUN

Type
Unknown
Origin
1 January, 2014
First seen
14 September, 2026
Last seen

IOCs

IP addresses
192.185.96.50
64.89.163.22
164.90.210.228
140.82.121.3
91.92.242.236
172.236.108.48
178.16.54.109
2.23.246.9
160.153.0.95
172.64.149.23
200.108.194.122
185.199.109.133
221.194.141.164
185.199.108.133
183.214.164.143
23.216.77.37
85.137.245.141
129.152.20.82
168.138.162.78
144.172.107.214
Hashes
020f1fa6072108c79ed6f553f4f8b08e157bf17f9c260a76353300230fed09f0
a8bd235303668981563dfb5aae338cb802817c4060e2c199b7c84901d57b7e1e
496aca80e4d8f29fb8e8cd816c3afb48d3f103970b3a2ee1600c08ca67326dee
56149c2caa7e4b648802d12d51fcd0d6523640925b44524d5261f193e7e217d6
4d2af9283f59dd98dc1852a5213d5092dd832c3e797c7ee57908fa9ff122983d
7d3b929171850274fb98568208e4300c0477382b439538a3ddefb9b8890ea0e9
a73c111c77e4de9e41fe478aefc73f77b7bcabc55f07f1482b62b8ba46a3e476
3cc8500a958cc125809b0467930ebcce88a09dcc0cedd7a45facf3e332f7db33
9a0e05274cad8d90f6ba6bc594261b36bfbddf4f5ca6846b6367fe6a4e2fdce4
0ed7a6ed080499bc6c29d7113485a8a61bdba93087b010fca67d9b8289cbe6fa
b20dd6f5fab31476d3d8d7f40cb5ab098117fa5612168c0ff4044945b6156d47
7d7f5f231eeec067a841e4cae009d9feb9b5fa0d8fd49ee889bf812b802b9f64
35a8879678f63635e2d4d41dec511b0e71ab8e5b8bf7f8b92ac615e4452d2af8
6efbac1d35ea5310a7c0df9b79a3e0c6f59ec9459d2a9a44da89be46c5d3507d
c7d94773176e1ac7cb58a822ee754b4ac54a6847f34314278c7e2c2194b0878f
c854df36b38a0ec029be08821b8757d3691312ca2aef7d7083badadeae990c9a
e3eaef80d44325034e9b6ccb60d43a30f0877cc20eb45789c15acb51ec996f9c
59f1ebc702c7d70146a890fda6933511a46b55d5f73dd7e54707d9f8d53002bd
d4f884fdabd94dc896c031a1b1f23ffbd52d07c2d6386afda05338a510218c82
490126abfa9f5d7a87268a78a0a511e6749ae52cc1114fda0460eceddf0756f6
Domains
bnet-api.playm8ru.win
thtp2.volamngayxua.net
tobecation.github.io
pvsa.gxfugy.cn
bnet.playm8ru.win
harmeetmotors.com
m.meta-dm.com
dcwblida.dz
dl.ijinshan.com
secure.firmwaresync.com.tr
checkfivem.com
ins.pplive.com
download2.huduntech.com
www.google.com
backupso.com
check.screenconnect.com
pub-bbbdebc2599c4d74b04c5d53e439f7a7.r2.dev
d.kpzip.com
release-assets.githubusercontent.com
acc.jiangsujiaxue.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://217.60.195.219/boss/boss.bat
http://91.92.242.236/files-129312398/files/file_44ef7cc8421220d0.exe
http://91.92.242.236/files-129312398/files/file_4b8d61b5a6f660b5.exe
http://193.178.158.107/bin/189e7e8ebfcbd873_cryptoclipper.exe
http://62.60.226.140/files/gold/file.exe
http://193.178.158.107/bin/46d0be2a38b04583_syshost_loader.exe
http://193.178.158.107/2.exe
http://193.178.158.107/4.exe
http://62.60.226.140/files/com/kliulij.exe
http://217.60.195.219/ty/s.bat
http://62.60.226.140/files/unique2/file.exe
http://178.16.54.109/rvn.exe
http://91.92.242.236/files-129312398/files/file_e52c89b6e6519b51.exe
http://144.172.107.214/29/goodthingsforbestpersonforme.hta
http://196.251.107.186/2.7.exe
http://192.162.199.246/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/6eq5gvofrvnmci54.exe
http://192.162.199.246/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/9z7bgnrgpgs8czv7.exe
http://178.16.54.109/xmrig.exe
Last Seen at
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1351
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1647
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3241
comments 0

CryptoWall Ransomware: How the Comeback Veteran Still Costs Businesses Millions

Key Takeaways

  1. CryptoWall remains active through code reuse and updated variants.
  2. Its main vectors: phishing, exploit kits, and RDP brute force.
  3. Businesses lose not only money — but operations and reputation.
  4. Detection requires layered security: EDR, logging, sandboxing.
  5. Offline backups dramatically reduce impact and negotiation leverage.
  6. Threat Intelligence Lookup lets analysts instantly check IOCs against data from 15K SOCs worldwide.

filePath:"Project_Workshop_7th_Minutes.txt".

File detected as CryptoWall IOC via TI Lookup File detected in CryptoWall malware samples via TI Lookup

  1. ANY.RUN's Sandbox helps analyze CryptoWall behavior and extract fresh indicators.

View analysis

CryptoWall sample in the Sandbox CryptoWall sample detonated in the ANY.RUN Sandbox

What is CryptoWall Malware?

CryptoWall represents a pivotal evolution in ransomware, transforming from a crude CryptoLocker clone into a sophisticated, polymorphic threat. Initially distributed in November 2013, it gained prominence in early 2014, after law enforcement dismantled CryptoLocker's infrastructure. By mid-2015, it has generated an estimated $325 million in revenue for its operators through relentless campaigns.

Unlike earlier ransomware that merely locked screens, CryptoWall employs asymmetric RSA encryption to scramble files across local drives, network shares, and removable media, appending extensions like .cryptowall to affected documents, photos, and databases. Its variants, up to CryptoWall 4.0, incorporated anti-detection techniques, such as Tor and I2P anonymity networks for command-and-control (C2) communication, RC4-encrypted traffic, and polymorphic code to evade antivirus signatures.

The malware communicates with command-and-control servers over the Tor anonymous network, making it difficult to trace or disrupt. After encryption, victims receive detailed ransom notes with instructions for payment, typically ranging from $200 to $10,000, though some victims reportedly paid significantly more. CryptoWall's trademark is its psychological warfare: ransom notes taunt victims with countdown timers, previews of decryptable files to build false hope, and threats to destroy keys if unpaid, often within 72 hours.

What distinguishes CryptoWall from simpler ransomware is its technical sophistication. It operates on both 32-bit and 64-bit systems, deletes shadow copies to prevent file recovery, disables System Restore features, and even installs spyware to steal passwords and Bitcoin wallets. The encryption implementation is effectively unbreakable without the private key held by attackers, making prevention the only viable defense strategy.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

CryptoWall Ransomware Victimology

The targeting strategy appears opportunistic rather than selective. CryptoWall campaigns have affected individuals who accidentally opened malicious email attachments, businesses whose employees fell victim to phishing schemes, and organizations with unpatched software vulnerabilities. Notable incidents included the Australian Broadcasting Corporation, which experienced disrupted television programming due to a CryptoWall infection, and numerous healthcare organizations that faced operational challenges when patient records became encrypted.

Geographic analysis shows that targets have primarily been concentrated in the United States and United Kingdom, though infections occurred globally. The ransomware infected over 625,000 systems within its first six months of widespread distribution, encrypting approximately 5.25 billion files.

How CryptoWall Functions

The attack sequence begins when the malware gains initial access through various infection vectors. Email remains the primary distribution method, with attackers using the Cutwail spam botnet sending massive campaigns that contain malicious attachments or links.

When victims open attachments disguised as PDF files, Word documents, or ZIP archives, they actually execute the dropper, which then contacts compromised websites to download the CryptoWall payload. This multi-stage delivery complicates detection, as the initial file may appear benign to security software while the actual ransomware is fetched dynamically.

Exploit kits represent another major infection vector. Major advertising networks serving sites including Disney, Facebook, and The Guardian were compromised in campaigns that exposed millions of users to potential infections.

Within organizational networks, CryptoWall spreads by encrypting files on network shares accessible to the infected user account. While the malware doesn't include worm-like capabilities for self-propagation between systems, its ability to encrypt files across mapped network drives means a single infected endpoint can potentially encrypt data throughout an entire organization.

Upon execution, the ransomware immediately attempts to establish persistence mechanisms, though later variants operate entirely in memory to avoid disk-based detection.

The malware's first critical action involves contacting command-and-control servers, typically hosted on the Tor network for anonymity. This communication serves multiple purposes: retrieving the public key used for encrypting the symmetric encryption keys, registering the victim with a unique identifier, and receiving configuration parameters that control the encryption process. If network connectivity fails, some variants will wait and retry rather than proceeding, as the C2 communication is essential for the attack's success.

Once connected, CryptoWall initiates its file discovery and encryption routine. The malware creates malicious instances of legitimate Windows processes like explorer.exe and svchost.exe to perform its operations, helping it blend with normal system activity. It systematically enumerates all accessible storage, identifying files with targeted extensions. The encryption process uses AES symmetric encryption for speed, with each file receiving a unique AES key. These symmetric keys are then encrypted with an RSA public key, making recovery impossible without the corresponding private key held by attackers.

Throughout the encryption process, CryptoWall takes defensive actions to prevent recovery. It deletes Volume Shadow Copies using the Windows vssadmin.exe utility with commands like "vssadmin delete shadows /all /quiet" to eliminate backup copies without user notification. The malware modifies registry entries to disable System Restore and may clear Windows Event Logs to remove evidence of its activities. Some variants also attempt to disable or evade antivirus software through various techniques including process injection and rootkit-like behaviors.

Sandbox Analysis of a CryptoWall Sample

ANY.RUN's interactive malware sandbox allows analysts to safely execute and analyze CryptoWall samples, revealing evasion techniques, C2 communications, and encryption behaviors that inform detection rules and defensive strategies.

View a CryptoWall sample analysis

CryptoWall Sandbox analysis CryptoWall Sandbox analysis

The malware is distributed as an LNK file disguised as a legitimate shortcut. When opened, the LNK launches a PowerShell script that executes the core functionality.

The script tracer of the Sandbox shows how at the start, the malware creates a scheduled task to ensure persistence. The parameters are added: daily mode, no additional day intervals or random delays, and an exact start time of 17:00. Additional options are configured so the task runs even on battery power, does not stop when switching to battery, starts as soon as possible, and ignores the computer's sleep mode.

CryptoWall script establishing persistence CryptoWall script establishing persistence

The malicious program also launches Windows Notepad to display the file Project_Workshop_7th_Minutes.txt, created to mask the program's main functionality.

CryptoWall key processes CryptoWall key processes

The encryption process can be divided into several stages. File discovery occurs recursively through user directories, skipping system folders.

Encryption uses the typical combination of symmetric AES for file encryption. The AES key is encrypted with the attackers' public RSA key. This encrypted AES key, along with the initialization vector and the encrypted file contents, is appended to the end of the file.

Encryption code snippet PowerShell commands showing AES key generation and RSA encryption

A ransom note is created as an HTML file with detailed payment instructions and a timer to pressure the victim into acting quickly.

CryptoWall ransom note screenshot CryptoWall ransom message screenshot with countdown timers for payment and file deletion

Overall, CryptoWall is a classic ransomware specimen: a combination of stealthy infection, rapid encryption, and mechanisms to pressure the victim. Regularly back up important files to external media, use up-to-date antivirus software, monitor the Windows Task Scheduler for suspicious entries, disable macros in Office and PDF files, and train users not to open suspicious shortcuts from emails or downloaded files.

How CryptoWall ransomware threatens businesses and organizations

For healthcare organizations, CryptoWall infections can delay patient care, limit access to medical records, and force reliance on paper-based systems. Educational institutions face interrupted classes, lost research data, and administrative challenges. Financial services organizations risk regulatory penalties for data security failures, while manufacturing and logistics companies experience supply chain disruptions when production systems become unavailable.

Customers and partners lose confidence in organizations that suffer ransomware attacks, particularly if sensitive data is potentially compromised. Media coverage of infections can damage brand value and market position. Even organizations that successfully recover from attacks often face long-term trust deficits that affect business relationships and customer retention.

Gathering Threat Intelligence on CryptoWall ransomware

Threat Intelligence Lookup enables security teams to quickly search for information about suspicious files, URLs, domains, and IP addresses potentially associated with CryptoWall.

By querying file hashes or URLs encountered in environments, analysts can immediately determine if they match known CryptoWall samples, view detailed behavioral analysis, and understand the specific capabilities and infrastructure of particular variants.

This rapid intelligence access accelerates incident response and enables proactive blocking of threats before they impact systems.

Start exploring the threat by looking it up by the name:

threatName:"cryptowall".

CryptoWall samples found via TI Lookup Malware samples with CryptoWall detected, found via TI Lookup]

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

CryptoWall demonstrates how cybercriminals can weaponize strong encryption to generate hundreds of millions of dollars while causing widespread organizational disruption. Though newer ransomware families have emerged since CryptoWall's peak activity, the fundamental threat model it established (combining multiple infection vectors, strong encryption, anonymous infrastructure, and cryptocurrency payments) persists across modern ransomware operations.

Modern threat intelligence and analysis tools have evolved significantly in response to threats like CryptoWall. Malware sandboxes, threat intelligence platforms, and security automation enable faster detection, more effective response, and proactive defense strategies that were unavailable during CryptoWall's emergence. Organizations that leverage these capabilities while maintaining security fundamentals position themselves to resist not only CryptoWall variants that may still circulate but also the next generation of ransomware threats.

Start gathering actionable threat intelligence on CryptoWall by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

Miolab Stealer screenshot
Miolab Stealer is a macOS malware threat designed to steal user credentials and sensitive files without raising immediate suspicion. It relies on fake system prompts and legitimate built-in tools to make malicious actions look routine. Instead of causing obvious disruption, it quietly collects valuable data and prepares it for exfiltration from the device. By blending deception with trusted macOS behavior, it increases the chance that the attack will go unnoticed in its early stages. This makes early behavioral detection critical before the theft of credentials and files is complete.
Read More
Qilin Ransomware screenshot
Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.
Read More
Kamasers screenshot
Kamasers
kamasers
Kamasers is a multi-functional DDoS botnet malware that transforms infected machines into remotely controlled attack nodes. It combines network-layer flooding capabilities, resilient command-and-control (C2), and payload delivery, making it not just a disruption tool but a gateway to broader compromise.
Read More
PureCrypter screenshot
PureCrypter
purecrypter
First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.
Read More
Trojan screenshot
Trojan
trojan trojan horse
Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.
Read More
Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More