Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

CryptoWall

62
Global rank
74 infographic chevron month
Month rank
134 infographic chevron week
Week rank
0
IOCs

CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.

Ransomware
Type
Unknown
Origin
1 January, 2014
First seen
28 August, 2026
Last seen

How to analyze CryptoWall with ANY.RUN

Type
Unknown
Origin
1 January, 2014
First seen
28 August, 2026
Last seen

IOCs

IP addresses
200.43.178.237
222.25.196.3
117.72.242.9
210.243.136.114
210.40.225.135
210.183.225.16
159.254.4.233
129.28.245.228
165.57.191.50
134.131.43.0
82.163.137.66
33.59.140.89
35.234.67.204
169.20.110.100
27.37.3.185
96.85.140.112
210.127.39.250
192.95.200.170
196.190.220.153
33.59.187.160
Hashes
92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50
a17fcf0a2f50e2d495e4f90ce263410edc183add6c62699a2facbccf60410f74
69b61b2c00323cea3686315617d0f452e205dae10c47e02cbe1ea96fea38f582
ba25fefad8a545281ae6f99515926717ebe8c1146805795bedd32041192a0688
61450bd6bc6590236b1df56e1594b12ae174496357a49b5963c41d0d1465d66f
84b900dbd7fa978d6e0caee26fc54f2f61d92c9c75d10b35f00e3e82cd1d67b4
5bdd60c20bf45fbb96d6df9a27040a12b2a131bbf81445bb291a3d4c237c3638
0bda727d28b1303c50ca05c71522af79a0dc714338ef57634682171327fc772f
4055d1b9e553b78c244143ab6b48151604003b39a9bf54879dee9175455c1281
f5d002bfe80b48386a6c99c41528931b7f5df736cd34094463c3f85dde0180bf
326bcb85652c67780d0193d78d5bab30e3668e6bcbcffcff304751b2f4518f54
28afa9302c5708c74af235d477cb13c0dd1358f2ea17f3d08a4c02b6fe4a0939
408ad45577c7d5d163c0019fa9f900fcbf132a1183dbc58cf14cb83e195c6bfa
99e6eb0215c652fe9e9b2f91db5759286cd04f837ce09b331f88f804b0be5195
c9d5bb7022889629ac75a5f7b56779c5ed3d4facea41effd1616039d95bbbc5d
2c8a0014e2b00ecece9639af449fee4c8b8af95a2b9e1589715168fdc9f14600
21ff1de20ee321daf3b67e5d4b8cbfa34cce3af19276abd7f8ae3dcf21e9e971
e01730fda4af0b4efcd46b2ed11ec9a6f46335f0da943ec574de0c0c81e87e62
8db6544480798c1f7e62868ab5f60722bba009cd2b7ca656dd72f40a51b4ebdd
63bcd09c106915cebed1ab7ed14f59b568ebb338e25c876b98580e4578be0cc2
Domains
ip-api.com
pastebin.com
slscr.update.microsoft.com
edge-consumer-static.azureedge.net
urlhaus.abuse.ch
www.google.com
0022a601.pphost.net
matthewsigmondv5.pages.dev
github.com
safeuploadz.com
fonts.googleapis.com
resolver.disbalancer.com
qiniuyunxz.yxflzs.com
mogimall.com
edge-mobile-static.azureedge.net
c.pki.goog
settings-win.data.microsoft.com
cnr.microsoft-telemetry.at
open.spotify.com
gitlab.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://urlhaus.abuse.ch/downloads/text_online/
http://144.172.71.105:1338/nova_flow/patcher.exe
https://www.blackhattoolz.com/licensing/updates/addmefast%20bot.exe
https://raw.githubusercontent.com/leetcipher/malware.development/main/process-injection/process-injection.exe
https://raw.githubusercontent.com/haa15/driver-shitty/main/kdmapper_release.exe
https://github.com/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/lol11.exe
https://release-assets.githubusercontent.com/github-production-release-asset/1055902550/c1473cf5-ad3b-426a-8984-5bc61976d274?sp=r&sv=2018-11-09&sr=b&spr=https&se=2026-08-28t12%3a24%3a38z&rscd=attachment%3b+filename%3dlol11.exe&rsct=application%2foctet-stream&skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0&sktid=398a6654-997b-47e9-b12b-9515b896b4de&skt=2026-08-28t11%3a23%3a43z&ske=2026-08-28t12%3a24%3a38z&sks=b&skv=2018-11-09&sig=c55xqnra0h1y9qkw2iqmtw5pab2x6spaimkomqi6niy%3d&jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc4nzkxnzizmiwibmjmijoxnzg3ote2otmylcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.xx_s-1rm4wy4vlc8piwgob44k-01m9e-y4y99trt0by&response-content-disposition=attachment%3b%20filename%3dlol11.exe&response-content-type=application%2foctet-stream
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://144.172.71.105:1338/nova_flow/patcher.exe?hash
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://45.138.16.51/bin/screenconnect.clientsetup.exe
http://192.162.199.149/uploads/d6a0dbb9ae834113a8401012b1f9aa18.exe
http://0022a601.pphost.net/threatsim/exe/640.exe
http://0022a601.pphost.net/threatsim/exe/xerox01_pdf.exe
http://119.193.158.215/center.exe
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 3153
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 8509
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 11265
comments 0

CryptoWall Ransomware: How the Comeback Veteran Still Costs Businesses Millions

Key Takeaways

  1. CryptoWall remains active through code reuse and updated variants.
  2. Its main vectors: phishing, exploit kits, and RDP brute force.
  3. Businesses lose not only money — but operations and reputation.
  4. Detection requires layered security: EDR, logging, sandboxing.
  5. Offline backups dramatically reduce impact and negotiation leverage.
  6. Threat Intelligence Lookup lets analysts instantly check IOCs against data from 15K SOCs worldwide.

filePath:"Project_Workshop_7th_Minutes.txt".

File detected as CryptoWall IOC via TI Lookup File detected in CryptoWall malware samples via TI Lookup

  1. ANY.RUN's Sandbox helps analyze CryptoWall behavior and extract fresh indicators.

View analysis

CryptoWall sample in the Sandbox CryptoWall sample detonated in the ANY.RUN Sandbox

What is CryptoWall Malware?

CryptoWall represents a pivotal evolution in ransomware, transforming from a crude CryptoLocker clone into a sophisticated, polymorphic threat. Initially distributed in November 2013, it gained prominence in early 2014, after law enforcement dismantled CryptoLocker's infrastructure. By mid-2015, it has generated an estimated $325 million in revenue for its operators through relentless campaigns.

Unlike earlier ransomware that merely locked screens, CryptoWall employs asymmetric RSA encryption to scramble files across local drives, network shares, and removable media, appending extensions like .cryptowall to affected documents, photos, and databases. Its variants, up to CryptoWall 4.0, incorporated anti-detection techniques, such as Tor and I2P anonymity networks for command-and-control (C2) communication, RC4-encrypted traffic, and polymorphic code to evade antivirus signatures.

The malware communicates with command-and-control servers over the Tor anonymous network, making it difficult to trace or disrupt. After encryption, victims receive detailed ransom notes with instructions for payment, typically ranging from $200 to $10,000, though some victims reportedly paid significantly more. CryptoWall's trademark is its psychological warfare: ransom notes taunt victims with countdown timers, previews of decryptable files to build false hope, and threats to destroy keys if unpaid, often within 72 hours.

What distinguishes CryptoWall from simpler ransomware is its technical sophistication. It operates on both 32-bit and 64-bit systems, deletes shadow copies to prevent file recovery, disables System Restore features, and even installs spyware to steal passwords and Bitcoin wallets. The encryption implementation is effectively unbreakable without the private key held by attackers, making prevention the only viable defense strategy.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

CryptoWall Ransomware Victimology

The targeting strategy appears opportunistic rather than selective. CryptoWall campaigns have affected individuals who accidentally opened malicious email attachments, businesses whose employees fell victim to phishing schemes, and organizations with unpatched software vulnerabilities. Notable incidents included the Australian Broadcasting Corporation, which experienced disrupted television programming due to a CryptoWall infection, and numerous healthcare organizations that faced operational challenges when patient records became encrypted.

Geographic analysis shows that targets have primarily been concentrated in the United States and United Kingdom, though infections occurred globally. The ransomware infected over 625,000 systems within its first six months of widespread distribution, encrypting approximately 5.25 billion files.

How CryptoWall Functions

The attack sequence begins when the malware gains initial access through various infection vectors. Email remains the primary distribution method, with attackers using the Cutwail spam botnet sending massive campaigns that contain malicious attachments or links.

When victims open attachments disguised as PDF files, Word documents, or ZIP archives, they actually execute the dropper, which then contacts compromised websites to download the CryptoWall payload. This multi-stage delivery complicates detection, as the initial file may appear benign to security software while the actual ransomware is fetched dynamically.

Exploit kits represent another major infection vector. Major advertising networks serving sites including Disney, Facebook, and The Guardian were compromised in campaigns that exposed millions of users to potential infections.

Within organizational networks, CryptoWall spreads by encrypting files on network shares accessible to the infected user account. While the malware doesn't include worm-like capabilities for self-propagation between systems, its ability to encrypt files across mapped network drives means a single infected endpoint can potentially encrypt data throughout an entire organization.

Upon execution, the ransomware immediately attempts to establish persistence mechanisms, though later variants operate entirely in memory to avoid disk-based detection.

The malware's first critical action involves contacting command-and-control servers, typically hosted on the Tor network for anonymity. This communication serves multiple purposes: retrieving the public key used for encrypting the symmetric encryption keys, registering the victim with a unique identifier, and receiving configuration parameters that control the encryption process. If network connectivity fails, some variants will wait and retry rather than proceeding, as the C2 communication is essential for the attack's success.

Once connected, CryptoWall initiates its file discovery and encryption routine. The malware creates malicious instances of legitimate Windows processes like explorer.exe and svchost.exe to perform its operations, helping it blend with normal system activity. It systematically enumerates all accessible storage, identifying files with targeted extensions. The encryption process uses AES symmetric encryption for speed, with each file receiving a unique AES key. These symmetric keys are then encrypted with an RSA public key, making recovery impossible without the corresponding private key held by attackers.

Throughout the encryption process, CryptoWall takes defensive actions to prevent recovery. It deletes Volume Shadow Copies using the Windows vssadmin.exe utility with commands like "vssadmin delete shadows /all /quiet" to eliminate backup copies without user notification. The malware modifies registry entries to disable System Restore and may clear Windows Event Logs to remove evidence of its activities. Some variants also attempt to disable or evade antivirus software through various techniques including process injection and rootkit-like behaviors.

Sandbox Analysis of a CryptoWall Sample

ANY.RUN's interactive malware sandbox allows analysts to safely execute and analyze CryptoWall samples, revealing evasion techniques, C2 communications, and encryption behaviors that inform detection rules and defensive strategies.

View a CryptoWall sample analysis

CryptoWall Sandbox analysis CryptoWall Sandbox analysis

The malware is distributed as an LNK file disguised as a legitimate shortcut. When opened, the LNK launches a PowerShell script that executes the core functionality.

The script tracer of the Sandbox shows how at the start, the malware creates a scheduled task to ensure persistence. The parameters are added: daily mode, no additional day intervals or random delays, and an exact start time of 17:00. Additional options are configured so the task runs even on battery power, does not stop when switching to battery, starts as soon as possible, and ignores the computer's sleep mode.

CryptoWall script establishing persistence CryptoWall script establishing persistence

The malicious program also launches Windows Notepad to display the file Project_Workshop_7th_Minutes.txt, created to mask the program's main functionality.

CryptoWall key processes CryptoWall key processes

The encryption process can be divided into several stages. File discovery occurs recursively through user directories, skipping system folders.

Encryption uses the typical combination of symmetric AES for file encryption. The AES key is encrypted with the attackers' public RSA key. This encrypted AES key, along with the initialization vector and the encrypted file contents, is appended to the end of the file.

Encryption code snippet PowerShell commands showing AES key generation and RSA encryption

A ransom note is created as an HTML file with detailed payment instructions and a timer to pressure the victim into acting quickly.

CryptoWall ransom note screenshot CryptoWall ransom message screenshot with countdown timers for payment and file deletion

Overall, CryptoWall is a classic ransomware specimen: a combination of stealthy infection, rapid encryption, and mechanisms to pressure the victim. Regularly back up important files to external media, use up-to-date antivirus software, monitor the Windows Task Scheduler for suspicious entries, disable macros in Office and PDF files, and train users not to open suspicious shortcuts from emails or downloaded files.

How CryptoWall ransomware threatens businesses and organizations

For healthcare organizations, CryptoWall infections can delay patient care, limit access to medical records, and force reliance on paper-based systems. Educational institutions face interrupted classes, lost research data, and administrative challenges. Financial services organizations risk regulatory penalties for data security failures, while manufacturing and logistics companies experience supply chain disruptions when production systems become unavailable.

Customers and partners lose confidence in organizations that suffer ransomware attacks, particularly if sensitive data is potentially compromised. Media coverage of infections can damage brand value and market position. Even organizations that successfully recover from attacks often face long-term trust deficits that affect business relationships and customer retention.

Gathering Threat Intelligence on CryptoWall ransomware

Threat Intelligence Lookup enables security teams to quickly search for information about suspicious files, URLs, domains, and IP addresses potentially associated with CryptoWall.

By querying file hashes or URLs encountered in environments, analysts can immediately determine if they match known CryptoWall samples, view detailed behavioral analysis, and understand the specific capabilities and infrastructure of particular variants.

This rapid intelligence access accelerates incident response and enables proactive blocking of threats before they impact systems.

Start exploring the threat by looking it up by the name:

threatName:"cryptowall".

CryptoWall samples found via TI Lookup Malware samples with CryptoWall detected, found via TI Lookup]

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

CryptoWall demonstrates how cybercriminals can weaponize strong encryption to generate hundreds of millions of dollars while causing widespread organizational disruption. Though newer ransomware families have emerged since CryptoWall's peak activity, the fundamental threat model it established (combining multiple infection vectors, strong encryption, anonymous infrastructure, and cryptocurrency payments) persists across modern ransomware operations.

Modern threat intelligence and analysis tools have evolved significantly in response to threats like CryptoWall. Malware sandboxes, threat intelligence platforms, and security automation enable faster detection, more effective response, and proactive defense strategies that were unavailable during CryptoWall's emergence. Organizations that leverage these capabilities while maintaining security fundamentals position themselves to resist not only CryptoWall variants that may still circulate but also the next generation of ransomware threats.

Start gathering actionable threat intelligence on CryptoWall by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

Salvador Stealer screenshot
Salvador Stealer
salvador
Salvador Stealer is a powerful, information-stealing Android malware designed to silently infiltrate systems, extract sensitive data, and exfiltrate it to cybercriminals. Often sold on underground forums, it is part of the growing ecosystem of “stealers-as-a-service” (SaaS) tools that target individuals and organizations alike.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More
DoubleTrouble screenshot
DoubleTrouble
doubletrouble
DoubleTrouble is a new-generation Android malware designed to quietly infiltrate mobile devices, harvest sensitive data, hijack financial operations, and maintain long-term persistence. Unlike commodity Android trojans, it blends advanced evasion, dual-stage infection, and dynamic payload updates, making it a rising mobile threat for both consumers and organizations.
Read More
MicroStealer screenshot
MicroStealer
microstealer
MicroStealer is a rapidly emerging infostealer first prominently observed in late 2025. It specializes in stealing browser credentials, active session data, screenshots, cryptocurrency wallets, and system information. It spreads quickly with low detection rates thanks to a sophisticated multi-stage delivery chain and exfiltrates data via Discord webhooks and attacker-controlled servers.
Read More
Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More