Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Jigsaw

87
Global rank
75 infographic chevron month
Month rank
62 infographic chevron week
Week rank

The Jigsaw ransomware, initially detected in 2016, encrypts files on compromised systems and requires a ransom payment in Bitcoin. If the ransom is not paid, the malware starts deleting files, increasing the pressure on victims to comply. Its source code is publicly accessible, allowing various threat actors to customize and repurpose the malware for different objectives.

Ransomware
Type
Unknown
Origin
1 March, 2016
First seen
7 October, 2026
Last seen

How to analyze Jigsaw with ANY.RUN

Type
Unknown
Origin
1 March, 2016
First seen
7 October, 2026
Last seen

IOCs

IP addresses
184.31.95.119
150.171.109.101
48.209.6.48
150.171.22.17
23.194.190.156
2.16.204.160
104.18.22.222
104.21.54.173
23.59.18.102
48.209.133.15
104.16.80.73
172.67.168.195
150.171.27.11
142.251.14.113
150.171.28.11
104.18.23.222
2.16.204.152
48.209.138.168
23.212.193.218
199.232.210.172
Hashes
26dc5ff4bfb9213291735808465e156d4a4691135f3815e3613761243e1f69c3
6081e5ab192226d10d4ccbb32070bd11f65a079467886afb905ee3b9440952e7
4a221530681185d5e32924c875d5fb9a1f486ce5d573041673bfe9e274ba0ffd
ac09d69d59f30a1c40022f0d4be225af5984ed28fe768f97fc3ab28a536cce73
ce9d07500ad91ec2b524c270764ec4c9a33e78320d8d374ec400ede488f6251b
2441a704cfe10a5e64a5e1d2a7e680e6aa6a2da8c5a73e6722530f33ff687049
b0835d74e57b8cbf94c1cb5dac51288e2c34c7d40dae9c0918e95bca9101af08
abde640ac4e20adce91d97c126306b44e98dc3f03c7295e715720c8af6acbbf6
7ae0f33fc402fa2ac974c68fa2c8aa8dee492e3ccc1b6f163b8370ad92d4c601
13db66ed9e841c88f58f0083676f081978ab2984aa1cd76832813ea9a83e2600
347743d6d19425fcebfa995a8fa28ff5d7e0ba3487ce6e2c9c81a6d7e2666d9e
08c4fd72f9d96a7aa554510dff2c293973b1b092dff1b9b282bce9111b50ef41
aa64d386b16b2aec1622503c0003fffeef91b1fdfe6b81231be2e186dfe683f9
ceb3b304acf16c71c4e6a0be8f4937900bd6c621fe8f0fc54b65cc46690e2014
75c1ec54f425e08a7a9a03c9788effe71b235be0e076df7cb556558f2f484cb3
1ddeb99fdae2737ff8fed5b9b4075665f2eee2a44aa158f0840397ad42d21959
3c38e3eabc0880e36bdd5d143b77d2b73792a5787f7ed917a63d7457dfdfc5db
346ea039b0efb5efd0a0ba5e21fef482654e1920c742ce0545e027679ee07793
a32e0a83001d2c5d41649063217923dac167809cab50ec5784078e41c9ec0f0f
ceebae7b8927a3227e5303cf5e0f1f7b34bb542ad7250ac03fbcde36ec2f1508
Domains
config.edge.skype.com
xpaywalletcdn.azureedge.net
irctctourism.com.fun
edge.microsoft.com
update.googleapis.com
www.bing.com
settings-win.data.microsoft.com
fs.microsoft.com
crl.microsoft.com
copilot.microsoft.com
edge-consumer-static.azureedge.net
www.microsoft.com
static.cloudflareinsights.com
google.com
edge-cloud-resource-static.azureedge.net
msedge.b.tlu.dl.delivery.mp.microsoft.com
edge-mobile-static.azureedge.net
ocsp.digicert.com
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:n6xbvj80lsv_tmov1n0h5jqe6yg07f9lthqhzgufxkc&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:rfgxbu-xucht7y2y3n9f9a9jfa8k4jfpqk8fnk1obhu&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
irctctourism.com.fun
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/fef489f0-c0aa-4886-ba2b-137e93d55624?p1=1791364289&p2=404&p3=2&p4=mpnpwu5xhqgqpwkiy%2bzxbxxfpjq6mjetkkupqbmin6vr8n%2buwd7naeubizvetjubikyo%2fefbeumuhdjmwxsucg%3d%3d
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/8f5fc415-8647-4b85-a913-4f863dae87ab?p1=1791958290&p2=404&p3=2&p4=uilorr6autzcfhfod0afxvcp5upxqg%2fzujiez4mumpwkz8szdol2wh1zkifuhipdhsg6qykbcdz9o5o%2bvkmmdw%3d%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/550117a4-8c0f-4d0d-8ff8-7c3caccb0e8a?p1=1791958290&p2=404&p3=2&p4=bljamxkfc%2fouqnw7uruqtt9fjbrvksx9933mun%2b1t2dqo3xb3bh2fokfqjt9b541n%2fwctmzocbeb%2btml4yagdq%3d%3d
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.3.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.2.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.1.crl
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/375ef5f2-c232-4849-a78c-249a2ab12ab0?p1=1791364289&p2=404&p3=2&p4=wny87l2jqaffhvyv5yydka5qbnx9xrckwdppucaglskhcdzqcuz03ksjujxshj9ukxbfnhkcijfxalhku7yyqa%3d%3d
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/8c48c7de-2dbf-4f68-b833-8b44f842754a?p1=1791958290&p2=404&p3=2&p4=b%2fdsfcptz%2b7mrx96ypk%2f%2bkxqtfkwipaydrfngitufy2ahhu0mugnmwonkzhowmmche708hgoaozv62%2bhq%2bx%2fla%3d%3d
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/86061e48-63b3-483f-8dac-609df0cbb238?p1=1791364289&p2=404&p3=2&p4=o6dxtvm%2bl5zp9tcxxnvsk8g8izmrj5ktlppycops1rhmt8bm87mbgkuijv2jrcnca3to94ovew9p8iksa4s1fw%3d%3d
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/03b2d981-4f59-42a6-8f9a-a2b6278a0020?p1=1791958290&p2=404&p3=2&p4=kyeyx60h9ldqfp%2b6tuluzah03e469uj0rw%2b0bjjfhe5sv26oi9xp1%2fl2qfxbnwoc0d%2bgceryiaccdfoshppg3w%3d%3d
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e1447940-5090-4f3b-9c07-17966e50ad9c?p1=1791364289&p2=404&p3=2&p4=i0oozwwhycvqnjyrwlnhwj%2flqwos16kumgvu94qsyeyli29kz6djitf8vmlqr4wqhbthbbc3kjtl3fj849l70a%3d%3d
Last Seen at
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1024
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2815
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10289
comments 0

What is Jigsaw Malware?

Jigsaw ransomware, initially detected in 2016, is a form of malware designed to encrypt files on a victim's system and extort a ransom payment in Bitcoin to restore access.

The creators of Jigsaw incorporate themes and visuals from the horror movie Saw, utilizing threatening messages inspired by the film to pressure victims into complying with the ransom demands.

If the victim does not pay the ransom, Jigsaw begins deleting files from the infected system, increasing the urgency for victims to act. This approach not only encrypts valuable data but also introduces a time-sensitive element that can cause significant distress and data loss.

The original malware is no longer active, as researchers were able to quickly develop decryption tools. However, Jigsaw's source code is openly available, allowing different threat actors to modify and adapt the malware for various purposes, including data theft.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Jigsaw Malware Technical Details

Jigsaw has a range of capabilities which vary across different variants.

  • The original Jigsaw used the AES encryption algorithm to lock files, making them inaccessible without the decryption key.
  • The malware employed over 80 different file extensions for encrypted files, including the .FUN, complicating the identification and recovery process.
  • It displayed ransom notes with instructions for payment, typically demanding Bitcoin in exchange for decryption.
  • Jigsaw verified ransom payments by querying a Bitcoin wallet address via HTTP requests. Upon detecting the required funds, it initiates the decryption process.
  • Despite the development of decryption tools by researchers, Jigsaw continues to evolve, with new variants emerging that incorporate additional malicious functionalities.

    Jigsaw Execution Process

    To analyze any sample of Jigsaw, you can upload it to ANY.RUN’s Interactive Sandbox, a safe cloud environment for examining malicious URLs and files. Check out this analysis of a Jigsaw sample

Jigsaw analysis inside ANY.RUN's Sandbox Analysis of Jigsaw inside ANY.RUN's Interactive Sandbox threat context

The execution process of Jigsaw ransomware involves several critical steps to ensure the encryption of files and the extortion of victims. Upon infecting a system, the malware begins by encrypting the files and displaying a ransom note with payment instructions. The ransom note typically includes a countdown timer, indicating the time remaining before files start being deleted.

Jigsaw results inside ANY.RUN's TI Lookup Process graph showing the execution of a Jigsaw sample

To verify that the ransom has been paid, Jigsaw queries a Bitcoin wallet address via HTTP requests. If the malware detects that the required funds have been deposited, it triggers the decryption process, restoring access to the encrypted files.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Jigsaw Distribution Methods

The distribution methods for Jigsaw ransomware have evolved significantly since its inception. Initially, the malware was spread through fake software executables that mimicked legitimate programs. These executables were designed to trick users into downloading and running the malicious files, leading to infection.

However, newer variants of Jigsaw utilize a broader range of distribution channels. Some of the most common methods include:

  • Phishing Emails: Threat actors send phishing emails with malicious attachments or links that, when opened, download and execute the Jigsaw ransomware.
  • File-Sharing Platforms: Malicious files are hosted on file-sharing platforms, where unsuspecting users may download them, leading to infection.
  • Compromised Websites: Jigsaw may be bundled with other malware as a downloader from compromised websites. Visitors to these sites may unknowingly download and install the ransomware.

Each threat actor may utilize their own channel of distribution, making it challenging to predict and defend against the spread of Jigsaw ransomware.

Collect Threat Intelligence on Jigsaw Ransomware

To gather information about Jigsaw ransomware and collect relevant intelligence, utilize Threat Intelligence Lookup.

This service provides access to a comprehensive database containing insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox. With over 40 search parameters, users can find specific data related to threats, including IP addresses, domains, file names, and process artifacts.

Jigsaw results inside ANY.RUN's TI Lookup TI Lookup helps you enrich your investigations with additional threat context

For example, you can search for Jigsaw by its name or related artifacts. A query like threatName:"Jigsaw" will retrieve all associated samples and sandbox results relevant to this ransomware. This tool is invaluable for staying informed about the latest variants and indicators of Jigsaw, helping security professionals to better understand and mitigate the threat.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Although the Jigsaw ransomware no longer presents a significant threat in the cybersecurity landscape, as it did in 2016, access to its source code makes it a potential security risk to organizations. To prevent possible infections with Jigsaw, it is important to implement comprehensive security measures, including proactive sandbox analysis.

Use ANY.RUN’s Interactive Sandbox to quickly examine suspicious files and URLs to identify threats early and address them before they have a chance to compromise your infrastructure.

Sign up for a free ANY.RUN account to access unlimited analysis!

HAVE A LOOK AT

MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More
Cactus Ransomware screenshot
Cactus ransomware-as-a-service (RaaS) was first caught in March 2023 targeting corporate networks. It became known for its self-encrypting payload and double extortion tactics. Cactus primarily targets large enterprises across industries in finance, manufacturing, IT, and healthcare. It is known for using custom encryption techniques, remote access tools, and penetration testing frameworks to maximize damage.
Read More
Moonrise screenshot
Moonrise
moonrise
Moonrise RAT is a newly discovered Go-based remote access trojan with zero detections at launch, featuring credential theft, keylogging, webcam access, clipboard hijacking, and UAC bypass.
Read More
CryptoWall screenshot
CryptoWall
cryptowall
CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.
Read More
NetSupport RAT screenshot
NetSupport RAT
netsupport
NetSupport RAT is a malicious adaptation of the legitimate NetSupport Manager, a remote access tool used for IT support, which cybercriminals exploit to gain unauthorized control over systems. It has gained significant traction due to its sophisticated evasion techniques, widespread distribution campaigns, and the challenge it poses to security professionals who must distinguish between legitimate and malicious uses of the underlying software.
Read More