Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Jigsaw

85
Global rank
112 infographic chevron month
Month rank
110 infographic chevron week
Week rank
0
IOCs

The Jigsaw ransomware, initially detected in 2016, encrypts files on compromised systems and requires a ransom payment in Bitcoin. If the ransom is not paid, the malware starts deleting files, increasing the pressure on victims to comply. Its source code is publicly accessible, allowing various threat actors to customize and repurpose the malware for different objectives.

Ransomware
Type
Unknown
Origin
1 March, 2016
First seen
26 August, 2026
Last seen

How to analyze Jigsaw with ANY.RUN

Type
Unknown
Origin
1 March, 2016
First seen
26 August, 2026
Last seen

IOCs

IP addresses
103.54.153.49
63.40.139.116
202.95.11.181
185.199.110.133
204.242.111.216
140.82.121.4
76.181.127.0
64.89.163.22
88.178.85.213
62.50.124.173
73.178.125.121
178.198.226.213
196.251.107.186
172.245.95.62
85.137.245.141
161.171.54.201
187.208.110.213
157.173.29.19
85.186.8.75
122.42.218.141
Hashes
92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50
d3acd72f585872f36d7329faf6146dc2d71c3cbcbd58d94e36da285738adaa68
e728f79439e07df1afbcf03e8788fa0b8b08cf459db31fc8568bc511bf799537
7f0121322785c107bfdfe343e49f06c604c719baff849d07b6e099675d173961
aac73b3148f6d1d7111dbca32099f68d26c644c6813ae1e4f05f6579aa2663fe
5822c2222c4a4121a1667c7d483ff8b91e489a4c5e881c75a4354712bfe6f435
26b4699a7b9eeb16e76305d843d4ab05e94d43f3201436927e13b3ebafa90739
15ffbb8d382cd2ff7b0bd4c87a7c0bffd1541c2fe86865af445123bc0b770d13
14dec7d1c20fc426ad5463d1b658f87a22f7e576ba4a08905caf399551813a72
2d79af8e1ff3465703e1dc73d3ef2182fd269ea2609c8afabdf1b80693405c1d
d30d7676a3b4c91b77d403f81748ebf6b8824749db5f860e114a8a204bca5b8f
96425ae53a5517b9f47e30f6b41fdc883831039e1faba02fe28b2d5f3efcdc29
4ae7d63ec497143c2acde1ba79f1d9eed80086a420b6f0a07b1e2917da0a6c74
b5fc4fd50e4ba69f0c8c8e5c402813c107c605cab659960ac31b3c8356c4e0ec
db0c7e3029fb2a048e7a3e74c9cbf3e8bcec06288b5eafac5aae678d8663bffc
3e59379f585ebf0becb6b4e06d0fbbf806de28a4bb256e837b4555f1b4245571
fc103a323d70caaac475ae1cfcacfd8eec4c6b1e130005c4793f2013b4b019f8
031ed0378f819926d7b5b2c6c9367a0fb1cbae40e1a3959e2652fe30a47d52f2
27f13c4829994b214bb1a26eef474da67c521fd429536cb8421ba2f7c3e02b5f
45791627ae8e67e6b616117cf21f04da381722faf08d07c0c25e0f28c9b8f82b
Domains
fkoqonr2vgbsw7qu.public.blob.vercel-storage.com
dl.natgo.cn
www.benshamcentre.co.uk
1h.vuregyy1.ru
tmcksa.com
cat.dashabi.in
c3436037.salamanderprocessing.pages.dev
vizyonuniversitesi.com.tr
hnjgdl.geps.glodon.com
palharesinformatica.com.br
www.astenterprises.com.pk
imagefiles-backup.oss-ap-southeast-7.aliyuncs.com
practisingcertificateprotection.com
konsor.ru
dcwblida.dz
www.hwgeneralins.com
www.saf-oil.ru
99194034-96-20180108171507.webstarterz.com
www.microsoft.com
local-update.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://45.13.186.37/crypt/21-32/qw1.exe
http://196.251.107.186/clpr11.exe
http://196.251.107.186/asemkiic.exe
http://193.104.58.65/binyu.exe
http://91.92.242.236/files-129312398/files/file_b41995cf38e90365.exe
http://91.92.242.236/files-129312398/files/file_6bbb893ae4adfb7c.exe
http://217.60.195.219/boss/boss.bat
http://196.251.107.186/clpmem.exe
http://85.203.4.64/notepad.exe
http://193.221.200.26:5001/odens.exe
http://217.60.195.219/ty/s.bat
http://85.203.4.64/client.exe
http://91.92.242.236/files-129312398/files/file_a91ac6d4a7389993.exe
http://91.92.242.236/files-129312398/files/file_21aeb275da3bb00b.exe
http://91.92.242.236/files-129312398/files/file_44ef7cc8421220d0.exe
http://196.251.107.186/uniform_4.44_install.exe
http://196.251.107.186/clp4.exe
http://196.251.107.186/2.7.exe
http://178.16.54.109/getit.exe
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2227
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6651
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10099
comments 0

What is Jigsaw Malware?

Jigsaw ransomware, initially detected in 2016, is a form of malware designed to encrypt files on a victim's system and extort a ransom payment in Bitcoin to restore access.

The creators of Jigsaw incorporate themes and visuals from the horror movie Saw, utilizing threatening messages inspired by the film to pressure victims into complying with the ransom demands.

If the victim does not pay the ransom, Jigsaw begins deleting files from the infected system, increasing the urgency for victims to act. This approach not only encrypts valuable data but also introduces a time-sensitive element that can cause significant distress and data loss.

The original malware is no longer active, as researchers were able to quickly develop decryption tools. However, Jigsaw's source code is openly available, allowing different threat actors to modify and adapt the malware for various purposes, including data theft.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Jigsaw Malware Technical Details

Jigsaw has a range of capabilities which vary across different variants.

  • The original Jigsaw used the AES encryption algorithm to lock files, making them inaccessible without the decryption key.
  • The malware employed over 80 different file extensions for encrypted files, including the .FUN, complicating the identification and recovery process.
  • It displayed ransom notes with instructions for payment, typically demanding Bitcoin in exchange for decryption.
  • Jigsaw verified ransom payments by querying a Bitcoin wallet address via HTTP requests. Upon detecting the required funds, it initiates the decryption process.
  • Despite the development of decryption tools by researchers, Jigsaw continues to evolve, with new variants emerging that incorporate additional malicious functionalities.

    Jigsaw Execution Process

    To analyze any sample of Jigsaw, you can upload it to ANY.RUN’s Interactive Sandbox, a safe cloud environment for examining malicious URLs and files. Check out this analysis of a Jigsaw sample

Jigsaw analysis inside ANY.RUN's Sandbox Analysis of Jigsaw inside ANY.RUN's Interactive Sandbox threat context

The execution process of Jigsaw ransomware involves several critical steps to ensure the encryption of files and the extortion of victims. Upon infecting a system, the malware begins by encrypting the files and displaying a ransom note with payment instructions. The ransom note typically includes a countdown timer, indicating the time remaining before files start being deleted.

Jigsaw results inside ANY.RUN's TI Lookup Process graph showing the execution of a Jigsaw sample

To verify that the ransom has been paid, Jigsaw queries a Bitcoin wallet address via HTTP requests. If the malware detects that the required funds have been deposited, it triggers the decryption process, restoring access to the encrypted files.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Jigsaw Distribution Methods

The distribution methods for Jigsaw ransomware have evolved significantly since its inception. Initially, the malware was spread through fake software executables that mimicked legitimate programs. These executables were designed to trick users into downloading and running the malicious files, leading to infection.

However, newer variants of Jigsaw utilize a broader range of distribution channels. Some of the most common methods include:

  • Phishing Emails: Threat actors send phishing emails with malicious attachments or links that, when opened, download and execute the Jigsaw ransomware.
  • File-Sharing Platforms: Malicious files are hosted on file-sharing platforms, where unsuspecting users may download them, leading to infection.
  • Compromised Websites: Jigsaw may be bundled with other malware as a downloader from compromised websites. Visitors to these sites may unknowingly download and install the ransomware.

Each threat actor may utilize their own channel of distribution, making it challenging to predict and defend against the spread of Jigsaw ransomware.

Collect Threat Intelligence on Jigsaw Ransomware

To gather information about Jigsaw ransomware and collect relevant intelligence, utilize Threat Intelligence Lookup.

This service provides access to a comprehensive database containing insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox. With over 40 search parameters, users can find specific data related to threats, including IP addresses, domains, file names, and process artifacts.

Jigsaw results inside ANY.RUN's TI Lookup TI Lookup helps you enrich your investigations with additional threat context

For example, you can search for Jigsaw by its name or related artifacts. A query like threatName:"Jigsaw" will retrieve all associated samples and sandbox results relevant to this ransomware. This tool is invaluable for staying informed about the latest variants and indicators of Jigsaw, helping security professionals to better understand and mitigate the threat.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Although the Jigsaw ransomware no longer presents a significant threat in the cybersecurity landscape, as it did in 2016, access to its source code makes it a potential security risk to organizations. To prevent possible infections with Jigsaw, it is important to implement comprehensive security measures, including proactive sandbox analysis.

Use ANY.RUN’s Interactive Sandbox to quickly examine suspicious files and URLs to identify threats early and address them before they have a chance to compromise your infrastructure.

Sign up for a free ANY.RUN account to access unlimited analysis!

HAVE A LOOK AT

Loader screenshot
Loader
loader downloader
A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
Balada Injector screenshot
Balada Injector is a long-running malware campaign that targets WordPress websites by exploiting vulnerabilities in plugins and themes. The attackers inject malicious code into compromised sites, leading to unauthorized redirects, data theft, and the creation of [backdoors](https://any.run/malware-trends/backdoor) for persistent access. The campaign operates in waves, with spikes in activity observed every few weeks, continually adapting to exploit newly discovered vulnerabilities.
Read More
 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
RedLine screenshot
RedLine
redline stealer redline stealer malware
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Read More
GREENBLOOD screenshot
GREENBLOOD
greenblood
GREENBLOOD is a Go-based ransomware that uses concurrent ChaCha8 encryption to lock entire Windows environments in under a minute while systematically destroying backups, disabling defenses, and threatening double extortion through a Tor-based data leak site.
Read More