A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #28347  by maddog4012
 Tue Apr 19, 2016 2:41 pm
JIGSAW arrives as a file downloaded from a free cloud storage service named 1fichier[.]com. This service has previously hosted other malware like the information stealer FAREIT, as well as COINSTEALER, which gathers bitcoins. It can also be downloaded at hxxp://waldorftrust[.]com, where JIGSAW is most probably bundled with a cryptominer software.
Attachments
pw virus
(692.98 KiB) Downloaded 137 times
pw virus
(1.28 MiB) Downloaded 115 times
pw virus
(218.59 KiB) Downloaded 146 times
Last edited by maddog4012 on Tue Apr 19, 2016 5:10 pm, edited 1 time in total.
 #28377  by yoto
 Sat Apr 23, 2016 3:15 pm
Thanks! The E variant doesn't work, however.
 #28653  by maddog4012
 Thu Jun 09, 2016 9:15 pm
JIGSAW Crypto-Ransomware Turns Customer-Centric, Uses Chat for Ransom Attempts

The attackers actually have people standing by to answer questions. To see how far they’d go, we posed as New York-based employee whose office PC had been hit by JIGSAW–our responses are on the left, the cybercriminal on the right. Both responses are unedited.


How can I help you

can you really decrypt my files?

yes
its automatic
on payment is received all you have to do is click that you made payment
and the system will verify instantly

why are you guys doing this to us?

I am here to help you get your files back.
Let me know if you need any other instructions or help

im doomed!
my boss gonna fired me

all you have to do is pay $150. New york has Bitcoin atms
or you can visit http://www.localbitcoins.com

thats too much for me

sorry. depending on the amount of files encrypted it doubles to $300 after 24 hours and $450 after 72
it doesnt happen to all computers it depends on the file size encryption

is there a way to lower na payment?

We can do $125
that the minimum
and that is within 24 hours

let me see if i can work this with my boss

just send a message if we are not online we will come back online within 10 minutes
And we do decrypt all you files
100%
you have to message me when you make the payment so I can accept the $125 into the system if not it will tell you you haven’t payed enough. Each wallet is unique to the computer so I can verify instantly
Attachments
PW virus
(424.54 KiB) Downloaded 120 times
 #28704  by xors
 Sat Jun 18, 2016 11:55 am
One more found
Attachments
(436.43 KiB) Downloaded 105 times