JIGSAW arrives as a file downloaded from a free cloud storage service named 1fichier[.]com. This service has previously hosted other malware like the information stealer FAREIT, as well as COINSTEALER, which gathers bitcoins. It can also be downloaded at hxxp://waldorftrust[.]com, where JIGSAW is most probably bundled with a cryptominer software.
Attachments
pw virus
(692.98 KiB) Downloaded 136 times
(692.98 KiB) Downloaded 136 times
pw virus
(1.28 MiB) Downloaded 114 times
(1.28 MiB) Downloaded 114 times
pw virus
(218.59 KiB) Downloaded 145 times
(218.59 KiB) Downloaded 145 times
Last edited by maddog4012 on Tue Apr 19, 2016 5:10 pm, edited 1 time in total.