JIGSAW arrives as a file downloaded from a free cloud storage service named 1fichier[.]com. This service has previously hosted other malware like the information stealer FAREIT, as well as COINSTEALER, which gathers bitcoins. It can also be downloaded at hxxp://waldorftrust[.]com, where JIGSAW is most probably bundled with a cryptominer software.
Attachments
pw virus
(692.98 KiB) Downloaded 137 times
(692.98 KiB) Downloaded 137 times
pw virus
(1.28 MiB) Downloaded 115 times
(1.28 MiB) Downloaded 115 times
pw virus
(218.59 KiB) Downloaded 146 times
(218.59 KiB) Downloaded 146 times
Last edited by maddog4012 on Tue Apr 19, 2016 5:10 pm, edited 1 time in total.