Cryptowall

First seen
2014-04-01 00:00:00
Malware type
ransomware, trojan
Family
Malware family
Last IoC activity
2026-07-22 00:36:14
Profile updated
2026-07-07 13:44:27

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality education-and-nonprofits government-and-public-sector

Context

CryptoWall is a ransomware, is usually spread by spam and phishing emails, malicious ads, hacked websites, or other malware and uses a Trojan horse to deliver the malicious payload.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Cryptowall_Auto (yara-rule)

Reports & references

  • sites.temple.edu — Ci Rw Attacks (report)
  • ESET — Eset Threat Report Q22020 (report)
  • gdatasoftware.com — 31666 Ransomware Identification For The Judicious Analyst (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cryptowall (report)
  • ryancor.medium.com — Genetic Analysis Of Cryptowall Ransomware 843F86055C7F (report)

External references