GANDCRAB
April 02, 2019
PLATFORM:
Windows
OVERALL RISK RATING:
REPORTED INFECTION:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
Gandcrab ransomware, discovered near the end of January 2018, operates on a ransomware-as-a-service (RaaS) model. It is the first ransomware that demands payment in DASH cryptocurrency, which is more complicated to trace and uses the .bit top level domain (TLD).
Some Gandcrab campaigns use malvertising and exploits vulnerabilities related to Apache Struts, JBoss, Weblogic and Apache Tomcat.
It is capable of the following:
- File encryption
- Disabling system
- Propagation
- Downloading files
Gandcrab ransomware typically follows the infection chain below: