CryptoWall Virus E-mail from gator3305.hostgator.com | 192.254.250.169

A new variant of CryptoLocker, called CryptoWall, is making the rounds in Canada and the United states. The infected file often originates from an e-mail attachment with a .zip extension and often appears to be a fax, resume, or invoice.

Once clicked on the user may see a pop-up or error message with no apparent negative consequences. However, after several hours or days it will begin encrypting word docs, excel, pdf, database files, and other files on the computer.

Train staff to never ever open .zip files or other attachments that they were not otherwise expecting to receive.

Here is the e-mail header of a recent example

Return-Path: dolph@gator3305.hostgator.com
Received: from gator3305.hostgator.com ([192.254.250.169])
Received: from dolph by gator3305.hostgator.com with local (Exim 4.82)
(envelope-from )
id 1YZVMv-0003Fm-Kj
Subject: Resume Jess West
X-PHP-Script: kingofironshow.com/memory.php for 173.252.210.26
Reply-To:
Mime-Version: 1.0
Content-Type:multipart/mixed;boundary="----------1426997633550E4181C1129"
Message-Id:
Date: Sat, 21 Mar 2015 21:12:01 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator3305.hostgator.com
X-AntiAbuse: Originator/Caller UID/GID - [32386 500] / [47 12]
X-AntiAbuse: Sender Address Domain - gator3305.hostgator.com
X-BWhitelist: no
X-Source-IP:
X-Exim-ID: 1YZVMv-0003Fm-Kj
X-Source: /opt/php52/bin/php-cgi
X-Source-Args: /opt/php52/bin/php-cgi /home4/dolph/public_html/kingofironshow.com/memory.php
X-Source-Dir: rosedolphin.com:/public_html/kingofironshow.com
X-Source-Sender:
X-Source-Auth: dolph
X-Email-Count: 331
X-Source-Cap: ZG9scGg7ZG9scGg7Z2F0b3IzMzA1Lmhvc3RnYXRvci5jb20=

Recent Visitors to this Spammer's Page

Below you will find a list of recent visitors to this page, it will often include people that have been targeted by this particular spammer or scammer or perhaps the criminal himself. We filter (hide) IP addresses of criminal investigators and police organizations that use this database.

Hostname Timestamp
217.155.27.102 10/15/2017 - 23:43
217.182.91.132 10/13/2017 - 04:11
88.78.232.215 09/25/2017 - 22:20
216.244.66.227 09/23/2017 - 07:34
217.182.88.168 09/12/2017 - 05:17
54.92.170.142 08/20/2017 - 09:36
137.82.36.20 08/08/2017 - 15:26
45.25.249.112 06/30/2017 - 15:46
54.146.28.90 06/23/2017 - 08:10
35.158.50.104 06/10/2017 - 06:14
52.58.195.132 05/04/2017 - 11:21
216.244.66.227 04/18/2017 - 17:16
125.227.12.12 03/04/2017 - 21:26
107.173.212.15 02/12/2017 - 18:30
93.177.134.113 02/10/2017 - 06:07
177.5.219.112 02/10/2017 - 06:03
138.201.20.233 10/09/2016 - 18:58
173.208.157.186 10/05/2016 - 14:37
216.244.66.233 09/18/2016 - 20:01
216.244.66.233 09/18/2016 - 20:00
76.29.80.211 07/01/2016 - 00:35
89.163.148.58 06/21/2016 - 03:18
198.23.247.3 06/12/2016 - 06:43
198.23.247.3 06/12/2016 - 06:43
141.105.71.131 06/04/2016 - 16:00
104.168.97.19 05/13/2016 - 21:13
104.168.97.19 05/13/2016 - 21:13
23.94.80.247 05/12/2016 - 23:56
192.40.93.158 05/08/2016 - 00:14
197.232.8.47 04/24/2016 - 02:26
69.30.215.142 04/02/2016 - 14:50
51.255.162.163 03/31/2016 - 14:01
69.81.209.86 03/31/2016 - 12:24
199.21.99.199 03/24/2016 - 17:08
69.30.198.186 03/20/2016 - 10:33
36.84.224.247 03/19/2016 - 10:33
46.5.2.127 03/15/2016 - 11:20
36.84.224.254 03/14/2016 - 00:05
36.84.224.254 03/14/2016 - 00:05
84.62.18.75 02/08/2016 - 05:53
199.21.99.193 02/07/2016 - 20:20
199.21.99.207 02/06/2016 - 16:56
199.21.99.207 02/05/2016 - 23:44
178.63.86.11 02/05/2016 - 16:45
177.245.31.50 02/01/2016 - 05:34
103.38.101.86 02/01/2016 - 05:31
189.199.34.213 01/28/2016 - 06:47
217.122.101.155 01/25/2016 - 14:03
81.192.68.126 01/08/2016 - 12:33
186.27.127.129 01/05/2016 - 02:21
174.98.177.83 12/22/2015 - 06:39
174.98.177.83 12/22/2015 - 06:36
213.87.104.168 12/11/2015 - 03:05
58.120.96.233 12/03/2015 - 05:08
40.83.179.46 11/28/2015 - 14:17
117.186.110.236 11/26/2015 - 11:42
14.218.157.193 11/25/2015 - 04:25
192.3.211.143 11/20/2015 - 00:45
146.162.240.242 11/13/2015 - 08:10
199.19.249.196 11/13/2015 - 08:10
64.233.172.235 11/10/2015 - 02:33
41.47.188.218 11/05/2015 - 11:30
24.134.142.50 11/01/2015 - 14:16
203.82.66.228 11/01/2015 - 02:46
41.214.136.218 10/26/2015 - 09:03
89.163.148.58 10/11/2015 - 06:05
172.82.164.64 10/09/2015 - 11:13
150.70.188.172 09/30/2015 - 23:20
219.109.93.84 09/30/2015 - 23:19
50.244.173.33 09/15/2015 - 07:12
76.120.136.152 09/06/2015 - 14:33
105.157.187.163 08/26/2015 - 17:39
217.73.208.150 07/30/2015 - 20:01
131.203.103.132 07/28/2015 - 20:53
Spamegory: 
E-mail Spammers