CryptoWall Virus E-mail from gator3305.hostgator.com | 192.254.250.169

A new variant of CryptoLocker, called CryptoWall, is making the rounds in Canada and the United states. The infected file often originates from an e-mail attachment with a .zip extension and often appears to be a fax, resume, or invoice.

Once clicked on the user may see a pop-up or error message with no apparent negative consequences. However, after several hours or days it will begin encrypting word docs, excel, pdf, database files, and other files on the computer.

Train staff to never ever open .zip files or other attachments that they were not otherwise expecting to receive.

Here is the e-mail header of a recent example

Return-Path: dolph@gator3305.hostgator.com
Received: from gator3305.hostgator.com ([192.254.250.169])
Received: from dolph by gator3305.hostgator.com with local (Exim 4.82)
(envelope-from )
id 1YZVMv-0003Fm-Kj
Subject: Resume Jess West
X-PHP-Script: kingofironshow.com/memory.php for 173.252.210.26
Reply-To:
Mime-Version: 1.0
Content-Type:multipart/mixed;boundary="----------1426997633550E4181C1129"
Message-Id:
Date: Sat, 21 Mar 2015 21:12:01 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator3305.hostgator.com
X-AntiAbuse: Originator/Caller UID/GID - [32386 500] / [47 12]
X-AntiAbuse: Sender Address Domain - gator3305.hostgator.com
X-BWhitelist: no
X-Source-IP:
X-Exim-ID: 1YZVMv-0003Fm-Kj
X-Source: /opt/php52/bin/php-cgi
X-Source-Args: /opt/php52/bin/php-cgi /home4/dolph/public_html/kingofironshow.com/memory.php
X-Source-Dir: rosedolphin.com:/public_html/kingofironshow.com
X-Source-Sender:
X-Source-Auth: dolph
X-Email-Count: 331
X-Source-Cap: ZG9scGg7ZG9scGg7Z2F0b3IzMzA1Lmhvc3RnYXRvci5jb20=

Recent Visitors to this Spammer's Page

Below you will find a list of recent visitors to this page, it will often include people that have been targeted by this particular spammer or scammer or perhaps the criminal himself. We filter (hide) IP addresses of criminal investigators and police organizations that use this database.

Hostname Timestamp
216.244.66.244 10/17/2018 - 21:16
94.130.10.89 09/03/2018 - 09:38
54.196.31.117 07/22/2018 - 04:16
18.184.207.239 07/19/2018 - 15:49
216.244.66.244 07/17/2018 - 20:13
54.236.16.87 06/21/2018 - 10:09
54.173.35.129 06/03/2018 - 06:00
54.38.252.149 05/31/2018 - 16:24
54.37.85.105 05/27/2018 - 10:57
54.156.76.187 05/25/2018 - 16:42
216.244.66.227 04/01/2018 - 07:53
174.139.205.218 03/25/2018 - 23:35
54.81.27.58 03/21/2018 - 04:43
159.203.127.111 02/19/2018 - 12:29
54.234.45.10 01/17/2018 - 11:48
54.163.39.19 01/13/2018 - 23:51
Spamegory: 
E-mail Spammers