The CryptoWall family has grown! The new member CryptoWall 4.0 with new features!
The fourth member of the CryptoWall ransomware family, CryptoWall 4.0, has just made its debut, refreshed, with a new look and accompanied by new features !
We reported in a recent article that CryptoWall 3.0 is causing damage to both businesses and individuals, totaling over $325 million annually. CryptoWall was first detected in April 2014. In its first massive upgrade, it was called CryptoWall 2.0, which first appeared in October 2014. Then, CryptoWall 3.0, first appeared in January 2015 and 'terrorized' businesses and organizations around the world. Now, in November 2015, CryptoWall 4.0 appears.
New features
New features such as encryption of the names and extensions of affected files have been introduced in the fourth member of the CryptoWall family. In addition, CryptoWall 4.0 has changed the name of the ransom notes to HELP_YOUR_FILES.TXT and HELP_YOUR_FILES.HTML.
The ransom note explains the ransom payment process and 'teases' the infected user.
Distribution Method
The initial sample reported was shared by an infected user on the Bleeping Computer forums, and was spread via email via phishing emails containing attached ZIP files purporting to be resumes. The file inside the ZIP archive is a JavaScript file, which is obfuscated and beautifully crafted to convince users to download the CryptoWall 4.0 payload from a hard-coded URL.

Nevertheless, it is likely that exploit kits will start delivering CW4 as a payload very soon, if they aren't already (especially the Angler EK) .
Technical Information
The C&C communication and behavioral activity of the CryptoWall 4.0 payload is more or less the same as that of previous versions. In the specific sample analyzed below, the actions are shown:
Contacted Domains
Added Files
Deleted Files
Modified Files
Added Registry Keys








