{
	"id": "6f55037c-b95d-4805-a0d3-cf381e1390bc",
	"created_at": "2026-04-06T00:15:45.408581Z",
	"updated_at": "2026-04-10T13:12:40.924471Z",
	"deleted_at": null,
	"sha1_hash": "f93b20d4ae6a1698ff89e1b9756156a454e2f926",
	"title": "New crypto ransomware in town : CryptoFortress",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 55115,
	"plain_text": "New crypto ransomware in town : CryptoFortress\r\nArchived: 2026-04-05 23:16:59 UTC\r\n2015-03-04 - Landscape\r\nBlitz post.\r\n[This post has been heavily edited to  fix my mistake.\r\n]\r\nI was hunting for Gootkit (pushed in a Nuclear Pack instance in France those days) but instead I got a\r\nTeerac.A  new crypto ransomware.\r\nhttp://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html\r\nPage 1 of 6\n\nNuclear Pack pushing CryptoFortress via CVE-2013-2551 - FR - 2015-03-04\r\n(have no sure explanation for the 444 error on the \"undefined\" and CVE-2015-0311 call in that pass).\r\nI thought i was facing Teerac.A (aka TorrentLocker) which was showing that design :\r\nhttp://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html\r\nPage 2 of 6\n\nClicking on the \"Buy Decryption software\" :\r\nhttp://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html\r\nPage 3 of 6\n\nThe sample I got today is showing a close identity :  CryptoFortress\r\nhttp://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html\r\nPage 4 of 6\n\nClicking on the \"Buy decryption software\"\r\nhttp://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html\r\nPage 5 of 6\n\nSamples :  Torrent Locker and a fresh CryptoFortress\r\n26f13c4ad8c1ccf81e80a556cf6db0af - 2014-10-25\r\ne6dda3e06fd32fc3670d13098f3e22c9 - 2015-03-04\r\nRead more :\r\n(PDF) TorrentLocker - Ransomware in a country near you - 2014-12 - Marc-Etienne M.Léveillé - Eset\r\nPost Publication Reading :\r\nCryptoFortress - 2015-03-06 - Renaud Tabary - CertLexsi\r\nSource: http://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html\r\nhttp://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html\r\nPage 6 of 6\n\n  http://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html  \nThe sample I got today is showing a close identity : CryptoFortress \n   Page 4 of 6",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"Malpedia"
	],
	"origins": [
		"web"
	],
	"references": [
		"http://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html"
	],
	"report_names": [
		"cryptofortress-teeraca-aka.html"
	],
	"threat_actors": [],
	"ts_created_at": 1775434545,
	"ts_updated_at": 1775826760,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/f93b20d4ae6a1698ff89e1b9756156a454e2f926.pdf",
		"text": "https://archive.orkl.eu/f93b20d4ae6a1698ff89e1b9756156a454e2f926.txt",
		"img": "https://archive.orkl.eu/f93b20d4ae6a1698ff89e1b9756156a454e2f926.jpg"
	}
}