-

   rss_drweb_viruses

 - e-mail

 

 -

 LiveInternet.ru:
: 30.09.2009
: 711
: 1
: 1

:


:

, 28 2017 . 23:34 +

28 2017

" " - Trojan.Encoder.12544, Petya, Petya.A, ExPetya WannaCry-2. " " , , , , , .

- Trojan.Encoder.12544 , Microsoft Windows. , Petya (Trojan.Ransom.369), Trojan.Encoder.12544 . , , .

, , WannaCry. Trojan.Encoder.12544 27.06.2017. , IP- 445 139. , , Trojan.Encoder.12544 SMB (MS17-10).

4 , 2 32- 64- Mimikatz, Windows. , , . Mimikatz, Trojan.Encoder.12544 , . , . , , Trojan.Encoder.12544 PsExec ( ) Wmic.exe.

, C:\Windows\. , . perfc.dat, , , C:\Windows\perfc. , C:\Windows\ perfc ( ), . , , .

, . . Trojan.Encoder.12544 VBR (Volume Boot Record, ) C:, . Windows , XOR, . , .3ds, .7z, .accdb, .ai, .asp, .aspx, .avhd, .back, .bak, .c, .cfg, .conf, .cpp, .cs, .ctl, .dbf, .disk, .djvu, .doc, .docx, .dwg, .eml, .fdb, .gz, .h, .hdd, .kdbx, .mail, .mdb, .msg, .nrg, .ora, .ost, .ova, .ovf, .pdf, .php, .pmf, .ppt, .pptx, .pst, .pvi, .py, .pyc, .rar, .rtf, .sln, .sql, .tar, .vbox, .vbs, .vcb, .vdi, .vfd, .vmc, .vmdk, .vmsd, .vmx, .vsdx, .vsv, .work, .xls, .xlsx, .xvd, .zip.

, . AES-128-CBC, ( , ). RSA-2048 ( , 800- ) README.TXT. .

, . , CHDISK.

screenshot Trojan.Encoder.12544 #drweb

Trojan.Encoder.12544 MFT (Master File Table). , Trojan.Encoder.12544 .

screenshot Trojan.Encoder.12544 #drweb

CHDISK, . , Windows , . Windows 7 , Windows . Windows XP . Dr.Web LiveDisk , , Dr.Web, , .

Trojan.Encoder.12544 , (, , ).

Trojan.Encoder.12544 , Dr.Web Security Space. , . Trojan.Encoder.12544.

Trojan.Encoder.12544

http://feedproxy.google.com/~r/drweb/viruses/~3/9-uHXVSeh78/


: [1] []
 

:
: 

: ( )

:

  URL