: |
28 2017
- Trojan.Encoder.12544 , Microsoft Windows. , Petya (Trojan.Ransom.369), Trojan.Encoder.12544 . , , .
, , WannaCry. Trojan.Encoder.12544 27.06.2017. , IP- 445 139. , , Trojan.Encoder.12544 SMB (MS17-10).
4 , 2 32- 64- Mimikatz, Windows. , , . Mimikatz, Trojan.Encoder.12544 , . , . , , Trojan.Encoder.12544 PsExec ( ) Wmic.exe.
, C:\Windows\. , . perfc.dat, , , C:\Windows\perfc. , C:\Windows\ perfc ( ), . , , .
, . . Trojan.Encoder.12544 VBR (Volume Boot Record, ) C:, . Windows , XOR, . , .3ds, .7z, .accdb, .ai, .asp, .aspx, .avhd, .back, .bak, .c, .cfg, .conf, .cpp, .cs, .ctl, .dbf, .disk, .djvu, .doc, .docx, .dwg, .eml, .fdb, .gz, .h, .hdd, .kdbx, .mail, .mdb, .msg, .nrg, .ora, .ost, .ova, .ovf, .pdf, .php, .pmf, .ppt, .pptx, .pst, .pvi, .py, .pyc, .rar, .rtf, .sln, .sql, .tar, .vbox, .vbs, .vcb, .vdi, .vfd, .vmc, .vmdk, .vmsd, .vmx, .vsdx, .vsv, .work, .xls, .xlsx, .xvd, .zip.
, . AES-128-CBC, ( , ). RSA-2048 ( , 800- ) README.TXT. .
, . , CHDISK.
Trojan.Encoder.12544 MFT (Master File Table). , Trojan.Encoder.12544 .
CHDISK, . , Windows , . Windows 7 , Windows . Windows XP . Dr.Web LiveDisk , , Dr.Web, , .
Trojan.Encoder.12544 , (, , ).
Trojan.Encoder.12544 , Dr.Web Security Space. , . Trojan.Encoder.12544.
http://feedproxy.google.com/~r/drweb/viruses/~3/9-uHXVSeh78/