-

   rss_rss_hh_new

 - e-mail

 

 -

 LiveInternet.ru:
: 17.03.2011
:
:
: 51

:


Petya

, 28 2017 . 17:19 +
- WannaCry, , 27 80 - Petya. WannaCry. Positive Technologies .



, , , , , , , , Mondelez International, TESA, Nivea, Mars, LifeCell, , . . .

, , , Petya (MBR) . , -, , . MBR 0x22- XOR 0x07.

, 1-2 , bootrec /fixMbr MBR . , , . AES, . RSA . , , . , 15 . , , ( ).

, , $300 ( 27 2017 0,123 ) . - 1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX. , , , .



45.



Petya 135, 139, 445 TCP- ( SMB WMI). : Windows Management Instrumentation (WMI) PsExec, , MS17-010 (EternalBlue). WMI Windows. PsExec Windows . , , , . EternalBlue . Mimikatz Windows, . Petya , WannaCry , .

Positive Technologies EternalBlue ( 44% 2017 ), Mimikatz ( ).

, Petya , , . , .

WannaCry , , , . . , WannaCry_Petya_FastDetect . MaxPatrol Audit, Pentest. . , MaxPatrol SIEM Petya.

Positive Technologies kill-switch . , MBR perfc ( ) C:\Windows\ ( ). , dll ( ).





. , , , MBR .



, . , , MBR.

, , C:\Windows\, , MBR .
, , , , MS Windows. , .

, . wowsmith123456@posteo.net , . , , . , , . , , .

, . . , . , , . . . , SIEM.

Petya :

  • C:\Windows\perf
  • Windows ()
  • "%WINDIR%\system32\shutdown.exe /r /f"

IDS/IPS:

  • msg: "[PT Open] Unimplemented Trans2 Sub-Command code. Possible ETERNALBLUE (WannaCry, Petya) tool"; sid: 10001254; rev: 2;
  • msg: "[PT Open] ETERNALBLUE (WannaCry, Petya) SMB MS Windows RCE"; sid: 10001255; rev: 3;
  • msg: "[PT Open] Trans2 Sub-Command 0x0E. Likely ETERNALBLUE (WannaCry, Petya) tool"; sid: 10001256; rev: 2;
  • msg: "[PT Open] Petya ransomware perfc.dat component"; sid: 10001443; rev: 1
  • msg:"[PT Open] SMB2 Create PSEXESVC.EXE"; sid: 10001444; rev:1

:

Original source: habrahabr.ru (comments, light).

https://habrahabr.ru/post/331858/

:  

: [1] []
 

:
: 

: ( )

:

  URL