- WannaCry, , 27 80 - Petya. WannaCry. Positive Technologies .
, , , , , , , , Mondelez International, TESA, Nivea, Mars, LifeCell, , . . .
, , , Petya (MBR) . , -, , . MBR 0x22- XOR 0x07.
, 1-2 ,
bootrec /fixMbr MBR . , , . AES, . RSA . , , . , 15 . , , ( ).
, , $300 ( 27 2017 0,123 ) . -
1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX. , , , .
45.
Petya 135, 139, 445 TCP- ( SMB WMI). : Windows Management Instrumentation (WMI)
PsExec, ,
MS17-010 (
EternalBlue). WMI Windows. PsExec Windows . , , , . EternalBlue .
Mimikatz Windows, .
Petya , WannaCry , .
Positive Technologies EternalBlue ( 44% 2017 ), Mimikatz ( ).
, Petya , , . , .
WannaCry , , , . . ,
WannaCry_Petya_FastDetect . MaxPatrol Audit, Pentest.
. , MaxPatrol SIEM
Petya.
Positive Technologies
kill-switch . , MBR
perfc (
)
C:\Windows\ ( ). , dll ( ).
. , , , MBR .
, . , , MBR.
, , C:\Windows\, , MBR .
, , , , MS Windows. , .
,
.
wowsmith123456@posteo.net , . , , . , , . , , .
, . . , . , , . . . , SIEM.
Petya :
- C:\Windows\perf
- Windows ()
- "%WINDIR%\system32\shutdown.exe /r /f"
IDS/IPS:
- msg: "[PT Open] Unimplemented Trans2 Sub-Command code. Possible ETERNALBLUE (WannaCry, Petya) tool"; sid: 10001254; rev: 2;
- msg: "[PT Open] ETERNALBLUE (WannaCry, Petya) SMB MS Windows RCE"; sid: 10001255; rev: 3;
- msg: "[PT Open] Trans2 Sub-Command 0x0E. Likely ETERNALBLUE (WannaCry, Petya) tool"; sid: 10001256; rev: 2;
- msg: "[PT Open] Petya ransomware perfc.dat component"; sid: 10001443; rev: 1
- msg:"[PT Open] SMB2 Create PSEXESVC.EXE"; sid: 10001444; rev:1
:
https://habrahabr.ru/post/331858/