logo

Petya Ransomware Without The Fluff

ID: c93b38f9-e25b-58f5-98d4-f9cbaf08c427

STIX ID: report--c93b38f9-e25b-58f5-98d4-f9cbaf08c427

Feed Name: Binary Defense Blog

Threat Score
90/100

Date Published: 2025-09-10

Date Updated: 2026-04-27

...
...

Binary Defense's analysis of the June 2017 NotPetya/Petya outbreak attributes rapid, destructive compromise to a supply‑chain update from Ukrainian accounting software M.E.Doc that deployed a perfc.dat payload and combined EternalBlue worming with credential theft (Mimikatz) and legacy PsExec/WMIC lateral movement; the report includes a SHA256 indicator, targeted file extensions, observed behaviors, and mitigations (block perfc.dat, patch MS17-010, remove admin rights).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.