Petya Ransomware Without The Fluff
ID: c93b38f9-e25b-58f5-98d4-f9cbaf08c427
STIX ID: report--c93b38f9-e25b-58f5-98d4-f9cbaf08c427
Feed Name: Binary Defense Blog
Threat Score
Binary Defense's analysis of the June 2017 NotPetya/Petya outbreak attributes rapid, destructive compromise to a supply‑chain update from Ukrainian accounting software M.E.Doc that deployed a perfc.dat payload and combined EternalBlue worming with credential theft (Mimikatz) and legacy PsExec/WMIC lateral movement; the report includes a SHA256 indicator, targeted file extensions, observed behaviors, and mitigations (block perfc.dat, patch MS17-010, remove admin rights).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
