FAQ about PETYA/GOLDENEYE/PETR outbreak
ID: 927db743-f680-5741-bbc6-d8f6de042360
STIX ID: report--927db743-f680-5741-bbc6-d8f6de042360
Feed Name: Fox-IT blog
**Executive summary:** This FAQ describes the Petya ransomware outbreak that began with a malicious update to Ukrainian accounting software M.E.Doc and spread laterally using leaked NSA exploits (EternalBlue/EternalRomance), credential harvesting and reuse, and legitimate admin tools (PsExec, WMI), resulting in file- and disk-level encryption that renders systems inoperable; it provides detection and mitigation guidance (MS17-010/KB2871997 patches, network port scans, credential inventory), notes a local "antidote" (placing the perfc/perfc.dat file), and warns that ransom payments are ineffective because the payment email was blocked.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
