Liveblog: Huge Petya ransomware wave
ID: a5576d42-4852-55a8-b09c-1dbdb140dca4
STIX ID: report--a5576d42-4852-55a8-b09c-1dbdb140dca4
Feed Name: Fox-IT blog
Threat Score
A June 27, 2017 intelligence report describes a new Petya ransomware variant that spread from Ukraine—likely via compromised Me-Doc auto-update servers—encrypting disks, rebooting victims to a ransom screen, and propagating across internal networks using EternalBlue and tools like PSEXEC/WMI; the report details infection behavior, mitigation steps (patch MS17-010, disable SMBv1, limit admin accounts, backups) and includes a Snort detection rule.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
