Petya Ransomware Outbreak
ID: d3f44008-cb25-56f6-8417-5a43b4d63f64
STIX ID: report--d3f44008-cb25-56f6-8417-5a43b4d63f64
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ reports a widespread Petya-like ransomware outbreak delivered via a compromised MeDoc software update that encrypts infected systems' Master Boot Record and demands $300 in Bitcoin; the malware propagates laterally using SMB exploits (EternalBlue/MS17-010) and WMIC, impacting businesses across multiple countries. The report provides technical analysis of two DLL payloads (including a killswitch marker and scheduled reboot for payload activation), IOC hashes, sandbox detection signatures, and recommended mitigations (apply MS17-010/CVE-2017-0199 patches, disable SMBv1/WMIC, block ports 135/139/445).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
