NotPetya pulls BadRabbit out of the hat
ID: 150ed20d-a8ee-5246-91b7-c3c67e358bd3
STIX ID: report--150ed20d-a8ee-5246-91b7-c3c67e358bd3
Feed Name: Group-IB Blog
This report analyzes the October 2017 BadRabbit ransomware campaign that propagated via drive-by downloads from compromised news and other websites in Ukraine, Russia and elsewhere. The malware drops infpub.dat, installs a disk driver and MBR encryptor, uses Mimikatz to harvest credentials, generates a unique AES/RSA-based key per machine and unique Bitcoin wallets, deletes logs, and schedules shutdown tasks; the report links code similarities to NotPetya, lists IOCs (domains, SHA256/MD5 hashes, compilation dates) and discusses likely attribution and infrastructure details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
