Bad Rabbit is a Windows ransomware family that emerged in October 2017 and is also tracked as Diskcoder.D. It is a worm-capable ransomware strain with strong code and behavioral similarities to NotPetya, but it is generally assessed as conventional ransomware rather than a pure wiper because it encrypts files and uses a modified boot process to present a ransom demand after disk encryption. The outbreak primarily affected organizations in Ukraine and Russia, with additional victims reported in other countries, including transportation and government entities.
Initial infection was widely associated with compromised websites that presented a fake Adobe Flash Player update, leading victims to manually execute a disguised installer. The malware requires elevated privileges through UAC to proceed. After execution, it drops and launches a malicious DLL component, deploys additional modules, and uses scheduled tasks and service-style startup mechanisms to continue execution and trigger a forced reboot.
Bad Rabbit combines immediate file encryption with post-reboot disk encryption. It abuses the legitimate DiskCryptor driver to encrypt the file system and then displays a ransom message through a modified bootloader. The malware also deletes event logs and the USN journal, searches for security-related processes, and uses multiple Windows API calls as part of execution, discovery, and evasion workflows.
A defining feature of Bad Rabbit is its lateral movement inside local networks. It enumerates DHCP-defined subnets and open SMB shares, checks remote administrative shares, and propagates using a combination of stored Windows credentials, harvested credentials via a Mimikatz-like password-dumping component, and hard-coded credential guesses. Reporting also indicates that some variants or incidents used an SMBv1 exploit within the scope of MS17-010 during propagation, with observed traffic resembling Eternal-family exploitation. This made the malware operationally similar to earlier 2017 worming outbreaks, though its spread was generally characterized as local-network focused rather than internet-scale.
Bad Rabbit also performs process enumeration and hashed process-name comparisons, attempts privilege escalation through UAC bypass-related behavior, and uses named pipes for inter-process communication with credential-dumping components. The family is notable for blending ransomware monetization with destructive and worm-like tradecraft, making it one of the most consequential ransomware outbreaks of 2017.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
10/26になりTalos(Cisco)からEternalRomanceを利用しているという情報が発信されました。... 同一環境に対しMS17-010の更新プログラムを適用した後に再度検証を実施した結果、横展開による感染が行われなくなったことも併せて確認しました。... Bad Rabbit が利用している脆弱性はEternalSynergy をベースとし改変されたExploitである可能性がある... 少なくともMS17-010で修正された範囲の脆弱性が利用されていることに違いはありません。 | Bad Rabbit の横展開に関わるワーム活動において、10/26になりTalos(Cisco)からEternalRomanceを利用しているという情報が発信されました。... 我々の調査においてはEternalSynergyと呼ばれる攻撃の通信と類似することを確認しました。
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI). ... CVE-2017-11882 is a 17-year old memory corruption issue in Microsoft Office ... The flaw resides within Equation Editor (EQNEDT32.EXE) ... A proof-of-concept exploit was released publicly, but this has been fixed by Microsoft’s November Patch Tuesday.
Dillon has crafted his modified exploits to take advantage of the following vulnerabilities: CVE-2017-0143 Type confusion between WriteAndX and Transaction requests EternalRomance EternalSynergy
Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。... 一定時間後に再起動... システム起動時に「dispci.exe」が自動起動されるようになります。
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。 次のタスクにより、感染後一定の時間が経過すると再起動が行われます。
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。... 一定時間後に再起動... システム起動時に「dispci.exe」が自動起動されるようになります。
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。 次のタスクにより、感染後一定の時間が経過すると再起動が行われます。
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。... 一定時間後に再起動... システム起動時に「dispci.exe」が自動起動されるようになります。
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。 次のタスクにより、感染後一定の時間が経過すると再起動が行われます。
NT Trans RequestにおけるNT Trans Secondary Requestの末尾へ、68バイトのSMBデータを繰り返し追記したリクエストを送信することでバッファーオーバーフローさせている様子が伺えます。
リソースセクションの文字列テーブル内には複数のバイナリデータが暗号化された状態で格納されています。... バイナリを隠蔽するために利用されることは基本的にないため、検知回避や解析妨害の目的と考えられます。
以下は「infpub.dat」がDhcpGetSubnetInfo APIおよびDhcpEnumSubnetClients APIを利用し、DHCPサーバで定義されたサブネットの列挙を行う際のコードです。
列挙された範囲のローカルネットワークアドレスを持つ端末への侵入を試みます。... リモート先の別端末における管理共有に...存在するかどうかを確認し、存在しなければ自身のコピーを配置します。
Bad Rabbit の横展開に関わるワーム活動において…Talos(Cisco)からEternalRomanceを利用しているという情報…該当環境においてもネットワークを介しBad Rabbit に感染する状況を確認しました。さらに同一環境に対しMS17-010の更新プログラムを適用した後に再度検証を実施した結果、横展開による感染が行われなくなったことも併せて確認しました。 | 10/26になりTalos(Cisco)からEternalRomanceを利用しているという情報(※1)が発信されました。 | その際の感染端末から送信された通信内容を確認した結果、脆弱性攻撃と思われる通信が確認できた為分析を進めたところ、我々の調査においてはEternalSynergyと呼ばれる攻撃の通信と類似することを確認しました。
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware associated in this detection with the creation or deletion of scheduled tasks via schtasks.exe, using task names such as rhaegal, drogon, and viserion_.
Destructive malware/ransomware that enumerates open SMB shares on internal victim networks.
Enterprise New Software: ... Bad Rabbit
Ransomware executed when users install an executable disguised as a Flash installer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.