Petya is a Windows disk-encrypting ransomware family first observed in March 2016. It was commonly delivered through German-language job-application phishing lures that directed victims to a malicious download. With administrative privileges, Petya overwrites early disk boot sectors with a custom bootloader and forces a reboot. Before Windows loads, the bootloader presents a fake disk-check screen and encrypts the NTFS Master File Table, rendering files inaccessible while generally leaving their underlying contents on disk. It subsequently displays a ransom screen, including its characteristic skull imagery. Petya’s privilege requirement led its operators to deploy Mischa, a conventional user-mode file-encrypting ransomware, as a fallback payload; the two were later combined in the GoldenEye campaign. Petya is distinct from the destructive 2017 NotPetya outbreak, despite substantial bootloader and MBR-related similarities that initially caused widespread naming confusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The ransomware appears to leverage multiple propagation mechanisms, including the ETERNALBLUE exploit that was previously used by the WannaCry ransomware worm... Based on an analysis in our labs, we have confirmed that the ETERNALBLUE exploit is one of the propagation vectors... Deployment of the MS17-010 patches is extremely important. The Microsoft SMB vulnerability is the primary means of spread. | The eSentire Threat Intelligence team is continuing to analyze Petya samples to gain further understanding of its behavior. Based on an analysis in our labs, we have confirmed that the ETERNALBLUE exploit is one of the propagation vectors.
The ransomware can also perform lateral movement by using two exploits that came with the ShadowBrokers dump in April, called ETERNALBLUE and ETERNALROMANCE. These tools exploit vulnerabilities in SMBv1 (CVE-2017-0144 and CVE-2017-0145). | Petya is a ransomware family, with several capabilities similar to the ransomware that started spreading yesterday (27.06.17). Kaspersky claims that yesterday’s variant is not based on Petya, naming it NotPetya instead. Others claim that this is a combination of several ransomwares, calling it GoldenEye.
There have been reports of malicious Word documents using the CVE-2017-0199 vulnerability being used as the initial infection vector for this ransomware attack. We have not confirmed these reports as yet. | The eSentire Threat Intelligence team is continuing to analyze Petya samples to gain further understanding of its behavior. Based on an analysis in our labs, we have confirmed that the ETERNALBLUE exploit is one of the propagation vectors.
6.CVE-2017-0144, CVE-2017-0145, CVE-2017-0143 Description: Windows SMBv1 Remote Code Execution Vulnerability WannaCry, Petya
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
hackers used a self-developed modification of Petya ransomware named PetrWrap.
This is a follow-up from our previous diary about today's ransomware attacks using the new Petya variant... Petya is a ransomware family that works by modifying the infected Windows system's Master Boot Record (MBR).
While the world is holding its breath, wondering where notorious cybercriminal groups like Lazarus or Telebots will strike next with another destructive malware such as WannaCryptor or Petya...
When Petya spread for the first time in March 2016... After a reboot the Master File Tabel (MFT) is encrypted... The evident similarity to Petya caused many researchers to name the new threat "Petya", too. But first doubts emerged soon, which are reflected in names like NotPetya, Nyetya, or Petna.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
If Petya finds valid credentials, it will use either PsExec or WMIC to infect other computers connected to the LAN... Lateral movements (remote WMI): "process call create \"C:\\Windows\\System32\\rundll32.exe \\\"C:\\Windows\\perfc.dat\\\" #1"
Commans lines: schtasks /Create /SC once /TN "" /TR "<system folder>\shutdown.exe /r /f" /ST <time>
Commans lines: schtasks /Create /SC once /TN "" /TR "<system folder>\shutdown.exe /r /f" /ST <time>
It also contains a lightweight version of Mimikatz. It is used to dump valid credentials from memory... After initial infection, the ransomware will drop a tool in the %temp% folder, of what seems to be a lightweight version of Mimikatz... The tools are used to steal valid credentials to spread to other hosts in the network.
If Petya finds valid credentials, it will use either PsExec or WMIC to infect other computers connected to the LAN.
There are also indications of other propagation mechanisms that rely on insecurely configured network shares. | Based on an analysis in our labs, we have confirmed that the ETERNALBLUE exploit is one of the propagation vectors.
“Petya, NotPetya, and OpenPetya use MBR to execute their custom bootloaders, display a fake CHKDSK process, and encrypt the Master File Table (MFT).”
NotPetya NtRaiseHardError、InitiateSystemshutdownExW、ExitWindowsExの順で試行 shutdownコマンドのタスクスケジュールの生成
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
79 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical example of MBR-based bootloader behavior, including a fake CHKDSK display and MFT encryption.
Bootkit-style ransomware that encrypts critical NTFS MFT structures and replaces the boot process with malicious low-level code.
Ransomware referenced for its similar behavior of manipulating the boot process.
Ransomware that encrypts systems and overwrites the Master Boot Record, rendering machines unusable and hindering recovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.