Skip to main content
Mallory
MalwareRansomwareUsed by 1 actorExploits 1 CVE

PetyaWrap

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2017-0144EternalBlue SMBv1 Remote Code Execution in Microsoft Windows

PetyaWrap, as some researchers are calling the ransomware, uses a cocktail of potent techniques to break into a network and from there spread from computer to computer.

via web archiveweb.archive.org
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Shadow Brokers

PetyaWrap, as some researchers are calling the ransomware, uses a cocktail of potent techniques to break into a network and from there spread from computer to computer.

via web archiveweb.archive.org
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1195Supply Chain CompromiseEvidence2

at least some of the attacks also exploited the update mechanism of a third-party Ukrainian software product called MeDoc... MeDoc was itself compromised by malware that took control of the mechanism that sends updates to end users.

Execution

1 technique
T1047Windows Management InstrumentationEvidence2
TacticExecution

infected computers would then use PSExec, a legitimate Windows component known as the Windows Management Instrumentation, and possibly other command-line utilities to infect other machines

Stealth

1 technique
T1497.003Time Based ChecksEvidence1

Once the malware takes hold of a computer, it waits 10 to 60 minutes to reboot the infected computers.

T1003OS Credential DumpingEvidence2

One, according to Kaspersky, was the use of the Mimikatz hacking tool to extract passwords from other computers on a network.

Discovery

1 technique
T1497.003Time Based ChecksEvidence1

Once the malware takes hold of a computer, it waits 10 to 60 minutes to reboot the infected computers.

Lateral Movement

3 techniques
T1021Remote ServicesEvidence1

With those network credentials in hand, infected computers would then use PSExec, a legitimate Windows component known as the Windows Management Instrumentation, and possibly other command-line utilities to infect other machines...

T1021.002SMB/Windows Admin SharesEvidence1

With those network credentials in hand, infected computers would then use PSExec... and possibly other command-line utilities to infect other machines.

T1210Exploitation of Remote ServicesEvidence2

Tuesday's attack made use of EternalBlue... Tuesday's attack also repurposed a separate NSA exploit dubbed EternalRomance.

Impact

2 techniques
T1486Data Encrypted for ImpactEvidence1
TacticImpact

The encryption routine that permanently locks data until targets pay a $300 fee starts only after the computer restarts.

T1561Disk WipeEvidence1
TacticImpact

The ransomware targets the computer's master boot record, which is a crucial file that allows a computer to locate its operating system and other key components.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

PetyaWrap | Mallory