General

  • Target

    Ransomware.Petya.zip

  • Size

    945KB

  • Sample

    240701-gs41ya1ekl

  • MD5

    4f0ac2ca591d3beefafa84f0e26ef4d9

  • SHA1

    b311dd7a99e7968e1f73c8136b5b06fadc6fd3ac

  • SHA256

    b44f9707df1665407b8327264ab679e68d24bf79b4e072c9f4b5024af7359641

  • SHA512

    eab058f0002568a394e43df45e9e4dae597204d059e33ddfea38f1fe4a3b7347c7d9e1407787bb06ef1bc01553256f4e2cc6e084b92d3a196e45cf4b1eccc324

  • SSDEEP

    12288:knKuhDSfxuPL5zJFwKBaNrRiCTAZTYVHzKV5zJFwKBaNrRiCTAZTYVHzKX:/uhDUxulJGKsr0QcJGKsr0QU

Score
7/10

Malware Config

Targets

    • Target

      Ransomware.Petya.zip

    • Size

      945KB

    • MD5

      4f0ac2ca591d3beefafa84f0e26ef4d9

    • SHA1

      b311dd7a99e7968e1f73c8136b5b06fadc6fd3ac

    • SHA256

      b44f9707df1665407b8327264ab679e68d24bf79b4e072c9f4b5024af7359641

    • SHA512

      eab058f0002568a394e43df45e9e4dae597204d059e33ddfea38f1fe4a3b7347c7d9e1407787bb06ef1bc01553256f4e2cc6e084b92d3a196e45cf4b1eccc324

    • SSDEEP

      12288:knKuhDSfxuPL5zJFwKBaNrRiCTAZTYVHzKV5zJFwKBaNrRiCTAZTYVHzKX:/uhDUxulJGKsr0QcJGKsr0QU

    Score
    7/10
    • Executes dropped EXE

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

    • Target

      Ransomware.Petya/26b4699a7b9eeb16e76305d843d4ab05e94d43f3201436927e13b3ebafa90739.bin

    • Size

      225KB

    • MD5

      af2379cc4d607a45ac44d62135fb7015

    • SHA1

      39b6d40906c7f7f080e6befa93324dddadcbd9fa

    • SHA256

      26b4699a7b9eeb16e76305d843d4ab05e94d43f3201436927e13b3ebafa90739

    • SHA512

      69899c47d0b15f92980f79517384e83373242e045ca696c6e8f930ff6454219bf609e0d84c2f91d25dfd5ef3c28c9e099c4a3a918206e957be806a1c2e0d3e99

    • SSDEEP

      6144:DCyjXhd1mialK+qoNr8PxtZE6x5v+k6f:rjXhd8ZlKOrMZE6x5b6f

    Score
    6/10
    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

    • Target

      Ransomware.Petya/4c1dc737915d76b7ce579abddaba74ead6fdb5b519a1ea45308b8c49b950655c.bin

    • Size

      788KB

    • MD5

      a92f13f3a1b3b39833d3cc336301b713

    • SHA1

      d1c62ac62e68875085b62fa651fb17d4d7313887

    • SHA256

      4c1dc737915d76b7ce579abddaba74ead6fdb5b519a1ea45308b8c49b950655c

    • SHA512

      361a5199b5a6321d88f6e7b66eaad3756b4ea7a706fa9dbbe3ffe29217f673d12dd1200e05f96c2175feffc6fecc7f09fda4dd6bfa0ce7bef3d9372f6a534920

    • SSDEEP

      24576:z0wz1d5bAbWhrc56zQ9T4Ole+5PIuklOjB:Hd5Vhr4IMTbeGPJHjB

    Score
    6/10
    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

    • Target

      Ransomware.Petya/gtaV.bin.exe

    • Size

      788KB

    • MD5

      a92f13f3a1b3b39833d3cc336301b713

    • SHA1

      d1c62ac62e68875085b62fa651fb17d4d7313887

    • SHA256

      4c1dc737915d76b7ce579abddaba74ead6fdb5b519a1ea45308b8c49b950655c

    • SHA512

      361a5199b5a6321d88f6e7b66eaad3756b4ea7a706fa9dbbe3ffe29217f673d12dd1200e05f96c2175feffc6fecc7f09fda4dd6bfa0ce7bef3d9372f6a534920

    • SSDEEP

      24576:z0wz1d5bAbWhrc56zQ9T4Ole+5PIuklOjB:Hd5Vhr4IMTbeGPJHjB

    Score
    6/10
    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

4
T1542

Bootkit

4
T1542.003

Defense Evasion

Pre-OS Boot

4
T1542

Bootkit

4
T1542.003

Tasks