Bad Rabbit is a worm-capable Windows ransomware family that emerged in October 2017 and primarily affected organizations in Ukraine and Russia, with additional victims reported elsewhere. It combines file encryption, disk encryption, and local-network propagation, making it operationally similar to NotPetya while functioning as ransomware rather than a pure wiper. The malware is widely associated with the Diskcoder naming convention and has also been referred to as Diskcoder.D.
Initial infection was commonly achieved through user execution of a trojanized installer masquerading as an Adobe Flash update, including distribution from compromised websites that presented fake update prompts. The dropper requires elevated privileges via UAC and aborts if elevation is denied. After execution, Bad Rabbit deploys multiple components, including a DLL used for immediate file encryption and credential harvesting, and additional components that prepare disk encryption and reboot-based execution.
Bad Rabbit uses password-dumping tooling similar to Mimikatz, leverages stored Windows credentials, and also contains hard-coded credential combinations to move laterally. It enumerates DHCP-defined local subnets, probes administrative shares, and copies itself to reachable hosts inside victim networks. Reporting also linked its worm activity to SMB exploitation covered by MS17-010, with observed traffic resembling Eternal-family exploit behavior, although direct reuse of a specific exploit implementation was not conclusively proven. Its propagation was assessed as primarily local-network focused rather than Internet-scale.
For encryption, Bad Rabbit uses a legitimate DiskCryptor driver component to facilitate disk encryption and modifies the boot process to display a ransom message after reboot. It creates scheduled tasks to trigger reboot and launch follow-on components, and it can register components for automatic execution. The malware also deletes event logs and the USN journal, searches for security-related processes, and includes a local kill-switch condition based on the presence of a specific file. Multiple code and behavioral similarities with NotPetya have been documented, including privilege-related logic, named-pipe IPC with credential-dumping components, process enumeration, and DLL-based propagation, but definitive attribution to the same operator has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
10/26になりTalos(Cisco)からEternalRomanceを利用しているという情報が発信されました。... 同一環境に対しMS17-010の更新プログラムを適用した後に再度検証を実施した結果、横展開による感染が行われなくなったことも併せて確認しました。... Bad Rabbit が利用している脆弱性はEternalSynergy をベースとし改変されたExploitである可能性がある... 少なくともMS17-010で修正された範囲の脆弱性が利用されていることに違いはありません。 | Bad Rabbit の横展開に関わるワーム活動において、10/26になりTalos(Cisco)からEternalRomanceを利用しているという情報が発信されました。... 我々の調査においてはEternalSynergyと呼ばれる攻撃の通信と類似することを確認しました。
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI). ... CVE-2017-11882 is a 17-year old memory corruption issue in Microsoft Office ... The flaw resides within Equation Editor (EQNEDT32.EXE) ... A proof-of-concept exploit was released publicly, but this has been fixed by Microsoft’s November Patch Tuesday.
Dillon has crafted his modified exploits to take advantage of the following vulnerabilities: CVE-2017-0143 Type confusion between WriteAndX and Transaction requests EternalRomance EternalSynergy
Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。... 一定時間後に再起動... システム起動時に「dispci.exe」が自動起動されるようになります。
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。 次のタスクにより、感染後一定の時間が経過すると再起動が行われます。
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。... 一定時間後に再起動... システム起動時に「dispci.exe」が自動起動されるようになります。
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。 次のタスクにより、感染後一定の時間が経過すると再起動が行われます。
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。... 一定時間後に再起動... システム起動時に「dispci.exe」が自動起動されるようになります。
「infpub.dat」は、以下に挙げるようないくつかのタスクをシステムに登録する挙動があります。 次のタスクにより、感染後一定の時間が経過すると再起動が行われます。
NT Trans RequestにおけるNT Trans Secondary Requestの末尾へ、68バイトのSMBデータを繰り返し追記したリクエストを送信することでバッファーオーバーフローさせている様子が伺えます。
According to their preliminary findings, Diskcoder.D uses the Mimikatz tool to extract credentials from the affected systems. Apart from this, it has also a hardcoded list of credentials.
また、「infpub.dat」はリソースセクションから以下の不正ファイルを作成し、サービスとして自動起動されるようにシステムに登録します。
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
リソースセクションの文字列テーブル内には複数のバイナリデータが暗号化された状態で格納されています。... バイナリを隠蔽するために利用されることは基本的にないため、検知回避や解析妨害の目的と考えられます。
以下は「infpub.dat」がDhcpGetSubnetInfo APIおよびDhcpEnumSubnetClients APIを利用し、DHCPサーバで定義されたサブネットの列挙を行う際のコードです。
列挙された範囲のローカルネットワークアドレスを持つ端末への侵入を試みます。... リモート先の別端末における管理共有に...存在するかどうかを確認し、存在しなければ自身のコピーを配置します。
リモート先の別端末における管理共有に「cscc.dat」...が存在するかどうかを確認し、存在しなければ自身のコピーを配置します。
Bad Rabbit の横展開に関わるワーム活動において…Talos(Cisco)からEternalRomanceを利用しているという情報…該当環境においてもネットワークを介しBad Rabbit に感染する状況を確認しました。さらに同一環境に対しMS17-010の更新プログラムを適用した後に再度検証を実施した結果、横展開による感染が行われなくなったことも併せて確認しました。 | 10/26になりTalos(Cisco)からEternalRomanceを利用しているという情報(※1)が発信されました。 | その際の感染端末から送信された通信内容を確認した結果、脆弱性攻撃と思われる通信が確認できた為分析を進めたところ、我々の調査においてはEternalSynergyと呼ばれる攻撃の通信と類似することを確認しました。
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware associated in this detection with the creation or deletion of scheduled tasks via schtasks.exe, using task names such as rhaegal, drogon, and viserion_.
Destructive malware/ransomware that enumerates open SMB shares on internal victim networks.
Enterprise New Software: ... Bad Rabbit
Ransomware executed when users install an executable disguised as a Flash installer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.