Petya is a Windows ransomware family first observed in March 2016. It modifies the master boot record to install a custom bootloader and forces the infected system to restart. During subsequent pre-operating-system execution, it displays a fake CHKDSK screen while encrypting the NTFS Master File Table, preventing normal access to files and rendering Windows unbootable. It then displays an ASCII-art skull and a ransom demand for a decryption key. Petya was also advertised through a ransomware-as-a-service program in 2016.
Petya is distinct from NotPetya, the destructive malware responsible for the June 2017 outbreak that was initially reported under the Petya name. Although both use custom boot code and Master File Table encryption, NotPetya's credential theft, SMB-exploit propagation, compromised software-update delivery, and Russian military attribution should not be attributed to the original Petya family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The manual contains an MS17-010 section discussing vulnerable Windows systems. The report also states that WannaCry, Petya, and NotPetya leveraged EternalBlue.
The same vulnerability was once again targeted a month later in the June Petya/NotPetya attacks.
The ransomware can also perform lateral movement by using two exploits that came with the ShadowBrokers dump in April, called ETERNALBLUE and ETERNALROMANCE. These tools exploit vulnerabilities in SMBv1 (CVE-2017-0144 and CVE-2017-0145). | Petya is a ransomware family, with several capabilities similar to the ransomware that started spreading yesterday (27.06.17). Kaspersky claims that yesterday’s variant is not based on Petya, naming it NotPetya instead. Others claim that this is a combination of several ransomwares, calling it GoldenEye.
There have been reports of malicious Word documents using the CVE-2017-0199 vulnerability being used as the initial infection vector for this ransomware attack. We have not confirmed these reports as yet. | The eSentire Threat Intelligence team is continuing to analyze Petya samples to gain further understanding of its behavior. Based on an analysis in our labs, we have confirmed that the ETERNALBLUE exploit is one of the propagation vectors.
6.CVE-2017-0144, CVE-2017-0145, CVE-2017-0143 Description: Windows SMBv1 Remote Code Execution Vulnerability WannaCry, Petya
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
hackers used a self-developed modification of Petya ransomware named PetrWrap.
This is a follow-up from our previous diary about today's ransomware attacks using the new Petya variant... Petya is a ransomware family that works by modifying the infected Windows system's Master Boot Record (MBR).
While the world is holding its breath, wondering where notorious cybercriminal groups like Lazarus or Telebots will strike next with another destructive malware such as WannaCryptor or Petya...
When Petya spread for the first time in March 2016... After a reboot the Master File Tabel (MFT) is encrypted... The evident similarity to Petya caused many researchers to name the new threat "Petya", too. But first doubts emerged soon, which are reflected in names like NotPetya, Nyetya, or Petna.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
If Petya finds valid credentials, it will use either PsExec or WMIC to infect other computers connected to the LAN... Lateral movements (remote WMI): "process call create \"C:\\Windows\\System32\\rundll32.exe \\\"C:\\Windows\\perfc.dat\\\" #1"
Commans lines: schtasks /Create /SC once /TN "" /TR "<system folder>\shutdown.exe /r /f" /ST <time>
Commans lines: schtasks /Create /SC once /TN "" /TR "<system folder>\shutdown.exe /r /f" /ST <time>
It also contains a lightweight version of Mimikatz. It is used to dump valid credentials from memory... After initial infection, the ransomware will drop a tool in the %temp% folder, of what seems to be a lightweight version of Mimikatz... The tools are used to steal valid credentials to spread to other hosts in the network.
If Petya finds valid credentials, it will use either PsExec or WMIC to infect other computers connected to the LAN.
There are also indications of other propagation mechanisms that rely on insecurely configured network shares. | Based on an analysis in our labs, we have confirmed that the ETERNALBLUE exploit is one of the propagation vectors.
“Petya, NotPetya, and OpenPetya use MBR to execute their custom bootloaders, display a fake CHKDSK process, and encrypt the Master File Table (MFT).”
NotPetya NtRaiseHardError、InitiateSystemshutdownExW、ExitWindowsExの順で試行 shutdownコマンドのタスクスケジュールの生成
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
91 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical example of MBR-based bootloader behavior, including a fake CHKDSK display and MFT encryption.
Bootkit-style ransomware that encrypts critical NTFS MFT structures and replaces the boot process with malicious low-level code.
Ransomware referenced for its similar behavior of manipulating the boot process.
Ransomware that encrypts systems and overwrites the Master Boot Record, rendering machines unusable and hindering recovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.