{"id":2539,"date":"2018-03-20T04:30:40","date_gmt":"2018-03-19T21:30:40","guid":{"rendered":"https:\/\/humanit.asia\/?p=2539"},"modified":"2019-07-22T14:42:16","modified_gmt":"2019-07-22T07:42:16","slug":"ta17-181a","status":"publish","type":"post","link":"https:\/\/old.humanit.asia\/th\/ta17-181a\/","title":{"rendered":"TA17-181A: Petya Ransomware"},"content":{"rendered":"<p>Original release date: July 01, 2017 | Last revised: February 15, 2018Systems Affected<br \/>\nMicrosoft Windows operating systems<br \/>\nOverview<br \/>\nThis Alert has been updated to reflect the U.S. Government&#8217;s public attribution of the &#8220;NotPetya&#8221; malware variant to the Russian military. Additional information may be found\u00a0in a Statement from the White House Press Secretary.\u00a0For more information related to\u00a0NotPetya activity, go to https:\/\/www.us-cert.gov\/grizzlysteppe.The scope of this Alert\u2019s analysis is limited to the newest Petya malware variant that surfaced on June 27, 2017. This malware is referred to as \u201cNotPetya\u201d throughout this Alert.On June 27, 2017, NCCIC [13] was notified of Petya malware events occurring in multiple countries and affecting multiple sectors. This variant of the Petya malware\u2014referred to as NotPetya\u2014encrypts files with extensions from a hard-coded list. Additionally, if the malware gains administrator rights, it encrypts the master boot record (MBR), making the infected Windows computers unusable. NotPetya differs from previous Petya malware primarily in its propagation methods.\u00a0The NCCIC Code Analysis Team produced a Malware Initial Findings Report (MIFR) to provide in-depth technical analysis of the malware. In coordination with public and private sector partners, NCCIC is also providing additional indicators of compromise (IOCs) in comma-separated-value (CSV) form for information sharing purposes.Available Files:MIFR-10130295.pdfMIFR-10130295_stix.xmlTA-17-181B_IOCs.csvDescription<br \/>\nNotPetya leverages multiple propagation methods to spread within an infected network. According to malware analysis, NotPetya attempts the lateral movement techniques below:PsExec &#8211; a legitimate Windows administration toolWMI &#8211; Windows Management Instrumentation, a legitimate Windows componentEternalBlue &#8211; the same Windows SMBv1 exploit used by WannaCryEternalRomance &#8211; another Windows SMBv1 exploitMicrosoft released a security update for the MS17-010 SMB vulnerability on March 14, 2017, which addressed the EternalBlue and EternalRomance lateral movement techniques.Technical DetailsNCCIC received a sample of the NotPetya malware variant and performed a detailed analysis. Based on the analysis, NotPetya encrypts the victim\u2019s files with a dynamically generated, 128-bit key and creates a unique ID of the victim. However, there is no evidence of a relationship between the encryption key and the victim\u2019s ID, which means it may not be possible for the attacker to decrypt the victim\u2019s files even if the ransom is paid. It behaves more like destructive malware rather than ransomware.NCCIC observed multiple methods used by NotPetya to propagate across a network. The first and\u2014in most cases\u2014most effective method, uses a modified version of the Mimikatz tool to steal the user\u2019s Windows credentials. The cyber threat actor can then use the stolen credentials, along with the native Windows Management Instrumentation Command Line (WMIC) tool or the Microsoft SysInternals utility, psexec.exe, to access other systems on the network. Another method for propagation uses the EternalBlue exploit tool to target unpatched systems running a vulnerable version of SMBv1. In this case, the malware attempts to identify other hosts on the network by checking the compromised system\u2019s IP physical address mapping table. Next, it scans for other systems that are vulnerable to the SMB exploit and installs the malicious payload. Refer to the malware report, MIFR-10130295, for more details on these methods.The analyzed sample of NotPetya encrypts the compromised system\u2019s files with a 128-bit Advanced Encryption Standard (AES) algorithm during runtime. The malware then writes a text file on the \u201cC:\u201d drive that includes a static Bitcoin wallet location as well as unique personal installation key intended for the victim to use when making the ransom payment and the user\u2019s Bitcoin wallet ID. NotPetya modifies the master boot record (MBR) to enable encryption of the master file table (MFT) and the original MBR, and then reboots the system. Based on the encryption methods used, it appears unlikely that the files could be restored, even if the attacker received the victim\u2019s unique key and Bitcoin wallet ID.The delivery mechanism of NotPetya during the June 27, 2017, event was determined to be the Ukrainian tax accounting software, M.E.Doc. The cyber threat actors used a backdoor to compromise M.E. Doc\u2019s development environment as far back as April 14, 2017. This backdoor allowed the threat actor to run arbitrary commands, exfiltrate files, and download and execute arbitrary exploits on the affected system. Organizations should treat systems with M.E.Doc installed as suspicious, and should examine these systems for additional malicious activity. [12]<br \/>\nImpact<br \/>\nAccording to multiple reports, this NotPetya malware campaign has infected organizations in several sectors, including finance, transportation, energy, commercial facilities, and healthcare. While these victims are business entities, other Windows systems are also at risk, such as:those that do not have patches installed for the vulnerabilities in MS17\u2011010, CVE-2017-0144, and CVE-2017-0145, andthose who operate on the \u00a0shared network of affected organizations.Negative consequences of malware infection include:temporary or permanent loss of sensitive or proprietary information,disruption to regular operations,financial losses incurred to restore systems and files, andpotential harm to an organization\u2019s reputation.Solution<br \/>\nNCCIC recommends against paying ransoms; doing so enriches malicious actors while offering no guarantee that the encrypted files will be released. In this NotPetya incident, the email address for payment validation was shut down by the email provider, so payment is especially unlikely to lead to data recovery.[1] According to one NCCIC stakeholder, the sites listed below sites are used for payment in this activity. These sites are not included in the CSV package as IOCs.hxxp:\/\/mischapuk6hyrn72[.]onion\/hxxp:\/\/petya3jxfp2f7g3i[.]onion\/hxxp:\/\/petya3sen7dyko2n[.]onion\/hxxp:\/\/mischa5xyix2mrhd[.]onion\/MZ2MMJhxxp:\/\/mischapuk6hyrn72[.]onion\/MZ2MMJhxxp:\/\/petya3jxfp2f7g3i[.]onion\/MZ2MMJhxxp:\/\/petya3sen7dyko2n[.]onion\/MZ2MMJNetwork SignaturesNCCIC recommends that organizations coordinate with their security vendors to ensure appropriate coverage for this threat. Given the overlap of functionality and the similarity of behaviors between WannaCry and NotPetya, many of the available rulesets can protect against both malware types when appropriately implemented. The following rulesets provided in publically available sources may help detect activity associated with these malware types:sid:2001569, \u201cET SCAN Behavioral Unusual Port 445 traffic Potential Scan or Infection\u201d[2]sid:2012063, \u201cET NETBIOS Microsoft SRV2.SYS SMB Negotiate ProcessID? Function Table Dereference (CVE-2009-3103)\u201d[3]sid:2024297, \u201cET CURRENT_EVENTS ETERNALBLUE Exploit M2 MS17-010\u201d[4]sid:42944,&#8221;OS-WINDOWS Microsoft Windows SMB remote code execution attempt&#8221;[11]sid:42340,&#8221;OS-WINDOWS Microsoft Windows SMB anonymous session IPC share access attempt&#8221;[11]sid:41984,&#8221;OS-WINDOWS Microsoft Windows SMBv1 identical MID and FID type confusion attempt&#8221;[11]Recommended Steps for PreventionReview US-CERT\u2019s Alert on The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations [6], and consider implementing the following best practices:Ensure you have fully patched your systems, and confirm that you have applied Microsoft\u2019s patch for the MS17-010 SMB vulnerability dated March 14, 2017.[5]Conduct regular backups of data and test your backups regularly as part of a comprehensive disaster recovery plan.Ensure anti-virus and anti-malware solutions are set to automatically conduct regular scans.Manage the use of privileged accounts. Implement the principle of least privilege. Do not assign administrative access to users unless absolutely needed. Those with a need for administrator accounts should only use them when necessary.\u00a0Configure access controls, including file, directory, and network share permissions with the principle of least privilege in mind. If a user only needs to read specific files, they should not have write access to those files, directories, or shares.\u00a0Secure use of WMI by authorizing WMI users and setting permissions.Utilize host-based firewalls and block workstation-to-workstation communications to limit unnecessary lateral communications.Disable or limit remote WMI and file sharing.Block remote execution through PSEXEC.Segregate networks and functions.Harden network devices and secure access to infrastructure devices.Perform out-of-band network management.Validate integrity of hardware and software.Disable SMBv1 and block all versions of SMB at the network boundary by blocking TCP port 445 with related protocols on UDP ports 137-138 and TCP port 139; this applies to all boundary devices.Note: Disabling or blocking SMB may create problems by obstructing access to shared files, data, or devices. Weigh the benefits of mitigation against potential disruptions to users.Recommended Steps for RemediationNCCIC strongly encourages organizations contact a local Federal Bureau of Investigation (FBI) field office upon discovery to report an intrusion and request assistance. Maintain and provide relevant logs.Implement a security incident response and business continuity plan. Ideally, organizations should ensure they have appropriate backups so their response is simply to restore the data from a known clean backup.\u00a0Report NoticeDHS encourages recipients who identify the use of tools or techniques discussed in this document to report information to DHS or law enforcement immediately. To request incident response resources or technical assistance, contact NCCIC at NCCICcustomerservice@hq.dhs.gov or 888-282-0870. You can also report cyber crime incidents to the Internet Crime Complaint Center (IC3) at https:\/\/www.ic3.gov\/default.aspx.<br \/>\nReferences<br \/>\nStatement from the White House Press Secretary<br \/>\n[1] Bleeping Computer: Email Provider Shuts Down Petya Inbox Preventing Victims From Recovering Files<br \/>\n[2] Emerging Threats 2001569<br \/>\n[3] Emerging Threats 2012063<br \/>\n[4] Emerging Threats 2024297<br \/>\n[5] Microsoft: Security Bulletin MS17-010<br \/>\n[6] US-CERT: The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations<br \/>\n[7] F-Secure: (Eternal) Petya from a Developer\u2019s Perspective<br \/>\n[8] Microsoft |TechNet: New ransomware, old techniques: Petya adds worm capabilities<br \/>\n[9] US-CERT: Ransomware and Recent Variants<br \/>\n[10] Microsoft: Windows 10 platform resilience against the Petya ransomware attack<br \/>\n[11] Talos: New Ransomware Variant &#8220;Nyetya&#8221; Compromises Systems Worldwide<br \/>\n[12] Talos: The MeDoc Connection<br \/>\n[13] NCCIC is the parent organization of US-CERT<br \/>\n[14] New Ransomware Variant &#8220;Nyetya&#8221; Compromises Systems Worldwide<br \/>\nMicrosoft: Update on Petya Malware attacks<br \/>\nMicrosoft: Authorize WMI users and set permissions<br \/>\nMicrosoft: Managing WMI Security<br \/>\nUS-CERT Alert TA16-091A<br \/>\nRevision History<br \/>\nJuly 1, 2017: Initial version<br \/>\nJuly 3, 2017: Updated to include MIFR-10130295_stix.xml file. Substituted TA-17-181B_IOCs.csv for TA-17-181A_IOCs.csv.<br \/>\nJuly 7, 2017: Included further guidance from Microsoft in the Reference Section<br \/>\nJuly 28, 2017: Revised multiple sections based on additional analysis provided<br \/>\nFebruary 15, 2018: Added attribution of the NotPetya malware variant to the Russian military and link to White House press statement.<br \/>\nThis product is provided subject to this Notification and this Privacy &amp; Use policy.<\/p>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener noreferrer\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original release date: July 01, 2017 | Last revised: Fe [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[106],"tags":[],"class_list":["post-2539","post","type-post","status-publish","format-standard","hentry","category-alerts-th"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TA17-181A: Petya Ransomware - humanit managed services<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/old.humanit.asia\/ta17-181a\/\" \/>\n<meta property=\"og:locale\" content=\"th_TH\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TA17-181A: Petya Ransomware - humanit managed services\" \/>\n<meta property=\"og:description\" content=\"Original release date: July 01, 2017 | Last revised: Fe [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/old.humanit.asia\/ta17-181a\/\" \/>\n<meta property=\"og:site_name\" content=\"humanit managed services\" \/>\n<meta property=\"article:published_time\" content=\"2018-03-19T21:30:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-07-22T07:42:16+00:00\" \/>\n<meta name=\"author\" content=\"Admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 \u0e19\u0e32\u0e17\u0e35\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta17-181a\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/th\\\/ta17-181a\\\/\"},\"author\":{\"name\":\"Admin\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"headline\":\"TA17-181A: Petya Ransomware\",\"datePublished\":\"2018-03-19T21:30:40+00:00\",\"dateModified\":\"2019-07-22T07:42:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/th\\\/ta17-181a\\\/\"},\"wordCount\":1671,\"articleSection\":[\"Alerts\"],\"inLanguage\":\"th\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/th\\\/ta17-181a\\\/\",\"url\":\"https:\\\/\\\/old.humanit.asia\\\/ta17-181a\\\/\",\"name\":\"TA17-181A: Petya Ransomware - humanit managed services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\"},\"datePublished\":\"2018-03-19T21:30:40+00:00\",\"dateModified\":\"2019-07-22T07:42:16+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta17-181a\\\/#breadcrumb\"},\"inLanguage\":\"th\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/old.humanit.asia\\\/ta17-181a\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta17-181a\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/old.humanit.asia\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TA17-181A: Petya Ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\",\"url\":\"https:\\\/\\\/old.old.humanit.asia\\\/\",\"name\":\"humanit managed services\",\"description\":\"making technology easy\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/old.old.humanit.asia\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"th\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\",\"name\":\"Admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"th\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"caption\":\"Admin\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TA17-181A: Petya Ransomware - humanit managed services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/old.humanit.asia\/ta17-181a\/","og_locale":"th_TH","og_type":"article","og_title":"TA17-181A: Petya Ransomware - humanit managed services","og_description":"Original release date: July 01, 2017 | Last revised: Fe [&hellip;]","og_url":"https:\/\/old.humanit.asia\/ta17-181a\/","og_site_name":"humanit managed services","article_published_time":"2018-03-19T21:30:40+00:00","article_modified_time":"2019-07-22T07:42:16+00:00","author":"Admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Admin","Est. reading time":"8 \u0e19\u0e32\u0e17\u0e35"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/old.humanit.asia\/ta17-181a\/#article","isPartOf":{"@id":"https:\/\/old.humanit.asia\/th\/ta17-181a\/"},"author":{"name":"Admin","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"headline":"TA17-181A: Petya Ransomware","datePublished":"2018-03-19T21:30:40+00:00","dateModified":"2019-07-22T07:42:16+00:00","mainEntityOfPage":{"@id":"https:\/\/old.humanit.asia\/th\/ta17-181a\/"},"wordCount":1671,"articleSection":["Alerts"],"inLanguage":"th"},{"@type":"WebPage","@id":"https:\/\/old.humanit.asia\/th\/ta17-181a\/","url":"https:\/\/old.humanit.asia\/ta17-181a\/","name":"TA17-181A: Petya Ransomware - humanit managed services","isPartOf":{"@id":"https:\/\/old.old.humanit.asia\/#website"},"datePublished":"2018-03-19T21:30:40+00:00","dateModified":"2019-07-22T07:42:16+00:00","author":{"@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"breadcrumb":{"@id":"https:\/\/old.humanit.asia\/ta17-181a\/#breadcrumb"},"inLanguage":"th","potentialAction":[{"@type":"ReadAction","target":["https:\/\/old.humanit.asia\/ta17-181a\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/old.humanit.asia\/ta17-181a\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/old.humanit.asia\/"},{"@type":"ListItem","position":2,"name":"TA17-181A: Petya Ransomware"}]},{"@type":"WebSite","@id":"https:\/\/old.old.humanit.asia\/#website","url":"https:\/\/old.old.humanit.asia\/","name":"humanit managed services","description":"making technology easy","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/old.old.humanit.asia\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"th"},{"@type":"Person","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c","name":"Admin","image":{"@type":"ImageObject","inLanguage":"th","@id":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","caption":"Admin"}}]}},"_links":{"self":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2539","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/comments?post=2539"}],"version-history":[{"count":2,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2539\/revisions"}],"predecessor-version":[{"id":2859,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2539\/revisions\/2859"}],"wp:attachment":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/media?parent=2539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/categories?post=2539"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/tags?post=2539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}