Petya and Mischa: ransomware duet (part 2) | Malwarebytes Labs
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Server - T1583.004 Server - T1584.004 |
Common Information
Type | Value |
---|---|
UUID | 3df953a4-9bd3-4593-bd3e-c589f493a299 |
Fingerprint | 262719563c6dc6d1 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | June 10, 2016, midnight |
Added to db | Jan. 18, 2023, 8:35 p.m. |
Last updated | Nov. 17, 2024, 6:55 p.m. |
Headline | Petya and Mischa: ransomware duet (part 2) |
Title | Petya and Mischa: ransomware duet (part 2) | Malwarebytes Labs |
Detected Hints/Tags/Attributes | 56/2/11 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | File | 9 | setup.dll |
|
Details | File | 2 | mischa.dll |
|
Details | File | 9 | your_files_are_encrypted.html |
|
Details | File | 7 | square.bmp |
|
Details | File | 137 | conhost.exe |
|
Details | File | 351 | recycle.bin |
|
Details | md5 | 1 | 8a241cfcc23dc740e1fadc7f2df3965e |
|
Details | md5 | 1 | c8e4829dcba8b288bd0ed75717214db6 |
|
Details | md5 | 1 | 10b2d20a3c36fe6a5bf6f3b15149c3d1 |
|
Details | md5 | 1 | 34da44570eb8c7a5038370f553eb3899 |
|
Details | Url | 1 | http://www.bleepingcomputer.com/news/security/petya-is-back-and-with-a-friend-named-mischa-ransomware |