Petya: easily disabling access to psexec
Common Information
Type Value
UUID 9cb1bafc-bff1-44c5-b4dc-a8a975563f24
Fingerprint 36ad0d7aacfb2b9b
Analysis status DONE
Considered CTI value 0
Text language
Published June 28, 2017, 7:36 a.m.
Added to db Jan. 18, 2023, 9:45 p.m.
Last updated Nov. 17, 2024, 10:40 p.m.
Headline Petya: easily disabling access to psexec
Title Petya: easily disabling access to psexec
Detected Hints/Tags/Attributes 31/1/9
Attributes
Details Type #Events CTI Value
Details Domain 1
myinvocation.mycommand.name
Details File 122
psexec.exe
Details File 240
wmic.exe
Details File 1122
svchost.exe
Details File 1208
powershell.exe
Details File 1
c:\temp\infected.ps1
Details File 2126
cmd.exe
Details File 33
sethc.exe
Details Windows Registry Key 104
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows