|

|
Dave Kennedy (ReL1K)
@HackingDave
|
World blowing up from Petya today - be careful out there!
Mass infections, shuts down large infrastructure via worm fast.
|
| |
|

|
Lukas Stefanko
@LukasStefanko
|
Unpatched PC's were hit again by #Petya #ransomeware.
POS, Banks, ATMs, Airport, GOV, Media companies, Metro, Cargo… https://t.co/2lSpXJmQaf
|
| |
|

|
Dave Kennedy (ReL1K)
@HackingDave
|
Spreads SUPER fast - saw org 5K systems hit in under 10 minutes.
Restarts computer with ransom message (MBR).
|
| |
|

|
Dave Kennedy (ReL1K)
@HackingDave
|
What we have seen so far (VERY EARLY ANALYSIS) - extracts pw's and use combo of EternalBlue, wmic and psexec as method for lateral. #Petya
|
| |
|

|
Dave Kennedy (ReL1K)
@HackingDave
|
Petya using authentication re-use on systems -> that means more than just exploit being used for spreading.
This will be bad for folks.
|
| |
|

|
Dave Kennedy (ReL1K)
@HackingDave
|
Just patching with EternalBlue (MS17-010) doesn't appear to save you - other techniques for lateral movement in play here it looks like.
|
| |
|

|
Security Response
@threatintel
|
Symantec analysts have confirmed #Petya #ransomware, like #WannaCry, is using #EternalBlue exploit to spread
|