Jump to content

Recommended Posts

Posted (edited)

Look at this approach at HardOCP, only takes 30 sec to immunize your PC with the creation of a simple file in C:\WINDOWS called perfc with NO extension.

 

https://www.hardocp.com/news/2017/06/28/petya_ass_there_killswitch_for_notpetya

 

 

HardOCP now states this does indeed work. You should make that file READ-ONLY as well.

Edited by BitMaster
  • Like 2

Gigabyte Aorus X570S Master - Ryzen 5900X - Gskill 64GB 3200/CL14@3600/CL14 - Sapphire  Nitro+ 7800XT - 4x Samsung 980Pro 1TB - 1x Samsung 870 Evo 1TB - 1x SanDisc 120GB SSD - Heatkiller IV - MoRa3-360LT@9x120mm Noctua F12 - Corsair AXi-1200 - TiR5-Pro - Warthog Hotas - Saitek Combat Pedals - Asus XG27ACG QHD 180Hz - Corsair K70 RGB Pro - Win11 Pro/Linux - Phanteks Evolv-X 

Posted

Do you know what the vector of this is? Email?

 

Good find.

PC:

 

6600K @ 4.5 GHz, 12GB RAM, GTX 970, 32" 2K monitor.

 

Posted (edited)

MeDoc accounting software is the source. They seem to have been hacked and any company downloading the recent patches from MeDoc got infected with the initial "downloader" for the actual virus. Email afaik is not the primary way of spreading.

 

Since it uses EternalBlue in it's code, it is very capable of spreading inside your LAN via SMB in various ways BEFORE it starts it's destruction. Once it has ( tried at least ) spreading internally it starts to encrypt that PC after a forced reboot, disguised as a CheckDisk. Pull the plug if you see that happening.

 

As there is no killswitch as with WannaCry it is still going strong as of now.

 

MeDoc is a Ukraine accounting software which every global company needs to have if they do business with the Ukraine...and many companies use it around the globe, they have to to file taxes afaik. MeDoc is a victim themselves, not the actual bad guy.

 

Some rumours blame it to NK as it is purely destructive. They will not make a single Bitcoin out of it, that is pretty clear and was never attempted as of the way it acts.

The Bitcoin thing is a disguise to hide it's actual intention, that is very clear.

Edited by BitMaster

Gigabyte Aorus X570S Master - Ryzen 5900X - Gskill 64GB 3200/CL14@3600/CL14 - Sapphire  Nitro+ 7800XT - 4x Samsung 980Pro 1TB - 1x Samsung 870 Evo 1TB - 1x SanDisc 120GB SSD - Heatkiller IV - MoRa3-360LT@9x120mm Noctua F12 - Corsair AXi-1200 - TiR5-Pro - Warthog Hotas - Saitek Combat Pedals - Asus XG27ACG QHD 180Hz - Corsair K70 RGB Pro - Win11 Pro/Linux - Phanteks Evolv-X 

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...