• lianatech.fi
Prenumerera på RSS Prenumerera på nyheter Logga in
LianaPress LianaPress
  • Pressmeddelanden
  • Nyhetsrum
  • Prenumerationer
  • Information om tjänsten
  • Kontakta oss
LianaPress
  • Pressmeddelanden
  • Nyhetsrum
  • Prenumerationer
  • Information om tjänsten
  • Kontakta oss
Logga in
Prenumerera på RSS Prenumerera på nyheter
ESET

“Petya” Ransomware: What we know now, and how to protect yourself.

ESET
28.6.2017, 13:12

LAST UPDATED 3:10 p.m. PDT: 

A massive new ransomware attack that started in Ukraine is spreading across Europe and the United States, according to Reuters and multiple other sources. Prominent companies that have been affected are the Danish shipping company Maersk and the British advertising company WPP.

The ransomware appears to be related to the Petya family, which is currently detected by ESET as Win32/Diskcoder.C Trojan. 

ESET users can find instructions to ensure the highest level of protection against this threat here. In addition, here is an advisory for ESET customers about the new malware. ESET protects against this threat, provided you have a default install of any modern ESET product. Additionally, any ESET product with network detection protects against the SMB spreading mechanism, EternalBlue, proactively.

The scale of the attack is being compared to the recent WannaCry outbreak. ESET protects both businessesand home users against WannaCry. 

ESET researchers have located the point from which this global epidemic has all started. Attackers have successfully compromised the accounting software M.E.Doc, popular across various industries in Ukraine, including financial institutions. Several of them executed a trojanized update of M.E.Doc, which allowed attackers to launch the massive ransomware campaign today which spread across the whole country and to the whole world. M.E.Doc has today released a warning on their website: http://www.me-doc.com.ua/vnimaniyu-polzovateley.

How does Petya work?

The Petya malware attacks a computer’s MBR (master boot record), a key part of the startup system that contains information about the hard disk partitions and helps load the operating system. If the malware successfully infects the MBR, it will encrypt the whole drive itself. Otherwise, it encrypts all files, like Mischa.

The new malware appears to be using a combination of the EternalBlue exploit used by WannaCryptor for getting inside the network, then spreading through PsExec for spreading within it.

To check if your Windows operating system is patched against it, use ESET's free EternalBlue Vulnerability Checker.

This powerful combination is likely the reason why the outbreak is spreading quickly, even after previous outbreaks have generated headlines and most vulnerabilities should have been patched. It only takes one unpatched computer to get inside the network. From there, the malware can take over administrator rights and spread to other computers.

Petya and crypto-ransomware

In Ukraine, the financial sector, energy sector and numerous other industries have been hit. The scope of the damage caused to the energy sector is not yet confirmed, and there has been no reports of a power outage, as was the case previously with the infamous Industroyer malware that was discovered by ESET.

[Image: Petya_detections.jpg] An image that reportedly shows the ransomware message is making the rounds online, including one from Group-IB with the following message (which we’ve paraphrased):

“If you see this text, then your files are no longer accessible, because they have been encrypted … We guarantee that you can recover all your files safely and easily. All you need to do is submit the payment [$300 bitcoins] and purchase the decryption key.”

How to protect yourself

  • Use reliable antimalware software: This is a basic but critical component. Just because it’s a server, and it has a firewall, does not mean it does not need antimalware. It does! Always install a reputable antimalware program and keep it updated.
  • Make sure that you have all current Windows updates and patches installed
  • Run ESET’s EternalBlue Vulnerability Checker to see whether your Windows machines are patched against EternalBlue exploit, and patch if necessary.
  • For ESET Home Users: Perform a Product Update.
  • For ESET Business Users: Send an Update Task to all Client Workstations or update Endpoint Security or Endpoint Antivirus on your client workstations.

For more on Petya and crypto-ransomware, see this article from 2016 from ESET’s WeLiveSecurity.com blog.

DatorerProgramvaraSäkerhet

Tillgängliga filer

eset-logo-primary-colour-mid-grey-tag-cmyk.jpg

ESET logo - Primary - Colour - Mid Grey tag - CMYK.jpg

Storlek: 0.33 MB Typ: jpg Upplösning: 4179x599

Ladda upp en fil

eset-logo-primary-colour-mid-grey-tag-cmyk.jpg

ESET logo - Primary - Colour - Mid Grey tag - CMYK.jpg

Storlek: 0.33 MB Typ: jpg Upplösning: 4179x599

Ladda upp en fil

petya_detections.jpg

Petya_detections.jpg

Storlek: 0.04 MB Typ: jpg Upplösning: 1200x630

Ladda upp en fil

petya_detections.jpg

Petya_detections.jpg

Storlek: 0.04 MB Typ: jpg Upplösning: 1200x630

Ladda upp en fil


Mer om utgivaren

About ESET

For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint and mobile security, to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give consumers and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real-time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D centers worldwide, ESET becomes the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003. For more information visit www.eset.com or follow us on LinkedIn, Facebook and Twitter.

ESET

ESET

Utgivarens nyhetsrum

De senaste pressreleaserna från utgivaren

De senaste nyheterna från branschen

ESET

ESET

LianaPress

  • Pressmeddelanden
  • Nyhetsrum
  • Prenumerationer
  • Information om tjänsten
  • Kontakta oss
  • Integritetspolicy

Branscher

  • Affärsverksamhet / ekonomi Annonsera Arbetsliv Bioteknik Båtliv Datorer Datorhårdvara Dekoration Detaljhandel Djur/husdjur Ekonomi Elektronik Energi Familj Fastigheter Finans
  • Flyg- och rymdsektorn Fordonsindustri Fotografi Fritid Försäkring Hantverk Hemland Ideell verksamhet Idrott Informationssäkerhet Ingenjörskonst Internationellt Jordbruk Juridik Kemikalier Konstruktion
  • Kultur och konst Landsbygd Livsstil Logistik och transport Marknadsföring Mat och dryck Media Medicinska frågor Metallindustri och metallurgi Militär Miljö och natur Musik och underhållning Pappersindustri Politik Programvara Publicistik
  • Religion Skog och trä Sociala tjänster Sport / fritid Statlig verksamhet Städer och provinser Säkerhet Tecknade serier Telekommunikation Tillverkning Toppnyheter Trädgårdsarbete Turism Utbildning Vetenskap
 
  • http://suomalai...
  • http://www.dnb....
  • http://www.busi...
  • https://www.goo...
  • https://www2.de...
  • https://www.iab...
  • https://www.inc...
  • Medlem i Swedis...

© Liana Technologies