4th Street Bar Hive-Bar

Hive-Bar Powered by Hive beta-fdb5b5b

Community post

Petya Ransomware Spreading Rapidly

It has not been so long that WannaCry had attacked too many Windows based PCs. Another ransomware like WannaCry which is called Petya is spreading rapidly now. It has infected so many computers in short period of time. Petya ransomware encrypts the hard drives master file and renders the master boot record. Petya replaces the computer's MBR with it's malicious code. Like WannaCry, it also demands 300$ woth of bitcoin to get the files back. Infected users shouldn't pay the ransom because the email address used by the attacker is suspended, so you cannot communicate with the attacker. Petya ransomware is exploiting SMBv1 EternalBlue Exploit, same as WannCry. If you're running Windows 10, your computer is not likely to be vulnerable to attack. You can prevent Petya ransomware by creating file named perfc in C:\Windows and marking it as Read Only. You can download this file and run it to do that for you.
Ways to protect yourself from ransomware attacks.

  • Keep your system up-to-date.
  • If you're using unsupported version of Windows like XP, Server 2003, Vista, 2008, download and apply patch from here .
  • Keep your antivirus up-to-date.
  • Enable firewall and modify your firewall configurations to block access to SMB ports over the network. The protocol operated on TCP ports 137, 139 and 445, and on UDP ports 137 and 138.
  • Disable SMB. Follow steps described by Microsoft to disable SMB.
  • Do not click on any links received from unknown source.
2 upvotes $0.00

Replies (2)

Review before signing

Posting as . Signing with . Keychain permission: Posting. Hive Keychain will ask you to approve this action next.


  
Technical details

Operation fingerprint: