Endpoint Protection

 View Only
Expand all | Collapse all

New ransomeware variant.

  • 1.  New ransomeware variant.

    Posted Jun 27, 2017 10:27 AM

    Hi Team,

    Is there any information on Petrwrap/Petya ransomeware variant. from Symantec.



  • 2.  RE: New ransomeware variant.

    Posted Jun 27, 2017 10:32 AM

    With what specifically? Symantec has had signatures for this variant for quite some time now.

    https://www.symantec.com/security_response/writeup.jsp?docid=2016-032913-4222-99



  • 3.  RE: New ransomeware variant.

    Posted Jun 27, 2017 11:23 AM

    Not a lot of information from Symantec, and definitions of PETYA are old for this variant

    • Latest Daily Certified version February 7, 2017 revision 001

     

    Waiting SRL blog.

    https://www.symantec.com/connect/symantec-blogs/sr

     

    Info about Petya.

     

    Discovered:
    March 29, 2016
    Updated:
    August 26, 2016 11:53:19 AM
    Also Known As:
    Trojan.Cryptolocker.AJ [Symantec]
    Type:
    Trojan
    Infection Length:
    Varies
    Systems Affected:
    Windows
     
    Ransom.Petya is a Trojan horse that encrypts files on the compromised computer. 

    Note: Definitions prior to August, 2016 may detect this threat as Trojan.Cryptolocker.AJ 

    For more information on ransomware threats, please see the following resource: 
    The dawn of ransomwear: How ransomware could move to wearable devices 

    Antivirus Protection Dates

    • Initial Rapid Release version May 20, 2016 revision 034
    • Latest Rapid Release version February 6, 2017 revision 033
    • Initial Daily Certified version May 20, 2016 revision 049
    • Latest Daily Certified version February 7, 2017 revision 001
    • Initial Weekly Certified release date March 30, 2016
    Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.


  • 4.  RE: New ransomeware variant.

    Posted Jun 27, 2017 11:29 AM

    After additional research, since this just started today, Symantec has not come out with more info. I assume that will follow here in the next couple hours or so. If running SEP 14 and all of its components, this should be detecting it, even though AV signatures may not catch it.



  • 5.  RE: New ransomeware variant.

    Posted Jun 27, 2017 11:43 AM

    Early results from VirusTotal show that SEP's machine learning component is detecting it:

    https://www.virustotal.com/en/file/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745/analysis/



  • 6.  RE: New ransomeware variant.

    Posted Jun 27, 2017 11:43 AM

    Thanks Brian,

    Please let us know if have any update and new definition released to cover.



  • 7.  RE: New ransomeware variant.

    Posted Jun 27, 2017 12:37 PM

    Currently, it's detected as Trojan.gen.2:

    https://www.virustotal.com/en/file/8143d7d370015ccebcdaafce3f399156ffdf045ac8bedcc67bdffb1507be0b58/analysis/



  • 8.  RE: New ransomeware variant.

    Posted Jun 27, 2017 01:01 PM

    Info has been updated on VT:

    https://virustotal.com/en/file/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745/analysis/



  • 9.  RE: New ransomeware variant.

    Posted Jun 27, 2017 01:10 PM

    I am currently monitoring our system network. I am running SEP 14 and SEP 12. Please let me know if there is a new definitions to cover this issue.



  • 10.  RE: New ransomeware variant.

    Posted Jun 27, 2017 01:11 PM

    Yes, revision 6/27/17 r1 detects it as Trojan.Gen.2



  • 11.  RE: New ransomeware variant.

    Posted Jun 27, 2017 01:21 PM

    Symantec Security Response just released their blog on this:

    https://www.symantec.com/connect/blogs/petya-ransomware-outbreak-here-s-what-you-need-know



  • 12.  RE: New ransomeware variant.

    Posted Jun 27, 2017 03:34 PM

    Tanks Brian, 

    I just find a small difference in detection name.

     

    In VirusTotal, certified definitions catch this under ML.Attribute.HighConfidence , but in Petya, only update is Rapid Release defiitions

    https://www.symantec.com/security_response/writeup.jsp?docid=2016-032913-4222-99

     

    For more information, please see the following resource: 
    Petya ransomware outbreak: Here’s what you need to know 

    Antivirus Protection Dates

    • Initial Rapid Release version May 20, 2016 revision 034
    • Latest Rapid Release version June 27, 2017 revision 009
    • Initial Daily Certified version May 20, 2016 revision 049
    • Latest Daily Certified version February 7, 2017 revision 001
    • Initial Weekly Certified release date March 30, 2016
    Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
     
     


  • 13.  RE: New ransomeware variant.

    Posted Jun 29, 2017 04:05 AM

    You can mark this post as solved.