Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not just Maersk. Petya going global. Writes to boot sector.


Writes to boot sector? Care to elaborate? Sources?


If you see the fake chkdsk reboot to media and overwrite/fix the master boot record. It encrypts the master file table on startup (before AV etc.), has sophisticated lateral movement capabilities using WMIC. Don't bother paying the ransom - the mailbox is dead you'll never get your files back that way.


google "petya boot sector"

the first link is:

https://blog.malwarebytes.com/threat-analysis/2016/04/petya-...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: