About us
Collection
For researchers
Subscribe
Our Telegram
Newsletter
About RIMA
For researchers
Collection
Kronika Project
About us
Collection
For researchers
Subscribe
Our Telegram
Date
06/28/2017
Author
Евгений Берг
Source
Meduza
Preserved copy
Internet Archive
Translated material

Experts from IT companies tell how the robber's virus managed to infect companies around the world

And what to do to protect yourself from the virus

Donat Sorokin / TASS / Scanpix / Leta

On Tuesday, June 27, a new robber virus began to spread on the Internet-when it enters the computer, it encrypts data and demands to transfer 300 dollars in exchange for the key to the cipher. Infection began with Ukraine, as a result, computers in 64 countries were infected with the virus; The program struck computers of large industrial companies - Maersk, Evraz and, apparently, Rosneft. The new virus is similar to the malicious Petya program, which appeared a year ago, and uses the same vulnerabilities as the Wannacry virus that hit thousands of computers in May 2017. "Medusa" with the help of specialists from large Russian IT companies answers key questions about the work of the virus.

How to call a new virus correctly?

In the media, the virus that spread around the world is called Petya-by the name of the Monk virus, which appeared a year ago . The new virus really looks a little like Petya, however, as Medusa was told in Kaspersky Laboratory, it differs from the old one in that it not only blocks, but also encrypts data on the disk, and also has additional distribution mechanisms along the local network. The new virus does not have a canonical name, in the “Kaspersky Laboratory” it is called Expetr; Other companies specializing in information security use the old name.

What does the virus do with a computer?

When the virus enters the computer on which the Windows operating system is installed, it downloads the encryption from the Internet and tries to impress part of the hard disk where the data necessary for downloading the computer is stored (this is called the MBR - Master Boot Record, the “main boot recording”). If it turns out, the system produces the “blue screen of death”, and after rebooting, instead of starting Windows, a standard message appears about checking the hard disk asking not to turn off the power.

In fact, this is a deception - the virus is disguised as a system for checking the disk, and at this time it encrypts files with certain extensions (for example, database and other files necessary for office work). When the encryption ends, the user sees a message that he became the victim of the Mount Program ( Ransomware ). To get a key for decryption, he must transfer 300 dollars to attackers with bitcoins.

In addition, after entering the computer, the virus seeks to infect other stations on the local network.

That the virus has already infected?

Infection began on July 27, 2017 from Ukraine. The virus struck the computers of the government, the “Ukrainian railways”, the Kiev metro, several banks, mobile companies, and the editorial offices of a number of media. The Security Service of Ukraine almost immediately accused Russia of attack.

In Russia itself, large industrial companies were hit-metallurgical Evraz, Mondelez (produces Alpen Gold chocolates), Rosneft (at the same time, Rosneft spokesman Mikhail Leontyev said that Kiberatak, which affected Rosneft computers and Bashneft belonging to it, could be connected. With the current trials of the company), Tatneft, as well as the Home Credit bank and others.

Then the virus spread to other countries-the WPP Group advertising and communication holding was injured in the UK, in Denmark-the Logistic company Maersk, in India-the largest container port named after Javaharlala Nera. Information Security Architect Informzamita, Pavel Taratynov, in a conversation with Medusa, said that by the evening of June 28, 12.5 thousand computers in 64 countries were infected.

The head of the Russian Research Center of Kaspersky Laboratory Yuri Vmesnikov told Medusa that the virus was “sharpened under business” - and was written in such a way as to amaze corporate networks.

How does the virus spread?

On June 27, the assumption appeared that Petya/Expetr was contained in the fresh update of the Medoc program, which is widely used in Ukraine for accounting. The developers said that this was not so , but also Taratynov from Inform Propetics, and the governors from the Kaspersky Lab of Kaspersky argue that the infection began with Medoc updates.

“Further it spread very simply. The whole economy is transnational, and therefore the virus from some offices was flowing into others, and in a few minutes, ”the Vicernikov explains. Experts did not specify how the virus hit the computers of companies that do not work with Medoc.

As both experts noted, the virus spreads either with the help of vulnerabilities in Windows, which used the Wannacry virus (he infected computers around the world in May), or through the PSEXEC and WMIC utilities built into Windows (and quite legitimate) - under normal conditions they are used to administer computer infrastructure. Experts said that we are talking about the use of social engineering in the case of Petya/Expetr, obviously does not go: e -mail or phishing links are not used to spread the virus.

How to protect yourself from the virus?

First of all, you need to update Windows. If you have an old version of the operating system, install updates manually (they are here ). This will save you from distribution through the vulnerability of the system, because fresh updates will be repaired. If you have antivirus software, upgrade signatures. Kaspersky also advises download a free utility for detecting robber viruses.

Experts also recommend forbidding their computer to contact some nodes on the Internet - then Petya/Expetr will not be able to download the encoder (list of nodes here ). Another way to reduce the risk of infection is to pretend that the computer is already infected; To do this, you will need a regular “notebook” (in the “Kaspersky Laboratory” this technique was called “Treatment of pneumonia garlic”, but Symantec experts recommend using it).

So that the infection does not violate your plans (if it occurs), make a backup of data. And in no case do not send money to the attackers - it often does not help: the mailboxes of scammers are blocked, and you simply cannot get the decryption key.

Evgeny Berg