
In the code of the Badrabbit-Sipper virus, who attacked many computers in Russia and Ukraine, there were references to the HBO TV channel Game of Thrones on the series of novels "Songs of the ice and flame of" George Martin ".
BBC draws attention to the screenshot, which was published on Twitter, researcher Kevin Bomon. According to the given data, the virus creates in Windows the tasks named after the Drogon, Rhaegal and Viserion dragons in the "Game of Thrones". This gives a “bad rabbit” more similarity to Locky virus than with notPetya than previously supposed.
Badrabbit Creates Two Scheduled Tasks, Named after the Dragons from Game of Thrones. Also A Reference to GrayWorm, The Skin Disease in Got. pic.twitter.com/bfqxgrmwc0
- Kevin Beaumont 🐿 (@gossithedog) October 24, 2017
Badrabbit gets to the computer, masking under the update for Adobeflash. After installation, it blocks activity in the system and encrypts files, and then requires a ransom of 0.05 bitcoin (about $ 280).
To date, Badrabbit’s mass distribution managed to stop, however, cybersecurity specialists recommend Windows users to play up to play up by blocking the execution of files C: \ Windows \ Infpub.dat and C: \ Windows \ CSCC.DAT and prohibiting the use of WMI, writes Lenta.ru .
Over the past six months, two waves of attacks of siphesis viruses have already swept around the world: on May 12, the Wannacry virus attack , and on June 27, the Petya-Meteraa virus struck the network of about 80 organizations in Russia and the government network in Ukraine.
Both viruses penetrated into computers working on the base of Windows, encrypted the contents of the hard drives and required a redemption for data restoration. The Wannacry virus attack affected hundreds of thousands of computers in more than 150 countries, and the Petya attack - over 10 thousand computers in 65 countries. A number of Russian companies were injured from the viruses, including Megafon and Rosneft, and as a result of the Petya attack, so -time cases of computers in banks were recorded.
The Monk virus, which blocks access to data and requires $ 300 in bitcoins for unlocking, has been known in various modifications since 2016.
The malicious program is distributed through spam. In particular, the first versions of Petya were disguised as a resume. When the user opened an infected letter, a Windows program appeared on the screen that required administrator rights.