Petya! A New Ransomware that is Wreaking Havoc around the World
Would you share this Article with others? +
Once a computer is infected, the ransomware will encrypt the files on it or make them unreadable, reboots it, and encrypts the MFT (Master File Tree) tables for NTFS partitions, which prevents victims from booting or accessing their computers. It also overwrites the MBR (Master Boot Record) with a custom bootloader that shows the ransom note below.
The Petya Ransom Note or Message
The Petya ransomware uses the following email address firstname.lastname@example.org for contact purposes and asks for a payment of $300 in Bitcoin for the victims to receive the key necessary to decrypt or make their files readable again. Because of this, Petya is more dangerous and intrusive compared to other versions or strains because it reboots systems and prevents them from working.
How to Protect Yourself Against the Petya Ransomware
Cyber criminals or hackers flood mailboxes with spam thus sending out fake email messages with malicious documents that deliver ransomware. This attack relies on users opening attached malicious document that will appear legitimate. Therefore, it is important that recipients of unexpected email messages never open the attachments in them, or have their I.T department or a tech-savvy family member or friend check the attachments before they attempt to open them.
Also, it is important that computer users and network administrators backup their important files in case they need to restore them if their computers get infected.
Petya spread via Server Message Block (SMB), a network protocol mainly used for providing shared access to files, printers, and serial ports and miscellaneous communications on a network.
Note: Some of the names, addresses, email addresses, telephone numbers or other information in samples on this website may have been impersonated or spoofed.
Check the comment section below for additional information and share what you know or ask a question about this article by leaving a comment below.
Remember to forward suspicious, malicious, or phishing email messages to us at the following email address: email@example.com. And, report missing persons, scams, untrustworthy, or fraudulent websites to us. Tell us why you consider the websites untrustworthy or fraudulent. Also, to quickly find answers to your questions, use our search
You can help maintain Online Threat Alerts (OTA) by paying a service fee. Click here to make payment.
Comments, Questions, Answers, or Reviews
To help protect your privacy, please do not post or remove, your full name, telephone number, email address, username, password, account number, credit card information, home address or other sensitive information in or from your comments, questions, or reviews. Also, remember to keep comments, reviews, answers respectful.
Show More Comments (1)
Write Your Comment, Question, Answer, or Review
Write your comment, question, answer, or review in the box below to share what you know or to get answers. NB: We will use your IP address to display your approximate location to other users.