petya ransomware skip the files and encrypts the hard drives

     


what is petya ransomware?
after wannacry ransomware the new ransomware spread all over the world it is called as petya. now , when the use becomes infected by a cypto-ransomware , the infected targets and encrypts the files on the victims hard drives. this leaves the operating system working properly, but with the user unable  to encrypted documents. but the petya ransomware take it to the next level by encrypting portions of the hard drive itself that you are unable to access anything on the drive including windows. and if you
want to decrypt your drives you have to pay ransom around ~9 . and if you successfully, pay it you drives become free to use.


why is it called 'petya'?
the malware appears to share a significant amount of code with older piece of ransomware that really was called petya. petya is family of encrypting ransomware that was first discovered in 2016.the malware targets microsoft windows-based systems,infecting the master boot record to execute a payload that encrypts a hard drives files






how does the petya ransomware work?

the ransomware takes over computer to demands $300,paid  in bitcoin. the main software spreads rapidly across and organization once a computer is infected using the EternalBlue vulnerability in microsoft windows(microsoft have  just patch it everyone have to install it) 




how it is distributed?
the petya ransomware is currently being distributed via email attachment . these email contains dropbox  link to supposed  application that download a file that when  executed will  install the petya ransomware the computer. 


Comments

Popular posts from this blog

MALWARE

Nmap for scanning networks