- Get link
- X
- Other Apps

The cipher virus that tried to attack Russian banks and hit the computers of a number of Ukrainian organizations and Russian media is called BadRabbit. Specialists of the Group-IB company, who analyzed it, noted that the new “extortionist” is nothing more than an improved version of the good old Petit that raged last spring. Cybersecurity experts were able to track the domain name from which the virus began to spread. There is a chance that the attackers will be able to track.
“The investigation revealed that the distribution of malware was carried out from the 1dnscontrol.com resource. The domain name 1dnscontrol.com has an IP of 5.61.37.209, ”the report says distributed by Group-IB.
Employees of "Group-IB" explain that BadRabbit is an improved and modified version of the virus "NotPetya", in the code of which encryption algorithms are fixed and there are a number of innovations. However, the code of the new virus has pieces of code completely similar to those found in NotPetya earlier.
The general director of Group-IB, Ilya Sachkov, on Sputnik radio said that the existing clue would allow the attackers to be found, but he does not exclude that such attacks can be repeated in the future. The fact is that the toolkit for creating similar viruses is freely available, which means that practically anyone can engage in its improvement and implementation.
Having infiltrated the computer, the ransomware virus encrypts all data on the hard disk, blocks the user's access to the PC and starts extorting an unlock reward in the amount of 0.05 Bitcoin (about $ 300 at the current rate).
“There is a great chance to understand where the physical arms and legs of this attack come from. You can determine who made the attack. The domain name was registered back in 2016, someone pays for it, and several other malicious domains are associated with it. The people who created them have been operating since 2011. That is, in our opinion, a fairly understandable criminal group. Not the fact that it is associated with this attack, but she was engaged, including spam and phishing. Unlike previous attacks, we already have a certain human footprint and logic, which will allow law enforcement agencies to conduct operational search activities and detain those who did it, ”Ilya Sachkova quotes RIA Novosti.
Among the first victims of the new virus encryption were Kiev Metro, Odessa airport and a number of Russian media, including Interfax and Fontanka.
The article is based on materials .
- Get link
- X
- Other Apps
Comments
Post a Comment