Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
Indian Computer Emergency Response Team issues medium severity alert on 'Bad Rabbit' ransomware
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit

Indian Computer Emergency Response Team issues medium severity alert on 'Bad Rabbit' ransomware

tech2 News Staff • October 31, 2017, 12:36:07 IST
Whatsapp Facebook Twitter

The ransomware infects a machine by pretending to be an Adobe Flash Installer and then encrypts the files and the drive.

Advertisement
Subscribe Join Us
Choose
Firstpost on Google
Choose
Firstpost on Google
Indian Computer Emergency Response Team issues medium severity alert on 'Bad Rabbit' ransomware

The Indian Computer Emergency Response Team (CERT-In) has issued a medium severity alert for Bad Rabbit, a ransomware that spread in  **Ukraine, Bulgaria, Turkey and Japan** . A major portion of the targets were in Russia. The ransomware infects a machine by pretending to be an Adobe Flash Installer, then spreads through the network though open server message block shares, dropping malware through a hardcoded list of credentials. [caption id=“attachment_4180843” align=“alignleft” width=“380”] ![Image: Max Pixel](https://images.firstpost.com/wp-content/uploads/2017/10/bad-rabbit-380.jpg) Image: Max Pixel[/caption] The Mimikatz post exploitation tool is used to retrieve credentials from the target systems. Bad Rabbit uses DiskCryptor to encrypt the entire drive with RSA 2048 keys, it also encrypts individual files. Bad Rabbit then demands a 0.05 bitcoin payment to allow the users to access the files, with a countdown timer, after which the ransom amount is increased.  CERT-In recommends keeping the software and operating system updated, regularly backing up critical data in air gapped drives, disabling SMB, activating the anti-ransomware folder protection feature in Windows 10, and blocking the execution of \windows\infpub.dat and c:\Windows\cscc.dat. The ransomware spreads by exploiting critical remote code execution vulnerabilities fixed by the Microsoft Security Bulletin MS17-010. Bad Rabbit uses EternalRomance, an **NSA tool** leaked by a hacking collective known as the **ShadowBrokers** . The same **cluster of tools** were used in a number of high profile malware attacks, including the **WannaCry ransomware** , A cryptocurrency miner known as  Adylkuzz , a ransomware that primarily spread in China called UIWIX , and NotPetya which was a massive cyberattack campaign  **designed to destroy data** disguised as a malware. According to research by ESET, 65 percent of the affected systems were in Russia, with only 2.4 percent of the infections occurring outside Russia, Ukraine, Turkey, Bulgaria or Japan. Many of the systems were affected at the same time, which indicates that the attackers already had a foothold inside the companies. Both ESET and and Cisco’s Talos intelligence confirm that there are no indications that Bad Rabbit is using the EternalBlue exploit, despite reports. According to Talos, Bad Rabbit is built on the same code base as the Nyetya malware and that the authors of Nyetya and Bad Rabbit are the same. According to Kaspersky’s SecureList, Bad Rabbit is a previously unknown malware family and analysis of the code shows similarities between Bad Rabbit and the ExPetr malware. [caption id=“attachment_4180939” align=“alignnone” width=“720”] ![A screenshot of the ransomware. Image: ESET. ](https://images.firstpost.com/wp-content/uploads/2017/10/mbr_cut.png) A screenshot of the ransomware. Image: ESET.[/caption] The scheduled tasks are named after dragons from The Game of Thrones, and are called viserion_, rhaegal and drogon. The hard coded passwords for dropping the malware is a rather weak list, with god, sex, love and secret right on top. This is a reference to the 1995 movie, Hackers.

Tags
Malware CERT In Ransomware cybersecurity
  • Home
  • Tech
  • News & Analysis
  • Indian Computer Emergency Response Team issues medium severity alert on 'Bad Rabbit' ransomware
End of Article
Latest News
Find us on YouTube
Subscribe
  • Home
  • Tech
  • News & Analysis
  • Indian Computer Emergency Response Team issues medium severity alert on 'Bad Rabbit' ransomware
End of Article

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Enjoying the news?

Get the latest stories delivered straight to your inbox.

Subscribe
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV