Advertisement
Guest User

Petya Ransomware IOCs

a guest
Jun 27th, 2017
1,782
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.17 KB | None | 0 0
  1. Petya Ransomware Campaign
  2.  
  3. Email address associated with infections:
  4.  
  5. Bitcoin address:
  6.  
  7. 1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX
  8. Targeted file extensions:
  9.  
  10. .3ds.7z.accdb.ai.asp.aspx.avhd.back.bak.c.cfg.conf.cpp.cs.ctl.dbf.disk.djvu.doc.docx.dwg.eml.fdb.gz.h.hdd.kdbx.mail.mdb.msg.nrg.ora.ost.ova.ovf.pdf.php.pmf.ppt.pptx.pst.pvi.py.pyc.rar.rtf.sln.sql.tar.vbox.vbs.vcb.vdi.vfd.vmc.vmdk.vmsd.vmx.vsdx.vsv.work.xls.xlsx.xvd.zip.
  11. Ransom note name:
  12.  
  13. README.TXT
  14. Ransom note text:
  15.  
  16. Send your Bitcoin wallet ID and personal installation key to e-mail
  17. 1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX
  18. Ooops, your important files are encrypted.
  19. If you see this text, then your files are no longer accessible, because
  20. they have been encrypted. Perhaps you are busy looking for a way to recover
  21. your files, but don't waste your time. Nobody can recover your files without
  22. our decryption service.
  23. We guarantee that you can recover all your files safely and easily.
  24. All you need to do is submit the payment and purchase the decryption key.
  25. Please follow the instructions:
  26. Send $300 worth of Bitcoin to following address:
  27. Does not encrypt files in this folder:
  28.  
  29. C:\Windows;
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement