Jump to content
UnixDevel

A TECHNICAL ANALYSIS OF THE BACKMYDATA RANSOMWARE USED TO ATTACK HOSPITALS IN ROMANIA

Recommended Posts

Posted

Summary

According to BleepingComputer, a ransomware attack that occurred starting 0n February 11 forced 100 hospitals across Romania to take their systems offline. BackMyData ransomware, which took credit for it, belongs to the Phobos family. The malware embedded an AES key that is used to decrypt its configuration containing whitelisted extensions, files, and directories, a public RSA key that is used to encrypt AES keys used for files’ encryption, and other information. Persistence is achieved by creating an entry under the Run registry key and copying the malware to the Startup folder. The ransomware encrypts the local drives as well as the network shares. It deletes all Volume Shadow Copies and runs commands to disable the firewall.

Full Article

https://cybergeeks.tech/a-technical-analysis-of-the-backmydata-ransomware-used-to-attack-hospitals-in-romania/

  • Upvote 1
Posted
1 hour ago, UnixDevel said:

Persistence is achieved by creating an entry under the Run registry key and copying the malware to the Startup folder

Hardcore malware, 2002. 

  • Haha 1
Posted

Am inteles de la niste cunostinte ca e plin de win7 si xp...mai ales la cabinetele mai mici, dispensare de comuna si tot asa. evident fara AD, userul e si admin.

 

long live cloudul guvernamental.

Posted

Din punctul meu de vedere poate sa fie si Windows 95 cat timp e patched pentru RCE sau nu e expus in Internet si cine are grija de ele nu descarca Midget_Porn.avi.exe 

Principiul KISS (Keep It Simple Stupid) ar ajuta destul de mult, dar la noi nu e nici macar awareness.

  • Upvote 1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...