

{"id":913,"date":"2017-10-25T19:39:58","date_gmt":"2017-10-25T19:39:58","guid":{"rendered":"https:\/\/warp.lacnic.net\/?p=913"},"modified":"2017-10-25T19:39:58","modified_gmt":"2017-10-25T19:39:58","slug":"badrabbit-ransomware","status":"publish","type":"post","link":"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware","title":{"rendered":"BadRabbit Ransomware"},"content":{"rendered":"<p>El d\u00eda 24 de Octubre de 2017 se di\u00f3 a conocer un incidente de ciberseguridad del cual fueron v\u00edctimas algunas organizaciones en ciertos pa\u00edses del mundo, Russia, Ukraine, Bulgaria, and Turkey.<\/p>\n<p>Esta vez se trata de un ataque de un nuevo ransomware, llamado BadRabbit. El mismo, utiliza m\u00faltiples vectores de ataque, siendo SMB s\u00f3lo uno de ellos. No se detect\u00f3 el C&amp;C, luego de la infecci\u00f3n, la v\u00edctima no se conecta con el atacante<\/p>\n<p>El malware fue enviado a trav\u00e9s de una actualizaci\u00f3n falsa de Adobe Flash.<\/p>\n<p>A la fecha de este reporte, se sabe que el sitio desde donde se descargaba el mismo fue dado de baja pero no se conoce ninguna herramienta para el descifrado de los archivos afectados.<br \/>\nEs importante tener en cuenta que a\u00fan los sistemas actualizados correctamente pueden verse afectados por este problema.<\/p>\n<p>Denominaciones posibles Win32\/Diskcoder.D (ESET), Trojan-Ransom.Win32.Gen.ftl (Kaspersky), Win32\/Tibbar.A (Microsoft), Troj\/Ransom-ERK (Sophos)<\/p>\n<p><b>Sistema afectado<\/b> Windows XP &#8211; Windows 10.<\/p>\n<p>El Antivirus Windows Defender, con versi\u00f3n de actualizaci\u00f3n 1.255.29.0 o mayor, detecta y elimina esta amenza. (<a href=\"https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia- description?Name=Ransom:Win32\/Tibbar.A\">https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia- description?Name=Ransom:Win32\/Tibbar.A<\/a>)<br \/>\nDada la criticidad, se recomienda aplicar los parches de seguridad de forma urgente.<\/p>\n<h3>Recomendaciones<\/h3>\n<h4>Prevenci\u00f3n<\/h4>\n<ul>\n<li>Actualizar los sistemas<\/li>\n<li>Realizar respaldos y mantenerlos al d\u00eda<\/li>\n<li>No exponer el protocolo SMB hacia fuera de la red. Bloquear puerto 445 protocolo TCP<\/li>\n<li>Deshabilitar SMBv1<\/li>\n<li>No correr procesos con privilegios de administrador si no es necesario<\/li>\n<li>Deshabilitar WMIC (Windows Management Instrumentation Command-line) si no se utiliza<\/li>\n<li>Evitar abrir archivos y\/o links de fuentes desconocidas ya sea recibidos por correo electr\u00f3nico o descargados de sitios web no confiables<\/li>\n<\/ul>\n<h4>Recuperaci\u00f3n<\/h4>\n<ul>\n<li>Puede recuperar sus sistemas desde los respaldos. Si los mismos no estuvieran disponibles, podr\u00eda intentar su recuperaci\u00f3n mediante el uso de Shadow Recover. En el siguiente link podr\u00e1 encontrar una gu\u00eda: <a href=\"https:\/\/www.bleepingcomputer.com\/tutorials\/how-to-recover-files-and-folders-using-shadow-volume- copies\/\">https:\/\/www.bleepingcomputer.com\/tutorials\/how-to-recover-files-and-folders-using-shadow-volume- copies\/<\/a><\/li>\n<li>Si el sistema es apagado antes de su reinicio se podr\u00eda reestablecer el MBR con el comando &#8220;bootrec \/FixMbr&#8221; (Vista+, Windows XP &#8220;fixmbr&#8221;)<\/li>\n<\/ul>\n<h3>Vacuna<\/h3>\n<p>El proceso de cifrado puede prevenirse mediante la creaci\u00f3n de 2 archivos de s\u00f3lo lectura llamados \u201ccscc.dat\u201d e \u201cinfpub.dat\u201d en %windir%. Cybereason ofrece una descripci\u00f3n de c\u00f3mo puede realizarse esto en forma manual: <a href=\"https:\/\/www.cybereason.com\/blog\/cybereason-researcher-discovers-vaccine-for-badrabbit-ransomware\">https:\/\/www.cybereason.com\/blog\/cybereason-researcher-discovers-vaccine-for-badrabbit-ransomware<\/a><br \/>\nActualizaciones disponibles<br \/>\nMS17-010 (ETERNALBLUE and ETERNALROMANCE) del 14 de Marzo: <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx<\/a><\/p>\n<p>Microsoft tambi\u00e9n divulg\u00f3 un parche para las versiones viejas de Windows el 12 de Mayo: <a href=\"https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks\/\">https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>El d\u00eda 24 de Octubre de 2017 se di\u00f3 a conocer un incidente de ciberseguridad del cual fueron v\u00edctimas algunas organizaciones en ciertos pa\u00edses del mundo, Russia, Ukraine, Bulgaria, and Turkey. Esta vez se trata de un ataque de un nuevo ransomware, llamado BadRabbit. El mismo, utiliza m\u00faltiples vectores de ataque, siendo SMB s\u00f3lo uno [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[46,18,24],"tags":[],"class_list":["post-913","post","type-post","status-publish","format-standard","hentry","category-archive","category-news","category-security-alerts"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>LACNIC CSIRT - BadRabbit Ransomware<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"LACNIC CSIRT - BadRabbit Ransomware\" \/>\n<meta property=\"og:description\" content=\"El d\u00eda 24 de Octubre de 2017 se di\u00f3 a conocer un incidente de ciberseguridad del cual fueron v\u00edctimas algunas organizaciones en ciertos pa\u00edses del mundo, Russia, Ukraine, Bulgaria, and Turkey. Esta vez se trata de un ataque de un nuevo ransomware, llamado BadRabbit. El mismo, utiliza m\u00faltiples vectores de ataque, siendo SMB s\u00f3lo uno [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware\" \/>\n<meta property=\"og:site_name\" content=\"LACNIC CSIRT\" \/>\n<meta property=\"article:published_time\" content=\"2017-10-25T19:39:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/csirt.lacnic.net\/wp-content\/uploads\/lacnic-csirt-2020.png\" \/>\n\t<meta property=\"og:image:width\" content=\"680\" \/>\n\t<meta property=\"og:image:height\" content=\"330\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"staffadmin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@lacnic_csirt\" \/>\n<meta name=\"twitter:site\" content=\"@lacnic_csirt\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/news\\\/badrabbit-ransomware#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/news\\\/badrabbit-ransomware\"},\"author\":{\"name\":\"staffadmin\",\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/#\\\/schema\\\/person\\\/6515878a80d7f33d87c848ee36332423\"},\"headline\":\"BadRabbit Ransomware\",\"datePublished\":\"2017-10-25T19:39:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/news\\\/badrabbit-ransomware\"},\"wordCount\":445,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/#organization\"},\"articleSection\":[\"Archive\",\"News\",\"Security Alerts\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/news\\\/badrabbit-ransomware#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/news\\\/badrabbit-ransomware\",\"url\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/news\\\/badrabbit-ransomware\",\"name\":\"LACNIC CSIRT - BadRabbit Ransomware\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/#website\"},\"datePublished\":\"2017-10-25T19:39:58+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/news\\\/badrabbit-ransomware#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/news\\\/badrabbit-ransomware\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/news\\\/badrabbit-ransomware#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"BadRabbit Ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/\",\"name\":\"LACNIC CSIRT\",\"description\":\"Incident Response Center - LACNIC CSIRT\",\"publisher\":{\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/#organization\",\"name\":\"LACNIC CSIRT\",\"url\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/csirt.lacnic.net\\\/wp-content\\\/uploads\\\/lacnic-csirt-2020.png\",\"contentUrl\":\"https:\\\/\\\/csirt.lacnic.net\\\/wp-content\\\/uploads\\\/lacnic-csirt-2020.png\",\"width\":680,\"height\":330,\"caption\":\"LACNIC CSIRT\"},\"image\":{\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/lacnic_csirt\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/#\\\/schema\\\/person\\\/6515878a80d7f33d87c848ee36332423\",\"name\":\"staffadmin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/de0c6fd2fb1bac54ad75003cf602dae06bf1d694dfd6c6699f1ef567587f8c0d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/de0c6fd2fb1bac54ad75003cf602dae06bf1d694dfd6c6699f1ef567587f8c0d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/de0c6fd2fb1bac54ad75003cf602dae06bf1d694dfd6c6699f1ef567587f8c0d?s=96&d=mm&r=g\",\"caption\":\"staffadmin\"},\"url\":\"https:\\\/\\\/csirt.lacnic.net\\\/en\\\/author\\\/staffadmin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"LACNIC CSIRT - BadRabbit Ransomware","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware","og_locale":"en_US","og_type":"article","og_title":"LACNIC CSIRT - BadRabbit Ransomware","og_description":"El d\u00eda 24 de Octubre de 2017 se di\u00f3 a conocer un incidente de ciberseguridad del cual fueron v\u00edctimas algunas organizaciones en ciertos pa\u00edses del mundo, Russia, Ukraine, Bulgaria, and Turkey. Esta vez se trata de un ataque de un nuevo ransomware, llamado BadRabbit. El mismo, utiliza m\u00faltiples vectores de ataque, siendo SMB s\u00f3lo uno [&hellip;]","og_url":"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware","og_site_name":"LACNIC CSIRT","article_published_time":"2017-10-25T19:39:58+00:00","og_image":[{"width":680,"height":330,"url":"https:\/\/csirt.lacnic.net\/wp-content\/uploads\/lacnic-csirt-2020.png","type":"image\/png"}],"author":"staffadmin","twitter_card":"summary_large_image","twitter_creator":"@lacnic_csirt","twitter_site":"@lacnic_csirt","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware#article","isPartOf":{"@id":"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware"},"author":{"name":"staffadmin","@id":"https:\/\/csirt.lacnic.net\/en\/#\/schema\/person\/6515878a80d7f33d87c848ee36332423"},"headline":"BadRabbit Ransomware","datePublished":"2017-10-25T19:39:58+00:00","mainEntityOfPage":{"@id":"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware"},"wordCount":445,"commentCount":0,"publisher":{"@id":"https:\/\/csirt.lacnic.net\/en\/#organization"},"articleSection":["Archive","News","Security Alerts"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware#respond"]}]},{"@type":"WebPage","@id":"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware","url":"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware","name":"LACNIC CSIRT - BadRabbit Ransomware","isPartOf":{"@id":"https:\/\/csirt.lacnic.net\/en\/#website"},"datePublished":"2017-10-25T19:39:58+00:00","breadcrumb":{"@id":"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/csirt.lacnic.net\/en\/news\/badrabbit-ransomware#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/csirt.lacnic.net\/en"},{"@type":"ListItem","position":2,"name":"BadRabbit Ransomware"}]},{"@type":"WebSite","@id":"https:\/\/csirt.lacnic.net\/en\/#website","url":"https:\/\/csirt.lacnic.net\/en\/","name":"LACNIC CSIRT","description":"Incident Response Center - LACNIC CSIRT","publisher":{"@id":"https:\/\/csirt.lacnic.net\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/csirt.lacnic.net\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/csirt.lacnic.net\/en\/#organization","name":"LACNIC CSIRT","url":"https:\/\/csirt.lacnic.net\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/csirt.lacnic.net\/en\/#\/schema\/logo\/image\/","url":"https:\/\/csirt.lacnic.net\/wp-content\/uploads\/lacnic-csirt-2020.png","contentUrl":"https:\/\/csirt.lacnic.net\/wp-content\/uploads\/lacnic-csirt-2020.png","width":680,"height":330,"caption":"LACNIC CSIRT"},"image":{"@id":"https:\/\/csirt.lacnic.net\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/lacnic_csirt"]},{"@type":"Person","@id":"https:\/\/csirt.lacnic.net\/en\/#\/schema\/person\/6515878a80d7f33d87c848ee36332423","name":"staffadmin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/de0c6fd2fb1bac54ad75003cf602dae06bf1d694dfd6c6699f1ef567587f8c0d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/de0c6fd2fb1bac54ad75003cf602dae06bf1d694dfd6c6699f1ef567587f8c0d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/de0c6fd2fb1bac54ad75003cf602dae06bf1d694dfd6c6699f1ef567587f8c0d?s=96&d=mm&r=g","caption":"staffadmin"},"url":"https:\/\/csirt.lacnic.net\/en\/author\/staffadmin"}]}},"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/csirt.lacnic.net\/en\/wp-json\/wp\/v2\/posts\/913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/csirt.lacnic.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/csirt.lacnic.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/csirt.lacnic.net\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/csirt.lacnic.net\/en\/wp-json\/wp\/v2\/comments?post=913"}],"version-history":[{"count":0,"href":"https:\/\/csirt.lacnic.net\/en\/wp-json\/wp\/v2\/posts\/913\/revisions"}],"wp:attachment":[{"href":"https:\/\/csirt.lacnic.net\/en\/wp-json\/wp\/v2\/media?parent=913"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/csirt.lacnic.net\/en\/wp-json\/wp\/v2\/categories?post=913"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/csirt.lacnic.net\/en\/wp-json\/wp\/v2\/tags?post=913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}