NotPetya Returns as Bad Rabbit

October 25, 2017

Written by

Jay Rosenberg

Large scale cyber attacks seem to be happening once a month these days. Originally discovered by ESET, Ukrainian and Russian organizations have been hit with the latest ransomware attack named Bad Rabbit. At the time of writing this post, the ransomware has believed to have originated from compromised webpages with a fake popup for updating Adobe Flash Player. It has been reported that much of the behavior of Bad Rabbit has been similar to a previous ransomware known as NotPetya.

Large scale cyber attacks

Screenshot from ESET report, after ransomware has infected a computer

Using Intezer Analyze™, we have found code reuse from NotPetya throughout different binaries of Bad Rabbit.

The Bad Rabbit loader, with the original name (install_flash_player.exe) and metadata (Adobe Systems Incorporated as the company and Adobe Flash Player Installer/Uninstaller), was made to look like the Adobe Flash Player installer. You can see in the screenshot below that according to our analysis, the binary did not contain any code from any Adobe product but does contain code from NotPetya. In fact, we find that 27% of the code in the loader has been seen in only NotPetya samples.

Using Intezer Analyze

Below is a direct comparison of function (0x1000C244) of NotPetya (027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745) and function (0x4033B4) of the Bad Rabbit loader (630325cac09ac3fab908f903e3b00d0dadd5fdaa0875ed8496fcbb97a558d0da).

Comparison of a NotPetya function with the Bad Rabbit loader

Another example of code reuse in the loader from a function that seems to initialize some type of struct.

Another example of code reuse in the Bad Rabbit loader

#BadRabbit (#NotPetya v2) unpacked DLL: infpub.dat

— hasherezade (@hasherezade) October 24, 2017

The final module that gets loaded and is responsible for encrypting the files on disk (579fd8a0385482fb4c789561a30b09f25671e86422f40ef5cca2036b28f99648) also has a code connection with NotPetya samples. According to our technology, we can see that 13% of the code has been reused.

#badrabbit found to have 13% code reuse of #notpetya #petya — here's a public report with the unpacked sample

— Jay Rosenberg (@jaytezer) October 24, 2017

Code reuse between Bad Rabbit and NotPetya

Below is a screenshot comparing a function (0x1000777B) of NotPetya (027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745) and a function (0x1000733C) of the encryptor module of Bad Rabbit (579fd8a0385482fb4c789561a30b09f25671e86422f40ef5cca2036b28f99648).

Matching function between NotPetya and the Bad Rabbit encryptor module

The next screenshot is of another matching function between the two samples.

Another matching function between the two samples

As you can see in this attack, and in many other cases, malware authors constantly reuse their code. By recognizing code reuse, you force malware authors to rewrite code and come up with new techniques to avoid detection. This changes the playing field and makes it far less cost effective for malware authors and cyber crime organizations.

IOCs

630325cac09ac3fab908f903e3b00d0dadd5fdaa0875ed8496fcbb97a558d0da
8ebc97e05c8e1073bda2efb6f4d00ad7e789260afa2c276f0c72740b838a0a93
579fd8a0385482fb4c789561a30b09f25671e86422f40ef5cca2036b28f99648

Jay Rosenberg

In this article

Share article

Related Articles

Research

5 min

NinjaMare and the enterprise security epidemic hiding behind a harmless label

The PUA label, aka "potentially unwanted application" means nuisance. Adware, toolbars, and other things that change your settings without asking. Our research team's findings say this label is far more serious than a mere nuisance.

‍

Alert Triage

AI SOC

3 min

We let a fruit fly brain triage 12,716 real SOC Alerts. Here is what happened.

On behalf of people who run SOCs, we explore how a fly brain triages alerts compared with a boring linear model you could train in eleven seconds.

‍

AI SOC

4 min

The impact of the AI SOC: Intezer joins the Cybersecurity Awesomeness Podcast

Intezer's Field CISO and CMO join the Cybersecurity Awesomeness Podcast to explain what the AI SOC is, how it cuts false positives, and why analysts end up more empowered.

‍