Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: Tool Released to Decrypt Petya Ransomware Infected Disks SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Tool Released to Decrypt Petya Ransomware Infected Disks

Recently a research who goes by @leo_and_stone has released a tool that will decrypt files on a Petya infected disk.  A long form of the details are available over at BleepingComputer but the short version is that by removing the disk and getting a 512-byte sequence from sector 53 of the disk and an 8-byte none from sector 54.  Then converting this to Base64 you can upload it to to retrieve the key (in most cases in seconds).  Ransomware historically has had problem getting the encryption "correct" to avoid mistakes that allow people to reverse engineer the decryption key and it has happened for several prominent families.  Unfortunately, such successes are usually short-lived as attackers figure out their mistakes (in weeks to a few months, maybe) and adapt.

Many researchers are putting in efforts to disrupt ransomware and expect more of this in these the future.  If you have used this tool, let us know your experiences in the comments.

John Bambenek
bambenek \at\ gmail /dot/ com
Fidelis Cybersecurity


262 Posts
ISC Handler
Apr 11th 2016
8-byte nonce? Oskewowow!

Sign Up for Free or Log In to start participating in the conversation!