Looks like someone took the text from the standard disk check warning and put it on the standard 80x25 text mode. Ransomware?
-
-
Looks like a new variant of Petya ransomware
2 replies 4 retweets 12 likes -
Replying to @PolarToffee @usr_local_share and
My first thought as well - may be PetrWrap, or another, new, derivative of Petya. https://securelist.com/petrwrap-the-new-petya-based-ransomware-used-in-targeted-attacks/77762/ …
1 reply 0 retweets 3 likes -
Replying to @bartblaze @usr_local_share and
Agreed. Either way, it's almost certainly based on the code of the Petya family of ransomware.
2 replies 0 retweets 1 like -
Replying to @PolarToffee @usr_local_share and
Indeed. Let's wait and see for confirmation, and hopefully they'll have backups!
1 reply 0 retweets 1 like -
Replying to @bartblaze @PolarToffee and
same BTC address for every message i've seen in 6 different countries
1 reply 0 retweets 0 likes -
Replying to @MalwareAnalyzer @PolarToffee and
Which other countries are those?
1 reply 0 retweets 0 likes
so far we have Russian (oil), Ukraine (bank and others), India (shipping), Denmark (part of India shipping co), UK, Spain
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.