A gut feeling of old acquaintances, new tools, and a common battleground
ID: 5a162faf-5d94-44f9-9045-3d76e725adff
STIX ID: report--5a162faf-5d94-44f9-9045-3d76e725adff
Threat Score
80/100
Uploaded: 2026-08-15
Published Date: 2017-06-30
Last Modified Date: 2017-06-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Securelist analysis explores code- and string-level similarities between the ExPetr/NotPetya wiper and BlackEnergy (KillDisk) destructive modules, comparing targeted file-extension lists, recursive file enumeration code, and identifying clustered generic strings (e.g., "ComSpec", "InitiateSystemShutdown") to build a YARA rule that reliably flags both families; the report includes multiple sample hashes and emphasizes the findings are low-confidence for definitive attribution while inviting further research.
