Cyber Alerts
Bad Rabbit Ransomware - Technical Analysis
On Oct 24, 2017, a few organisation in Ukraine, Russia, Turkey and Germany had reported of disruptions attributing to ransomware. Based on initial information received, a new variant of WannaCry and NotPetya ransomware known as Bad Rabbit are responsible for the incidents. Further analysis of the ransomware has been carried out and details of the ransomware is explained below. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.
- First observed
- 25 Oct 2017
- Last checked
- 31 Jul 2026
- Evidence records
- 1
- Publication state
- Published
What happened?
Current assessment
On Oct 24, 2017, a few organisation in Ukraine, Russia, Turkey and Germany had reported of disruptions attributing to ransomware. Based on initial information received, a new variant of WannaCry and NotPetya ransomware known as Bad Rabbit are responsible for the incidents. Further analysis of the ransomware has been carried out and details of the ransomware is explained below. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.
Why it matters
Encrypt user files and demand ransom to decrypt the files for 0.05 worth of Bitcoin.
Who is affected?
Affected products and groups
- Software: All Windows Operating System
What should you do now?
Actions from official guidance
For technical teams
- Patch your Windows Operating System with MS17-010 Microsoft Security bulletin; Patch your computers with the latest Windows Security Updates. Users are strongly recommended to turn on the 'Automatic Updates' features in Windows OS to ensure that security patches and updates are applied as soon as they are released; Back up your important files and data to an external drive; Update and run your computer with antivirus that has the latest anti-malware signatures; Block SMB ports (139, 445) from all accessible hosts. If the SMB service is required, please ensure that the required patch (MS17-010) has been applied; Update Windows Defender with the latest update from Microsoft; To prevent getting infected by Bad Rabbit, users are advised to create these two files in C:\windows and remove all permissions - C:\windows\infpub.dat and C:\windows\cscc.dat Advise your users not to click any popup window regarding updating Adobe Flash without informing the IT department; Report any incidents related to this attack to NC4. Official source
- First published : 26 Oct 2017 Official source
Which sources support it?
Evidence and official sources
-
NACSA / NC4 Alerts and AdvisoriesOfficial sourceBad Rabbit Ransomware - Technical Analysis
On Oct 24, 2017, a few organisation in Ukraine, Russia, Turkey and Germany had reported of disruptions attributing to ransomware. Based on initial information received, a new variant of WannaCry and NotPetya ransomware known as Bad Rabbit are responsible for the incidents. Further analysis of the ransomware has been carried out and details of the ransomware is explained below. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.
Published 25 Oct 2017 · Retrieved 31 Jul 2026