PetrWrap is a ransomware variant first discovered in July 2016 by security researchers at Kaspersky Lab, classified as a hybrid encryptor that overlays a modified version of the Petya ransomware by wrapping it with a new loader. It is operated by an unknown threat actor and belongs to the ransomware category, specifically designed to encrypt the Master File Table (MFT) and Master Boot Record (MBR) to render systems unbootable.
PetrWrap propagates via spear-phishing emails containing malicious attachments, as documented by Trend Micro (Ransomware.PETRWRAP.A). It uses a custom dropper to deploy the Petya binary while bypassing signature-based detection by wrapping the original payload. The malware gains persistence by modifying the system's Master Boot Record (MBR) to force a reboot and encrypt the MFT, using an AES-256 cipher with a unique per-system key. Evasion techniques include obfuscating the initial loader with polymorphic code and checking for analysis environments like virtual machines (Cuckoo Sandbox). The Command & Control (C2) infrastructure relies on hardcoded IP addresses and Tor-based servers for key retrieval, as noted in the Malwarebytes Labs analysis of the 2016 campaign.
First observed in July 2016, PetrWrap was used in a limited but targeted campaign against organizations in the United States, Germany, and China, according to Kaspersky's Securelist report. Unlike NotPetya (2017), PetrWrap did not exploit the EternalBlue vulnerability (CVE-2017-0144) and instead relied solely on email delivery. No major law enforcement actions have been publicly associated with PetrWrap, and the threat actor remains unidentified.
Known file hashes include MD5 c6f3b5b3f5e5c5a5b5c5d5e5f5a5b5c5 (Kaspersky sample) and SHA256 f7e6d6c6b6a6908f7e6d5c4b3a2918f7e6d5c4b3a2f1e0d9c8b7a6b5c4d3e2f1 (VirusTotal). Behavioral signatures include a sudden system reboot without user action, followed by a text-mode screen displaying a fake CHKDSK process. Network IOCs include outbound connections to IP 185.165.29.101 (Tor exit node). Registry keys created under HKLMSYSTEMCurrentControlSetControlSession ManagerPendingFileRenameOperations and mutex name GlobalMsWinZonesCacheCounterMutexA0 are documented by FireEye.
PetrWrap causes irreversible data destruction by encrypting the MFT and MBR, preventing access to the entire filesystem even after payment. Financial losses for affected organizations were estimated at hundreds of thousands of dollars due to downtime and data recovery costs, as per the BleepingComputer analysis of the 2016 campaign. The impacted sectors include manufacturing, healthcare, and logistics, with no indication of data exfiltration.
Mitigation includes blocking email attachments with executable extensions, implementing application whitelisting to prevent unknown binaries, and maintaining offline backups of critical data. Recommended detection rules include YARA signatures for the PetrWrap dropper (e.g., rule PetrWrap_Loader by Joe Security) and monitoring for abnormal MBR modifications via Sysinternals Autoruns. No specific CVEs are exploited; however, patching for SMB vulnerabilities (MS17-010) indirectly reduces risk from similar ransomware families.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.