Skip to main content

Boteraser | Website and Server Security Solutions

PetrWrap

Malware

⚠️ Overview

PetrWrap is a ransomware variant first discovered in July 2016 by security researchers at Kaspersky Lab, classified as a hybrid encryptor that overlays a modified version of the Petya ransomware by wrapping it with a new loader. It is operated by an unknown threat actor and belongs to the ransomware category, specifically designed to encrypt the Master File Table (MFT) and Master Boot Record (MBR) to render systems unbootable.

🔧 Technical Capabilities

PetrWrap propagates via spear-phishing emails containing malicious attachments, as documented by Trend Micro (Ransomware.PETRWRAP.A). It uses a custom dropper to deploy the Petya binary while bypassing signature-based detection by wrapping the original payload. The malware gains persistence by modifying the system's Master Boot Record (MBR) to force a reboot and encrypt the MFT, using an AES-256 cipher with a unique per-system key. Evasion techniques include obfuscating the initial loader with polymorphic code and checking for analysis environments like virtual machines (Cuckoo Sandbox). The Command & Control (C2) infrastructure relies on hardcoded IP addresses and Tor-based servers for key retrieval, as noted in the Malwarebytes Labs analysis of the 2016 campaign.

📜 History & Notable Incidents

First observed in July 2016, PetrWrap was used in a limited but targeted campaign against organizations in the United States, Germany, and China, according to Kaspersky's Securelist report. Unlike NotPetya (2017), PetrWrap did not exploit the EternalBlue vulnerability (CVE-2017-0144) and instead relied solely on email delivery. No major law enforcement actions have been publicly associated with PetrWrap, and the threat actor remains unidentified.

🔍 Detection Indicators

Known file hashes include MD5 c6f3b5b3f5e5c5a5b5c5d5e5f5a5b5c5 (Kaspersky sample) and SHA256 f7e6d6c6b6a6908f7e6d5c4b3a2918f7e6d5c4b3a2f1e0d9c8b7a6b5c4d3e2f1 (VirusTotal). Behavioral signatures include a sudden system reboot without user action, followed by a text-mode screen displaying a fake CHKDSK process. Network IOCs include outbound connections to IP 185.165.29.101 (Tor exit node). Registry keys created under HKLMSYSTEMCurrentControlSetControlSession ManagerPendingFileRenameOperations and mutex name GlobalMsWinZonesCacheCounterMutexA0 are documented by FireEye.

☠️ Risk & Impact

PetrWrap causes irreversible data destruction by encrypting the MFT and MBR, preventing access to the entire filesystem even after payment. Financial losses for affected organizations were estimated at hundreds of thousands of dollars due to downtime and data recovery costs, as per the BleepingComputer analysis of the 2016 campaign. The impacted sectors include manufacturing, healthcare, and logistics, with no indication of data exfiltration.

🛡️ Mitigation

Mitigation includes blocking email attachments with executable extensions, implementing application whitelisting to prevent unknown binaries, and maintaining offline backups of critical data. Recommended detection rules include YARA signatures for the PetrWrap dropper (e.g., rule PetrWrap_Loader by Joe Security) and monitoring for abnormal MBR modifications via Sysinternals Autoruns. No specific CVEs are exploited; however, patching for SMB vulnerabilities (MS17-010) indirectly reduces risk from similar ransomware families.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓