The M.E.Doc Backdoor Behind NotPetya

Updated 5 Oct 2026 · Incident date 22 Jun 2017 · vendor binary

PackageM.E.Doc 10.01.188 -> 10.01.189 (earlier backdoored updates 10.01.176 on 14 Apr 2017 and 10.01.181 on 15 May 2017)
FileZvitPublishedObjects.dll

Three updates of the Ukrainian accounting software M.E.Doc carried a backdoor in ZvitPublishedObjects.dll. They are 10.01.175 to 10.01.176 on 14 April 2017, 10.01.180 to 10.01.181 on 15 May 2017, and 10.01.188 to 10.01.189 on 22 June 2017.

The attackers used the backdoor to deliver the XData and NotPetya ransomware.

Major incident. Microsoft observed infections in Ukraine and another 64 countries after the NotPetya outbreak. Impact source

What happened

The update servers of the vendor, Intellect Service, delivered the backdoored DLL as a normal update. BleepingComputer reports that a Ukrainian official said the vendor had installed no updates on the affected servers since February 2013. Ukrainian police seized the vendor's servers on 4 July 2017 and stopped a second attack wave that had started.

ESET analyzed the DLL. It is a 5 MB .NET file, and the backdoor class is named MeCom. The backdoor collected:

It saved them in the registry under HKEY_CURRENT_USER\SOFTWARE\WC, in values named Cred and Prx. It talked to the vendor's update host, upd.me-doc.com.ua, and hid its data in HTTP cookies, so no separate command server was needed. It had six commands, including shell execution, file extraction, system reconnaissance and running a DLL through rundll32.exe.

Affected versions

ESET and BleepingComputer name three backdoored update ranges.

The 22 June update came days before the NotPetya outbreak on 27 June. Updates before April 2017 were clean.

Indicators of compromise

How to check

Hash the DLL in the M.E.Doc folder and compare it with the SHA-1 values above.

Get-ChildItem -Path C:\ -Recurse -Filter ZvitPublishedObjects.dll -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA1

Then check for the registry key that the backdoor used.

reg query HKCU\SOFTWARE\WC

What to do now

  1. Isolate any machine with a matching hash or the registry key.
  2. Change the email and proxy credentials the backdoor could read.
  3. Check the machine for the ransomware and for other tools that were delivered.
  4. Restore from a backup made before the first bad update, 14 April 2017, where you need a clean state.
  5. Take any software update channel into account in your network design. Limit what the accounting host can reach.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here an existing DLL gained credential reading, command traffic and payload execution. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old M.E.Doc-10.01.188 --new M.E.Doc-10.01.189
files scanned: 81

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    ZvitPublishedObjects.dll
           It now downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which M.E.Doc versions were backdoored?

Updates 10.01.175 to 10.01.176 (14 April 2017), 10.01.180 to 10.01.181 (15 May 2017) and 10.01.188 to 10.01.189 (22 June 2017).

How do I check for the M.E.Doc backdoor?

Hash ZvitPublishedObjects.dll and compare it with the SHA-1 values published by ESET. Also check for the registry key HKCU\SOFTWARE\WC.

Sources

  1. welivesecurity.com/2017/07/04/analysis-of-telebots-cunning-backdoor/
  2. bleepingcomputer.com/news/security/m-e-doc-software-was-backdoored-3-times-servers-left-without-updates-since-2013/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free