Anatova Ransomware
First observed in January 2018, Anatova is a ransomware tool targeting users throughout Western Europe and the USA. In active development, the tool appears to have additional function modules, although they do not appear to be activated.
Summary
First observed in January 2018, Anatova is a ransomware tool targeting users throughout Western Europe and the USA. In active development, the tool appears to have additional function modules, although they do not appear to be activated.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it appears Antova is delivered disguised as legitimate applications via peer-to-peer networks . Once installed, it will perform a check to verify if it is running on a virtual machine and will delete itself if this is the case. It also uses several other techniques, including string encryption and dynamic calling, to prevent analysis.
Antova will then encrypt all non-system files smaller than 1MB on local and network drives using the Salsa20 algorithm, before deleting any Volume Shadow Copies to prevent recovery. Unlike most ransomware, Anatova will not append a new extension to encrypted files, making it difficult to identify them. Additional modules included in Antova suggest new functionality will be included in later versions.
Update
A new variant of Anatova has been observed terminating processes during encryption. The variant uses the OpenProcess and TerminateProcess APIs to identify and terminate processes matching a hard-coded list.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:49 pm