SYMBOLCOMMON_NAMEaka. SYNONYMS
win.anatova_ransom (Back to overview)

Anatova Ransomware

VTCollection    

Anatova is a ransomware family with the goal of ciphering all the files that it can and then requesting payment from the victim. It will also check if network shares are connected and will encrypt the files on these shares too. The code is also prepared to support modular extensions.

References
2019-01-23 ⋅ Bleeping Computer ⋅ Ionut Ilascu
New Anatova Ransomware Supports Modules for Extra Functionality
Anatova Ransomware
2019-01-22 ⋅ McAfee ⋅ Alexandre Mundo
Happy New Year 2019! Anatova is here!
Anatova Ransomware
Yara Rules
[TLP:WHITE] win_anatova_ransom_auto (20260917 | Detects win.anatova_ransom.)
rule win_anatova_ransom_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.anatova_ransom."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.anatova_ransom"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4989c2 4c89d1 4c89da e8???????? b800000000 4989c1 48b80000000000000000 }
            // n = 7, score = 200
            //   4989c2               | arpl                ax, ax
            //   4c89d1               | dec                 eax
            //   4c89da               | mov                 ecx, dword ptr [ebp - 0x10]
            //   e8????????           |                     
            //   b800000000           | add                 eax, 1
            //   4989c1               | mov                 dword ptr [ebp - 0x68], eax
            //   48b80000000000000000     | jmp    0xab0

        $sequence_1 = { 8885f0feffff b80a000000 8885f1feffff b80e000000 8885f2feffff b80c000000 }
            // n = 6, score = 200
            //   8885f0feffff         | mov                 byte ptr [ebp - 0x29], al
            //   b80a000000           | mov                 eax, 0
            //   8885f1feffff         | mov                 dword ptr [ebp - 0x30], eax
            //   b80e000000           | mov                 eax, dword ptr [ebp - 0x30]
            //   8885f2feffff         | dec                 eax
            //   b80c000000           | mov                 dword ptr [ebp - 0x28], eax

        $sequence_2 = { 4989c2 4c89d1 e8???????? 0fb6c0 888597fdffff 0fb68597fdffff 83f800 }
            // n = 7, score = 200
            //   4989c2               | jmp                 0xbc4
            //   4c89d1               | mov                 eax, dword ptr [ebp - 0x94]
            //   e8????????           |                     
            //   0fb6c0               | dec                 eax
            //   888597fdffff         | arpl                ax, ax
            //   0fb68597fdffff       | dec                 eax
            //   83f800               | mov                 ecx, dword ptr [ebp - 0x30]

        $sequence_3 = { 0f832e000000 e9???????? 8b45ec 4889c1 }
            // n = 4, score = 200
            //   0f832e000000         | mov                 ecx, eax
            //   e9????????           |                     
            //   8b45ec               | jae                 0x30
            //   4889c1               | mov                 eax, dword ptr [ebp - 0x7c]

        $sequence_4 = { 488d05ec570000 48894588 488d05eb570000 48894590 488d05f4570000 48894598 }
            // n = 6, score = 200
            //   488d05ec570000       | lea                 eax, [ebp - 0x20]
            //   48894588             | dec                 ecx
            //   488d05eb570000       | mov                 ecx, eax
            //   48894590             | mov                 eax, 0x8000001
            //   488d05f4570000       | dec                 ecx
            //   48894598             | mov                 eax, eax

        $sequence_5 = { 4989c8 4989c3 488b05???????? 4989c2 4c89d1 4c89da 4c8b1d???????? }
            // n = 7, score = 200
            //   4989c8               | add                 eax, 1
            //   4989c3               | mov                 dword ptr [ebp - 4], eax
            //   488b05????????       |                     
            //   4989c2               | cmp                 eax, 0x10
            //   4c89d1               | jge                 0x181d
            //   4c89da               | mov                 eax, dword ptr [ebp - 4]
            //   4c8b1d????????       |                     

        $sequence_6 = { 488d05d3390000 48898518ffffff 488d05d6390000 48898520ffffff 488d05d4390000 48898528ffffff }
            // n = 6, score = 200
            //   488d05d3390000       | je                  0x6df
            //   48898518ffffff       | dec                 eax
            //   488d05d6390000       | cmp                 eax, 0
            //   48898520ffffff       | je                  0x6d8
            //   488d05d4390000       | dec                 eax
            //   48898528ffffff       | cmp                 eax, 0

        $sequence_7 = { e8???????? 488945d8 488b45e0 4883f800 }
            // n = 4, score = 200
            //   e8????????           |                     
            //   488945d8             | lea                 eax, [0x52d9]
            //   488b45e0             | dec                 ecx
            //   4883f800             | mov                 ebx, eax

        $sequence_8 = { 0fbe01 83f005 8801 ebdb 488b45e8 4989c2 4c89d1 }
            // n = 7, score = 200
            //   0fbe01               | dec                 ecx
            //   83f005               | mov                 ecx, ecx
            //   8801                 | mov                 ecx, dword ptr [ebp - 0x20]
            //   ebdb                 | dec                 eax
            //   488b45e8             | lea                 eax, [0x4f40]
            //   4989c2               | dec                 ecx
            //   4c89d1               | mov                 edx, eax

        $sequence_9 = { 41ffd3 b800000000 4889442428 48b80000000000000000 }
            // n = 4, score = 200
            //   41ffd3               | movzx               eax, al
            //   b800000000           | mov                 eax, 0x8007
            //   4889442428           | dec                 ecx
            //   48b80000000000000000     | mov    edx, eax

    condition:
        7 of them and filesize < 671744
}
Download all Yara Rules