- Mar 15, 2017
- 58
In this scenario, the ransomware attack comes over the network via mapped drives. There are two computers involved:
- one running the Satana variant, without any protection installed and having a mapped drive to the second computer;
- the second computer has TEMASOFT Ranstop installed, with protection enabled.
The ransomware sample is a Satana variant (similar to Petya). Virustotal details here: Antivirus scan for 683a09da219918258c58a7f61f7dc4161a3a7a377cf82a31b840baabfb9a4a96 at 2017-03-22 04:54:55 UTC - VirusTotal
Os of both machines is Windows 10.
This use case is important because ransomware loves mapped drives. Most start to encrypt those along with the local drive because they know they are reaching beyond the infected machine. Here are the challenges for the security products in this case:
- one running the Satana variant, without any protection installed and having a mapped drive to the second computer;
- the second computer has TEMASOFT Ranstop installed, with protection enabled.
The ransomware sample is a Satana variant (similar to Petya). Virustotal details here: Antivirus scan for 683a09da219918258c58a7f61f7dc4161a3a7a377cf82a31b840baabfb9a4a96 at 2017-03-22 04:54:55 UTC - VirusTotal
Os of both machines is Windows 10.
This use case is important because ransomware loves mapped drives. Most start to encrypt those along with the local drive because they know they are reaching beyond the infected machine. Here are the challenges for the security products in this case:
- There is no malicious code running on the machine having the anti-ransomware solution installed (on the protected computer);
- The remote encryption started on the infected machine, is carried out on the protected machine by system processes through file operations similar to the ones that are used by employees;
- The infected computer has no protection, meaning that the ransomware attack over the network is persistent and takes place for as long as the ransomware finds files to encrypt and a network connection is available.