The Annabelle Ransomware Is a Horrific Mess

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
While most ransomware is created to actually generate revenue, some developers create them to show off their "skills". Such is the case with a new ransomware based off of the horror movie franchise Annabelle.

Discovered by security researcher Bart, Annabelle Ransomware includes everything but the kitchen sink when it comes to screwing up a computer. This includes terminating numerous security programs, disabling Windows Defender, turning off the firewall, encrypting your files, trying to spread through USB drives, making it so you can't run a variety of programs, and then to sweeten the pot, it overwrites the master boot record of the infected computer with a silly boot loader.
...
...

The good news is that this ransomware is based off of Stupid Ransomware and is easily decryptable. As it uses a static key, Michael Gillespie was able to update his StupidDecryptor in order to decrypt this variant.

By replacing the MBR, running Rkill in safe mode to clean up the IFEO registry entries, using Michael's decryptor to decrypt the files, and then a few security scans to remove any left overs you shouldbe able to get your computer back to normal.
...

VirusTotal
 
Last edited by a moderator:

Faybert

Level 24
Verified
Top Poster
Well-known
Jan 8, 2017
1,320
Any security software which cannot protect the MBR in 2018 is awful IMO. So some vendors are in the clear but hardly many xD
Security companies live by saying that your AV will detect everything, that you will always be protected against ransomware and etc, but in practice we know that this is not true, so things have to be proven in practice, I've seen many AV detect a sample and after I just renomer it, it did not detect anymore, being that the malicious code is the same but by just having changed the name it seems that it got confused, are unexpected things that can happen with an AV,then it is always valid to test to prove.
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
updated result
VirusTotal

not detecting in VT doesn't mean the AV doesn't detect in real test because the way they provide the engine to VT is different from their own engine
I recently tested Malwarebytes and in VT, it didn't detect the sample (recently updated in <1 minute) but when I scanned with MB in the VM, MB got the signature for it

BD, for example, detected the malware on VT but in the updated system, it couldn't detect by signature
 
Last edited:

Electr0n

Level 4
Verified
Well-known
Feb 19, 2018
182
Any security software which cannot protect the MBR in 2018 is awful IMO. So some vendors are in the clear but hardly many xD

Backups are best defence against ransomwares. There are softwares like MBRwizards which can backup the MBR. Never used it before, but looks like with regular image backups we will have to backup MBR too.
 

BigWrench

Level 19
Verified
Top Poster
Well-known
Apr 13, 2014
928
Sadly.......:( And not sadly.....:)
 

Attachments

  • ScreenShot_20180221211041.png
    ScreenShot_20180221211041.png
    31.4 KB · Views: 378
  • ScreenShot_20180221211528.png
    ScreenShot_20180221211528.png
    53.8 KB · Views: 364
Last edited:

jackuars

Level 28
Verified
Top Poster
Well-known
Jul 2, 2014
1,717
Doesn't the VirusTotal results show that if they will be detected by the signature's and not the other shields that an antivirus has? They could block it on execution if am not wrong? I'd be interested to know if the big names (like Qihoo/WD) in the "did not block" list for this ransomware actually detected and killed it through other shields.
 

Aleeyen

Level 22
Verified
Top Poster
Well-known
Nov 19, 2012
1,121
I think if an AV cannot detect a new threat using its signature but can detect it using its behavior blocker, then its better. That means that even if the signature is not updated by the user then also the user is safe and also the user may be well protected against threats like this in the future. Just my opinion.
 

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
Tested it with 360TS. Not detected on Static scan but blocked on execution. I like to see how it behaves but I got a BSOD 0x0F4 when I allowed the process. There goes my screenshots.


I think if an AV cannot detect a new threat using its signature but can detect it using its behavior blocker, then its better. That means that even if the signature is not updated by the user then also the user is safe and also the user may be well protected against threats like this in the future. Just my opinion.

Kaspersky (see @harlan4096 post) and 360 blocked it even thought it was not detected static scan.
 

jackuars

Level 28
Verified
Top Poster
Well-known
Jul 2, 2014
1,717
Tested it with 360TS. Not detected on Static scan but blocked on execution. I like to see how it behaves but I got a BSOD 0x0F4 when I allowed the process. There goes my screenshots.




Kaspersky (see @harlan4096 post) and 360 blocked it even thought it was not detected static scan.

Thank you WinXPert. So my assumption wasn't wrong. It's not so bad even if they don't record a "GREEN" sign in VT results as long as they do their job. It's wrong to judge the ability of an antivirus from VT results.

Btw can you test it for Windows Defender too?
 

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
Thank you WinXPert. So my assumption wasn't wrong. It's not so bad even if they don't record a "GREEN" sign in VT results as long as they do their job. It's wrong to judge the ability of an antivirus from VT results.

Btw can you test it for Windows Defender too?

Yes I noticed that Qihoo is not included on the list that can detect the malware at the time of testing but it's BB did block the malware.

Test with WD, I'll see what I can do
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top