SATANA RANSOMWARE


SATANA Trojan encrypts files and corrupts windows Master Boot Record (MBR) thus blocking the Windows boot process. SATANA behaves quite similarly like the notorious PetyaRansomware.


Image Source


To encrypt PC files, PETYA relies on the help of a tagalong Trojan called Mischa, while SATANA manages tasks on its own.

Once the ransomware start running it disappears, and hides under a different name in the %TEMP% folder. Then after it will always prompt the user to download a malicious file until they click yes. Once the action starts, the malicious code will be written to the beginning of disk.

After it installs and runs its malicious code, SATANA then waits for the computer to reboot.
But the system won’t start instead it will show a screen with the ransom note, like most ransomware.

Comments

Popular posts from this blog

WANNACRY RANSOMWARE