Ransomware Analysis and Defense-WannaCry and the Win32 environment

Volume: 6 Number: 4 December 1, 2017
  • Justin Jones

Ransomware Analysis and Defense-WannaCry and the Win32 environment

Abstract

Ransomware is a specific type of malware that threatens the victim’s access to her data unless a ransom is paid. Itis also known as a cryptovirus due to its method of operation. Typically, ransomware encrypts the contents of the victim’s hard drive thereby rendering it inaccessible to the victim. Upon payment of the ransom, the decryption key is released to the victim.This is therefore also called cryptoviral extortion. The ransomware itslef is delivered to the victim using several channels. The mostcommon channel of delivery is by masquerading the malware as a trojan horse via an email attachment. In this paper, we study ahigh-profile example of a ransomware called the WannaCry worm. This ransomware is particularly malicious since it had the ability to traverse computing equipment on a network without any human intervention. To better understand the inner workings of thishigh-profile ransomware, we obtain a sample of WannaCry and dissect it completely using advanced static and dynamic malwareanalysis techniques. This effort, we hope, will shed light on the inner workings of the malware and will enable cyber security expertsto better thwart similar attacks in the future. Our analysis is conducted in a Win32 environment and we present our detailed analysisso as to enable reproduction of our work by other malware analysts. Lastly, we present a protoype software that will enable a userto prevent this malware from unleashing its payload and protect the user on a Win32 environment.

Keywords

References

  1. [1] Chen, Q. and Bridges, R. A. (2017). Automated behavioral analysis of malware a case study of wannacry ransomware. arXiv preprint arXiv:1709.08753.
  2. [2] Filiol, E. and Raynal, F. (2008). Malicious cryp- ´ tography... reloaded. In CanSecWest Conference, Vancouver, Canada.[online] http://cansecwest. com/csw08/csw08-raynal. pdf.
  3. [3] Kumar, S. M. and Kumar, M. R. (2013). Cryptoviral extortion: A virus based approach. International Journal of Computer Trends and Technology (IJCTT), 4(5):1149–1153.
  4. [4] McCormack, M. (1996). Europe hit by cryptoviral extortion. Computer Fraud & Security, 6(1996):3.
  5. [5] Pascariu, C., BARBU, I.-D., and Bacivarov, I. C. (2017). Investigative analysis and technical overview of ransomware based attacks. case study: Wannacry. Int’l J. Info. Sec. & Cybercrime, 6:57.
  6. [6] Salvi, M. H. U. and Kerkar, M. R. V. (2016). Ransomware: A cyber extortion. Asian Journal of Convergence in Technology, 2(2).
  7. [7] Young, A. L. (2006). Cryptoviral extortion using microsoft’s crypto api. International Journal of Information Security, 5(2):67–76.
  8. [8] Young, A. L. and Yung, M. (2017). Cryptovirology: The birth, neglect, and explosion of ransomware. Communications of the ACM, 60(7):24–26.

Details

Primary Language

English

Subjects

-

Journal Section

-

Authors

Justin Jones This is me

Publication Date

December 1, 2017

Submission Date

-

Acceptance Date

-

Published in Issue

Year 2017 Volume: 6 Number: 4

APA
Jones, J. (2017). Ransomware Analysis and Defense-WannaCry and the Win32 environment. International Journal of Information Security Science, 6(4), 57-69. https://izlik.org/JA23JU76HM
AMA
1.Jones J. Ransomware Analysis and Defense-WannaCry and the Win32 environment. IJISS. 2017;6(4):57-69. https://izlik.org/JA23JU76HM
Chicago
Jones, Justin. 2017. “Ransomware Analysis and Defense-WannaCry and the Win32 Environment”. International Journal of Information Security Science 6 (4): 57-69. https://izlik.org/JA23JU76HM.
EndNote
Jones J (December 1, 2017) Ransomware Analysis and Defense-WannaCry and the Win32 environment. International Journal of Information Security Science 6 4 57–69.
IEEE
[1]J. Jones, “Ransomware Analysis and Defense-WannaCry and the Win32 environment”, IJISS, vol. 6, no. 4, pp. 57–69, Dec. 2017, [Online]. Available: https://izlik.org/JA23JU76HM
ISNAD
Jones, Justin. “Ransomware Analysis and Defense-WannaCry and the Win32 Environment”. International Journal of Information Security Science 6/4 (December 1, 2017): 57-69. https://izlik.org/JA23JU76HM.
JAMA
1.Jones J. Ransomware Analysis and Defense-WannaCry and the Win32 environment. IJISS. 2017;6:57–69.
MLA
Jones, Justin. “Ransomware Analysis and Defense-WannaCry and the Win32 Environment”. International Journal of Information Security Science, vol. 6, no. 4, Dec. 2017, pp. 57-69, https://izlik.org/JA23JU76HM.
Vancouver
1.Justin Jones. Ransomware Analysis and Defense-WannaCry and the Win32 environment. IJISS [Internet]. 2017 Dec. 1;6(4):57-69. Available from: https://izlik.org/JA23JU76HM