首页> 外文期刊>Computers & Security >Avaddon ransomware: An in-depth analysis and decryption of infected systems
【24h】

Avaddon ransomware: An in-depth analysis and decryption of infected systems

机译:Avaddon Ransomware:深入分析和解密的受感染系统

获取原文
获取原文并翻译 | 示例

摘要

Malware is an emerging and popular threat flourishing in the underground economy. The commoditization of Malware-as-a-Service (MaaS) allows criminals to obtain financial benefits at a low risk and with little technical background. One such popular product is ransomware, which is a popular type of malware traded in the underground economy. In ransomware attacks, data from infected systems is held hostage (encrypted) until a ransom is paid to the criminals. In addition, a recent blackmailing strategy adopted by criminals is to leak data online from the infected systems if the ransom is not paid before a given time, producing further economic and reputational damage. In this work, we perform an in-depth analysis of Avaddon, a ransomware offered in the underground economy as an affiliate program business. This threat has been linked to various cyberattacks and has infected and leaked data from at least 62 organizations. Additionally, it also runs Distributed Denial-of-Service (DDoS) attacks against victims that do not pay the ransom. We first provide an analysis of the criminal business model in the underground economy. Then, we identify and describe its technical capabilities, dissecting details of its inner structure. As a result, we provide tools to assist analysis, decrypting and labeling obfuscated strings observed in the ransomware binary. Additionally, we provide empirical evidence of links between this variant and a previous family, suggesting that the same group was behind the development and, possibly, the operation of both campaigns. Finally, we develop a procedure to recover files encrypted by Avaddon. We successfully tested the proposed procedure against different versions of Avaddon. The proposed method is released as an open-source tool so it can be incorporated in existing Antivirus engines and extended to decrypt other ransomware families that implement a similar encryption approach.
机译:恶意软件是地下经济的新兴和受欢迎的威胁。恶意软件服务(MAA)的商品化允许犯罪分子以低风险和技术背景上获得金融益处。一种如此流行的产品是勒索软件,这是地下经济中的一种流行的恶意软件。在赎金软件攻击中,来自受感染系统的数据被持有人质(加密),直到赎金支付给罪犯。此外,如果在给定时间之前没有支付赎金,产生进一步的经济和声誉损害,最近犯罪分子采用的最近逮捕的制度是从受感染的系统泄露数据。在这项工作中,我们对Avaddon进行了深入的分析,该公司在地下经济中提供作为联盟计划业务。这种威胁已与各种网络攻击相关联,并从至少62个组织中感染和泄露数据。此外,它还运行了对不支付赎金的受害者的分布式拒绝服务(DDOS)攻击。我们首先对地下经济中的犯罪商业模式进行了分析。然后,我们识别并描述其技术能力,解剖其内部结构的细节。因此,我们提供工具来帮助分析,解密和标记在勒索软件二进制中观察到的混淆字符串。此外,我们还提供了这种变体与之前的家庭之间的联系的经验证据,这表明同一组是发展的背后,可能是两种运动的运作。最后,我们开发了一种恢复由Avaddon加密的文件的过程。我们成功地测试了针对不同版本的Avaddon的拟议程序。该方法被释放为开源工具,因此它可以在现有的防病毒发动机中并入并扩展以解密实现类似加密方法的其他勒索软件系列。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号