An Analysis of LockerGoga Ransomware

An Analysis of LockerGoga Ransomware
复制标题

LockerGoga勒索软件分析

DOI:
--
复制
发表时间:
2019
期刊:
East-West Design & Test Symposium
影响因子:
--
通讯作者:
T. Surmacz
T. Surmacz
中科院分区:
--
文献类型:
--
作者:
A. Adamov;Anders Carlsson;T. Surmacz

文献摘要

被引文献

相似文献

本文分析了LockerGoga勒索软件,该勒索软件用于2019年上半年针对Norsk Hydra(世界五大铝制造商)以及美国化学企业Hessel和Momentive的有针对性的网络攻击,这些公司只是向公众报告攻击的冰山一角。勒索软件是由企业网络内部的攻击者执行的,目的是加密企业服务器上的数据,从而摧毁信息控制系统。入侵者要求赎金释放主密钥和解密工具,可用于解密受影响的文件。分析的目的是找出LockerGoga勒索软件在加密锁攻击期间使用的策略和技术,以及加密模型,以回答加密文件是否可以在支付赎金或不支付赎金的情况下解密的问题。该论文的科学新奇在于基于各种逆向工程技术的分析方法,例如多进程调试和使用加密库的开源代码来找出勒索软件加密模型。
This paper contains an analysis of the LockerGoga ransomware that was used in the range of targeted cyberattacks in the first half of 2019 against Norsk Hydra - a world top 5 aluminum manufacturer, as well as the US chemical enterprises Hexion, and Momentive - those companies are only the tip of the iceberg that reported the attack to the public. The ransomware was executed by attackers from inside a corporate network to encrypt the data on enterprise servers and, thus, taking down the information control systems. The intruders asked for a ransom to release a master key and decryption tool that can be used to decrypt the affected files. The purpose of the analysis is to find out tactics and techniques used by the LockerGoga ransomware during the cryptolocker attack as well as an encryption model to answer the question if the encrypted files can be decrypted with or without paying a ransom. The scientific novelty of the paper lies in an analysis methodology that is based on various reverse engineering techniques such as multi-process debugging and using open source code of a cryptographic library to find out a ransomware encryption model.