An Analysis of LockerGoga Ransomware
An Analysis of LockerGoga Ransomware
复制标题
LockerGoga勒索软件分析
DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
T. Surmacz
中科院分区:
文献类型:
--
作者:
A. Adamov;Anders Carlsson;T. Surmacz
This paper contains an analysis of the LockerGoga ransomware that was used in the range of targeted cyberattacks in the first half of 2019 against Norsk Hydra - a world top 5 aluminum manufacturer, as well as the US chemical enterprises Hexion, and Momentive - those companies are only the tip of the iceberg that reported the attack to the public. The ransomware was executed by attackers from inside a corporate network to encrypt the data on enterprise servers and, thus, taking down the information control systems. The intruders asked for a ransom to release a master key and decryption tool that can be used to decrypt the affected files. The purpose of the analysis is to find out tactics and techniques used by the LockerGoga ransomware during the cryptolocker attack as well as an encryption model to answer the question if the encrypted files can be decrypted with or without paying a ransom. The scientific novelty of the paper lies in an analysis methodology that is based on various reverse engineering techniques such as multi-process debugging and using open source code of a cryptographic library to find out a ransomware encryption model.