arrow
Return

Ransomware Automatic Data Acquisition Tool

delete2018-01-01
delete9
delete
OA
AI
L
Luis Javier García Villalba *
A
Ana Lucila Sandoval Orozco
A
Antonio López Vivar
E
Esteban Alejandro Armas Vega
T
Tai-hoon Kim
DOI:10.1109/ACCESS.2018.2868885delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Ransomware attacks reported to authorities face the technical difficulty of local police units in gathering information and executing proper forensic analysis. This paper proposes a forensic analysis tool that acts during the final stage of the ransomware infection cycle to provide a quick and easy option to acquire valuable information for the forensic analyst in order to facilitate the subsequent classification of ransomware. The proposed tool combines pop-up window capture showing the ransomware and through the optical character recognition techniques, obtaining the rescue message along with the payment address and value. In addition, it extracts the files generated by the ransomware and dumps the virtual memory of the system for analysis by the forensic technician. To evaluate the accuracy of the tool, experiments were conducted with different samples of ransomware on a real computer, under a controlled environment.
Keywords:
Bitcoin
crypto currency
forensic analysis
Internet
memory dump
optical character recognition
pattern recognition
ransomware
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

C
Complutense University of Madrid
Scholars:
2.6W
Papers: 2.2W
Citations: 31