Working mechanism of Eternalblue and its application in ransomworm

12/29/2021
by   Zian Liu, et al.
0

After the leaking of exploit Eternalblue, some ransomworms utilizing this exploit have been developed to sweep over the world in recent years. Ransomworm is a global growing threat as it blocks users' access to their files unless a ransom is paid by victims. Wannacry and Notpetya are two of those ransomworms which are responsible for the loss of millions of dollar, from crippling U.K. national systems to shutting down a Honda Motor Company in Japan. Many dynamic analytic papers on Wannacry were published, however, static analytic papers about Wannacry were limited. Our aim is to present readers an systematic knowledge about exploit Eternalblue, from a high–leveled semantic view to the code details. Specifically, the working mechanism of Eternalblue, the reverse engineering analysis of Eternalblue in Wannacry, and the comparison with the Metasploit's Eternalblue exploit are presented. The key finding of our analysis is that the code remains almost the same when Eternalblue is transplanted into Wannacry, which indicates its potential for signatures and thus detection.

READ FULL TEXT
research
12/28/2019

Opportunities and Challenges in Deep Learning Methods on Electrocardiogram Data: A Systematic Review

Objective: To conduct a systematic review of deep learning methods on El...
research
02/16/2018

Accumulation of Knowledge in Para-Scientific Areas. The Case of Analytic Philosophy

This study analyzes how accumulation of knowledge takes place in para-sc...
research
09/28/2022

Automatic Analysis of Available Source Code of Top Artificial Intelligence Conference Papers

Source code is essential for researchers to reproduce the methods and re...
research
06/25/2020

Revenue Maximizing Markets for Zero-Day Exploits

Markets for zero-day exploits (software vulnerabilities unknown to the v...
research
08/16/2019

All About Phishing: Exploring User Research through a Systematic Literature Review

Phishing is a well-known cybersecurity attack that has rapidly increased...
research
04/12/2019

Guidelines for data analysis scripts

Unorganized heaps of analysis code are a growing liability as data analy...
research
05/23/2022

A Model-Driven-Engineering Approach for Detecting Privilege Escalation in IoT Systems

Software vulnerabilities in access control models can represent a seriou...

Please sign up or login with your details

Forgot password? Click here to reset