SearcharxivSearch

arXiv subjects

Vadim Kotov

Publications and source records attributed to Vadim Kotov.

2 recordsLinked to original sources

Understanding Crypto-Ransomware

Crypto-Ransomware has been increasing in sophistication since it first appeared in September 2013, leveraging new attack vectors, incorporating advanced encryption algorithms, and expanding the number of file types it targets. In this report, we dissect nearly 30 samples of ransomware variants that have been encountered since September 2013, revealing a trend of increasing sophistication.

cs.CR

Towards Generic Deobfuscation of Windows API Calls

A common way to get insight into a malicious program's functionality is to look at which API functions it calls. To complicate the reverse engineering of their programs, malware authors deploy API obfuscation techniques, hiding them from analysts' eyes and anti-malware scanners. This problem can be partially addressed by using dynamic analysis; that is, by executing a malware sample in a controlled environment and logging the API calls. However, malware that is aware of virtual machines and sandboxes might terminate without showing any signs of malicious behavior. In this paper, we introduce a static analysis technique allowing generic deobfuscation of Windows API calls. The technique utilizes symbolic execution and hidden Markov models to predict API names from the arguments passed to the API functions. Our best prediction model can correctly identify API names with 87.60% accuracy.

cs.CR