Deakin University
Browse

File(s) under permanent embargo

Working Mechanism of Eternalblue and Its Application in Ransomworm

conference contribution
posted on 2023-02-07, 01:48 authored by Z Liu, C Chen, LY Zhang, Shang GaoShang Gao
After the leaking of exploit Eternalblue, some ransomworms utilizing this exploit have been developed to sweep over the world in recent years. Ransomworm is a global growing threat as it blocks users’ access to their files unless a ransom is paid by victims. Wannacry and Notpetya are two of those ransomworms which are responsible for the loss of millions of dollar, from crippling U.K. national systems to shutting down a Honda Motor Company in Japan. Many dynamic analytic papers on Wannacry were published, however, static analytic papers about Wannacry were limited. Our aim is to present readers an systematic knowledge about exploit Eternalblue, from a high– leveled semantic view to the code details. Specifically, the working mechanism of Eternalblue, the reverse engineering analysis of Eternalblue in Wannacry, and the comparison with the Metasploit’s Eternalblue exploit are presented. The key finding of our analysis is that the code remains almost the same when Eternalblue is transplanted into Wannacry, which indicates its potential for signatures and thus detection.

History

Volume

13547 LNCS

Pagination

178-191

Location

Xian, PEOPLES R CHINA

Start date

2022-10-16

End date

2022-10-18

ISSN

0302-9743

eISSN

1611-3349

ISBN-13

9783031180668

Language

English

Editor/Contributor(s)

Susilo W

Title of proceedings

Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)

Event

14th International Symposium on Cyberspace Safety and Security (CSS)

Publisher

SPRINGER INTERNATIONAL PUBLISHING AG

Series

Lecture Notes in Computer Science