Comparative Analysis of Attack Behavior Patterns in Petya, CryptInfinite, and Locky Ransomware Using Hybrid Analysis

Arga Yuda Prasetya, Khirsa Inayatul Aini, Charles Ci-Wen Lim · 2023

Technological development brings numerous benefits to human life, particularly technology, the internet, and computers. However, criminals increasingly exploit these advancements to commit crimes, including malware attacks. Malware is software that infiltrates and damages computers, resulting in financial and material losses. To prevent such attacks, analyzing malware functionality and characteristics is essential. Three methods for malware analysis are static, dynamic, and hybrid approaches, which provide comprehensive results and information. Using these methods, the author examined Petya, CryptInfinite, and Locky Ransomware, focusing on ransomware due to its ability to lock user data and demand ransom. Static analysis revealed that multiple security vendors identified all three types of malware as malicious files and could extract information from various Process IDs on the computer. Dynamic analysis showed that Petya.A.exe and CryptInfinite.exe could operate on the Windows victim, while Locky.AZ.exe could not. Hybrid analysis revealed that Petya.A.exe caused direct damage to the victim’s Windows system, while InfinityCrypt.exe operated silently to collect information about the infected system. Locky.AZ.exe also failed to run on the victim’s Windows system.

Read the paper · More papers on PaperTik