Ransomware Extraction Using Static Portable Executable (PE) Feature-Based Approach

Iik Muhamad Malik Matin · 2023

Currently cyberspace has often been used for crime. Ransomware is a type of malware that takes the victim's data hostage by asking for a ransom accompanied by threats. This attack is more aimed at Windows users. Preventive measures are needed to prevent ransomware attacks, one of which is a learning-based approach. The challenge to the learning-based approach is data. We propose a static non-signature approach for extracting PE-based ransomware. The main focus of this research is the development of a non-signature static analysis approach that can identify and extract ransomware code from PE files without being affected by signature obfuscation or mutation. We extracted the 3 main headers namely dos_header, file_header, and optional_header plus the derived feature. The results show that from 132 samples, 71 of them were successfully extracted with PE file ransomware. This research contributes to the development of ransomware detection methodologies by offering a non-signature static analysis approach that improves resilience against evolving ransomware threats.

Read the paper · More papers on PaperTik