CryptoLocker demystified: a study in ransomware analysis techniques

Riya Rajendran Nair, Parth Lakhalani, Heena Sirajudddin Karbhari, Kiranbhai Ramabhai Dodiya · International Journal of Security and Networks · 2025

Ransomware is a kind of malware that spreads by itself and uses encryption to demand payment for its victims' data. It is one of the deadliest cyber dangers that have surfaced in recent years. These ransomware assaults have been becoming more frequent. Technical investigation of such malicious programs is vital, as is determining the source of such assaults, if possible. Although recovering the affected files may be difficult due to the heavy encryption placed on such material, locating the origin of ransomware attacks has become essential for criminal prosecution. In this work, we used a virtual computer running Windows 10 to analyse the CryptoLocker ransomware sample in a safe environment. Our combined analysis found several noteworthy similarities between the different code components. Using various open-source tools and software, our goal is to use statically extracted features and dynamic analysis of the malware's behaviour to get a comprehensive report on our malware's properties and its capacity to infect any system with a weak defence mechanism.

Read the paper · More papers on PaperTik