{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T16:45:40Z","timestamp":1783788340549,"version":"3.55.0"},"publisher-location":"Cham","reference-count":40,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319205496","type":"print"},{"value":"9783319205502","type":"electronic"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-20550-2_1","type":"book-chapter","created":{"date-parts":[[2015,6,22]],"date-time":"2015-06-22T01:55:06Z","timestamp":1434938106000},"page":"3-24","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":276,"title":["Cutting the Gordian Knot: A Look Under the Hood of Ransomware Attacks"],"prefix":"10.1007","author":[{"given":"Amin","family":"Kharraz","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"William","family":"Robertson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Leyla","family":"Bilge","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2015,6,23]]},"reference":[{"key":"1_CR1","unstructured":"Minotaur Analysis - Malware Repository. http:\/\/minotauranalysis.com"},{"key":"1_CR2","unstructured":"VX Vault - Online Repository of Malware Samples. http:\/\/vxvault.siri-urz.net"},{"key":"1_CR3","unstructured":"Malware Tips - Your Security Advisor. http:\/\/malwaretips.com\/forums\/virus-exchange.104\/"},{"key":"1_CR4","unstructured":"MalwareBlackList - Online Repository of Malicious URLs. http:\/\/www.malwareblacklist.com"},{"key":"1_CR5","unstructured":"Police ransomware threat assessment. Europol Public Information (2014)"},{"key":"1_CR6","unstructured":"Ajjan, A.: Ransomware: Next-Generation Fake Antivirus (2013). http:\/\/www.sophos.com\/en-us\/medialibrary\/PDFs\/technicalpapers\/SophosRansomwareFakeAntivirus.pdf"},{"key":"1_CR7","unstructured":"Bayer, U., Kruegel, C., Kirda, E.: TTAnalyze: a tool for analyzing malware. In: Proceedings of the European Institute for Computer Antivirus Research Annual Conference, April 2006"},{"key":"1_CR8","unstructured":"Blockchain.info. Bitcoin Block Explorer. https:\/\/blockchain.info"},{"key":"1_CR9","doi-asserted-by":"crossref","unstructured":"Bowen, B.M., Hershkop, S., Keromytis, A.D., Stolfo, S.J.: Baiting inside attackers using decoy documents. Springer (2009)","DOI":"10.21236\/ADA500672"},{"key":"1_CR10","unstructured":"Carrier, B.: File System Forensic Analysis. Addison-Wesley Professional (2005)"},{"key":"1_CR11","doi-asserted-by":"crossref","unstructured":"Christin, N.: Traveling the silk road: a measurement analysis of a large anonymous online marketplace. In: Proceedings of WWW 2013, May 2013","DOI":"10.21236\/ADA579383"},{"key":"1_CR12","unstructured":"Cisco, Inc., Ransomware on Steroids: Cryptowall 2.0. (2015). http:\/\/blogs.cisco.com\/security\/talos\/cryptowall-2"},{"key":"1_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"442","DOI":"10.1007\/978-3-642-15512-3_23","volume-title":"Recent Advances in Intrusion Detection","author":"M Cova","year":"2010","unstructured":"Cova, M., Leita, C., Thonnard, O., Keromytis, A.D., Dacier, M.: An analysis of rogue AV campaigns. In: Jha, S., Sommer, R., Kreibich, C. (eds.) RAID 2010. LNCS, vol. 6307, pp. 442\u2013463. Springer, Heidelberg (2010)"},{"key":"1_CR14","unstructured":"Cuckoo Foundation. Cuckoo Sandbox: Automated Malware Analysis (2014). http:\/\/www.cuckoosandbox.org"},{"key":"1_CR15","unstructured":"Dell SecureWorks. Cryptolocker Ransomware (2014). http:\/\/www.secureworks.com\/cyber-threat-intelligence\/threats\/cryptolocker-ransomware\/"},{"key":"1_CR16","unstructured":"Donohue, B.: Reveton Ransomware Adds Password Purloining Function (2013). http:\/\/threatpost.com\/reveton-ransomeware-adds-password-purloining-function\/100712"},{"key":"1_CR17","first-page":"197","volume-title":"Security and Privacy in Social Networks","author":"F Reid","year":"2012","unstructured":"Reid, F., Harrigan, M.: An analysis of anonymity in the bitcoin system. In: Altshuler, Y., Elovici, Y., Cremers, A.B., Aharony, N., Pentland, A. (eds.) Security and Privacy in Social Networks, pp. 197\u2013223. Springer, New York (2012)"},{"issue":"1","key":"1_CR18","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/s11416-008-0092-2","volume":"6","author":"A Gazet","year":"2010","unstructured":"Gazet, A.: Comparative analysis of various ransomware virii. J. Comput. Virol. 6(1), 77\u201390 (2010)","journal-title":"J. Comput. Virol."},{"key":"1_CR19","unstructured":"Hoglund, G., Butler, J.: Rootkits: Subverting the Windows Kernel. Addison-Wesley Professional (2005)"},{"key":"1_CR20","doi-asserted-by":"crossref","unstructured":"Juels, A., Rivest, R.L.: Honeywords: Making password-cracking detectable. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security, pp. 145\u2013160. ACM (2013)","DOI":"10.1145\/2508859.2516671"},{"key":"1_CR21","unstructured":"Krebs, B.: Inside a Reveton Ransomware Operation (2012). http:\/\/krebsonsecurity.com\/2012\/08\/inside-a-reveton-ransomware-operation\/"},{"key":"1_CR22","doi-asserted-by":"crossref","unstructured":"Lanzi, A., Balzarotti, D., Kruegel, C., Christodorescu, M., Kirda, E.: Accessminer: using system-centric models for malware protection. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, CCS 2010, pp. 399\u2013412. ACM (2010)","DOI":"10.1145\/1866307.1866353"},{"key":"1_CR23","unstructured":"Malware Don\u2019t Need Coffee. Guess who\u2019s back again ? Cryptowall 3.0. (2015). http:\/\/malware.dontneedcoffee.com\/2015\/01\/guess-whos-back-again-cryptowall-30.html"},{"key":"1_CR24","doi-asserted-by":"crossref","unstructured":"Meiklejohn, S., Pomarole, M., Jordan, G., Levchenko, K., McCoy, D., Voelker, G. M., Savage, S.: A fistful of bitcoins: characterizing payments among men with no names. In: Proceedings of the 2013 Conference on Internet Measurement Conference, IMC 2013, pp. 127\u2013140 (2013)","DOI":"10.1145\/2504730.2504747"},{"key":"1_CR25","unstructured":"Microsoft, Inc. Microsoft Security Intelegence Report, vol. 16 (2013). http:\/\/www.microsoft.com\/security\/sir\/default.aspx"},{"key":"1_CR26","unstructured":"Microsoft, Inc. File System Minifilter Drivers (2014). https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/hardware\/ff540402"},{"key":"1_CR27","unstructured":"M\u00f6ser, M.: Anonymity of bitcoin transactions: an analysis of mixing services. In: Proceedings of Monster Bitcoin Conference (2013)"},{"key":"1_CR28","unstructured":"Nikiforakis, N., Balduzzi, M., Acker, S.V., Joosen, W., Balzarotti, D.: Exposing the lack of privacy in file hosting services. In: Proceedings of the 4th USENIX Conference on Large-Scale Exploits and Emergent Threats, LEET 2011 (2011)"},{"key":"1_CR29","unstructured":"O\u2019Gorman, G., McDonald, G.: Ransomware: A Growing Menance (2012). http:\/\/www.symantec.com\/connect\/blogs\/ransomware-growing-menace"},{"key":"1_CR30","unstructured":"Prince, B.: CryptoLocker Could Herald Rise of More Sophisticated Ransomware (2013). http:\/\/www.darkreading.com\/attacks-breaches\/cryptolocker-could-herald-rise-of-more-sophisticated-ransomware"},{"key":"1_CR31","unstructured":"QuickBT. Disturbing Bitcoin Virus, October 2013. http:\/\/www.reddit.com\/r\/Bitcoin\/comments\/1o53hl\/"},{"key":"1_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"6","DOI":"10.1007\/978-3-642-39884-1_2","volume-title":"Financial Cryptography and Data Security","author":"D Ron","year":"2013","unstructured":"Ron, D., Shamir, A.: Quantitative analysis of the full bitcoin transaction graph. In: Sadeghi, A.-R. (ed.) FC 2013. LNCS, vol. 7859, pp. 6\u201324. Springer, Heidelberg (2013)"},{"key":"1_CR33","doi-asserted-by":"crossref","unstructured":"Rossow, C., Dietrich, C.J., Grier, C., Kreibich, C., Paxson, V., Pohlmann, N., Bos, H., Van Steen, M.: Prudent practices for designing malware experiments: status quo and outlook. In: 2012 IEEE Symposium on Security and Privacy (SP), pp. 65\u201379. IEEE (2012)","DOI":"10.1109\/SP.2012.14"},{"key":"1_CR34","unstructured":"Sophos, Inc. Security Threat Report 2014, Smarter, Shadier, Stealthier Malware (2014). http:\/\/www.sophos.com\/en-us\/medialibrary\/PDFs\/other\/sophos-security-threat-report-2014.pdf"},{"key":"1_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"452","DOI":"10.1007\/978-3-319-07127-5","volume-title":"Financial Cryptography and Data Security","author":"M Spagnuolo","year":"2014","unstructured":"Spagnuolo, M., Maggi, F., Zanero, S.: BitIodine: extracting intelligence from the bitcoin network. In: Christin, N., Safavi-Naini, R. (eds.) FC 2014. LNCS, vol. 8437, pp. 452\u2013463. Springer, Heidelberg (2014)"},{"key":"1_CR36","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1007\/978-1-4614-1981-5_4","volume-title":"Economics of Information Security and Privacy III","author":"B Stone-Gross","year":"2013","unstructured":"Stone-Gross, B., Abman, R., Kemmerer, R.A., Kruegel, C., Steigerwald, D.G., Vigna, G.: The underground economy of fake antivirus software. In: Schneier, B. (ed.) Economics of Information Security and Privacy III, pp. 55\u201378. Springer, New York (2013)"},{"key":"1_CR37","unstructured":"Symantec, Inc. Internet Security Threat Report (2014). http:\/\/www.symantec.com\/security_response\/publications\/threatreport.jsp"},{"key":"1_CR38","unstructured":"Young, A., Yung, M.: Cryptovirology: extortion-based security threats and countermeasures. In: Proceedings of the 1996 IEEE Symposium on Security and Privacy, 1996, pp. 129\u2013140. IEEE (1996)"},{"key":"1_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"389","DOI":"10.1007\/11556992_28","volume-title":"Information Security","author":"AL Young","year":"2005","unstructured":"Young, A.L.: Building a cryptovirus using microsoft\u2019s cryptographic API. In: Zhou, J., L\u00f3pez, J., Deng, R.H., Bao, F. (eds.) ISC 2005. LNCS, vol. 3650, pp. 389\u2013401. Springer, Heidelberg (2005)"},{"key":"1_CR40","doi-asserted-by":"crossref","unstructured":"Yuill, J., Zappe, M., Denning, D., Feer, F.: Honeyfiles: deceptive files for intrusion detection. In: Proceedings from the Fifth Annual IEEE SMC Information Assurance Workshop, pp. 116\u2013122. IEEE (2004)","DOI":"10.1109\/IAW.2004.1437806"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-20550-2_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T19:42:01Z","timestamp":1748461321000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-20550-2_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319205496","9783319205502"],"references-count":40,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-20550-2_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015]]},"assertion":[{"value":"23 June 2015","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}