{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T22:17:26Z","timestamp":1778278646606,"version":"3.51.4"},"reference-count":194,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2019,8,7]],"date-time":"2019-08-07T00:00:00Z","timestamp":1565136000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2019,8,7]],"date-time":"2019-08-07T00:00:00Z","timestamp":1565136000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100010055","name":"University of Salford","doi-asserted-by":"crossref","id":[{"id":"10.13039\/100010055","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2019,12]]},"DOI":"10.1007\/s11416-019-00338-7","type":"journal-article","created":{"date-parts":[[2019,8,7]],"date-time":"2019-08-07T08:02:25Z","timestamp":1565164945000},"page":"277-305","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":91,"title":["A Cyber-Kill-Chain based taxonomy of crypto-ransomware features"],"prefix":"10.1007","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0908-6483","authenticated-orcid":false,"given":"Tooska","family":"Dargahi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ali","family":"Dehghantanha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pooneh Nikkhah","family":"Bahrami","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giuseppe","family":"Bianchi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Loris","family":"Benedetto","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,8,7]]},"reference":[{"key":"338_CR1","unstructured":"Palmer, D.: Ransomware is about to get a lot worse, by holding your operating system hostage (2017). \nhttp:\/\/www.zdnet.com\/article\/ransomware-is-about-to-get-a-lot-worse-by-holding-your-operating-system-hostage\/\n\n. Accessed Dec 2018"},{"key":"338_CR2","unstructured":"Fox-Brewster, T.: How one simple trick just put out that huge ransomware fire (2017). \nhttps:\/\/www.forbes.com\/sites\/thomasbrewster\/2017\/05\/13\/wannacry-ransomware-outbreak-stopped-by-researcher\/#74fca09b74fc\n\n. Accessed Dec 2018"},{"key":"338_CR3","unstructured":"Ajjan, A.: Ransomware: Next-generation fake antivirus (2013). \nhttps:\/\/www.sophos.com\/en-us\/medialibrary\/PDFs\/technical%20papers\/SophosRansomwareFakeAntivirus.pdf\n\n. Accessed Dec 2018"},{"key":"338_CR4","unstructured":"Lee, B.: Ransomware: Unlocking the lucrative criminal business model. Palo Alto Networks (2016). \nhttps:\/\/www.paloaltonetworks.com\/content\/pan\/en_US\/resources\/research\/ransomware-report.html\n\n. Accessed Dec 2018"},{"key":"338_CR5","series-title":"Handbook of Digital Currency: Bitcoin, Innovation, Financial Instruments, and Big Data","first-page":"5","volume-title":"Introduction to Bitcoin","author":"LP Nian","year":"2015","unstructured":"Nian, L.P., Chuen, D.: Introduction to Bitcoin. Handbook of Digital Currency: Bitcoin, Innovation, Financial Instruments, and Big Data, pp. 5\u201329. Academic Press, Cambridge (2015)"},{"key":"338_CR6","unstructured":"Nakamoto, S.: Bitcoin: a peer-to-peer electronic cash system (2008). \nhttps:\/\/bitcoin.org\/bitcoin.pdf"},{"key":"338_CR7","unstructured":"Kharraz, A., Arshad, S., Mulliner, C., Robertson, W., Kirda, E.: Unveil: a large-scale, automated approach to detecting ransomware. In: Proceedings of the 25th USENIX Security Symposium, pp. 757\u2013772 (2016)"},{"key":"338_CR8","doi-asserted-by":"crossref","unstructured":"Scaife, N., Carter, H., Traynor, P., Butler, K.R.: Cryptolock (and drop it): stopping ransomware attacks on user data. In: Proceedings of the International Conference on Distributed Computing Systems, ser. ICDCS\u201916, pp. 303\u2013312. IEEE (2016)","DOI":"10.1109\/ICDCS.2016.46"},{"issue":"4","key":"338_CR9","doi-asserted-by":"publisher","first-page":"1141","DOI":"10.1007\/s12652-017-0558-5","volume":"9","author":"A Azmoodeh","year":"2018","unstructured":"Azmoodeh, A., Dehghantanha, A., Conti, M., Choo, K.-K.R.: Detecting crypto-ransomware in IoT networks based on energy consumption footprint. J. Ambient Intell. Human. Comput. 9(4), 1141\u20131152 (2018)","journal-title":"J. Ambient Intell. Human. Comput."},{"key":"338_CR10","doi-asserted-by":"publisher","unstructured":"Homayoun, S., Dehghantanha, A., Ahmadzadeh, M., Hashemi, S., Khayami, R.: Know abnormal, find evil: Frequent pattern mining for ransomware threat hunting and intelligence. IEEE Trans. Emerg. Top. Comput. (2017). \nhttps:\/\/doi.org\/10.1109\/TETC.2017.2756908","DOI":"10.1109\/TETC.2017.2756908"},{"key":"338_CR11","first-page":"107","volume-title":"Advances in Information Security","author":"James Baldwin","year":"2018","unstructured":"Baldwin, J., Dehghantanha, A.: Leveraging support vector machine for opcode density based detection of crypto-ransomware. In: Dehghantanha, A., Conti, M., Dargahi, T. (eds.) Cyber threat intelligence. Advances in Information Security, vol. 70. Springer, Cham (2018)"},{"key":"338_CR12","first-page":"93","volume-title":"Advances in Information Security","author":"Omar M. K. Alhawi","year":"2018","unstructured":"Alhawi, O.M.K., Baldwin, J., Dehghantanha, A.: Leveraging machine learning techniques for windows ransomware network traffic detection. In: Dehghantanha, A., Conti, M., Dargahi, T. (eds.) Cyber threat intelligence. Advances in Information Security, vol. 70. Springer, Cham (2018)"},{"issue":"5","key":"338_CR13","doi-asserted-by":"publisher","first-page":"1286","DOI":"10.1109\/TIFS.2017.2787905","volume":"13","author":"J Chen","year":"2018","unstructured":"Chen, J., Wang, C., Zhao, Z., Chen, K., Du, R., Ahn, G.-J.: Uncovering the face of android ransomware: characterization and real-time detection. IEEE Trans. Inf. Forensics Secur. 13(5), 1286\u20131300 (2018)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"338_CR14","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-20550-2_1","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"Amin Kharraz","year":"2015","unstructured":"Kharraz, A., Robertson, W., Balzarotti, D., Bilge, L., Kirda, E.: Cutting the gordian knot: a look under the hood of ransomware attacks. In: Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, ser. DIMVA\u201915. Springer. pp. 3\u201324 (2015)"},{"key":"338_CR15","doi-asserted-by":"publisher","first-page":"444","DOI":"10.1016\/j.comnet.2017.09.003","volume":"129","author":"I Yaqoob","year":"2017","unstructured":"Yaqoob, I., Ahmed, E., Rehman, M., Ahmed, A., Al-garadi, M., Imran, M., Guizani, M.: The rise of ransomware and emerging security challenges in the internet of things. Comput. Netw. 129, 444\u2013458 (2017)","journal-title":"Comput. Netw."},{"issue":"2","key":"338_CR16","first-page":"48","volume":"6","author":"S Aurangzeb","year":"2017","unstructured":"Aurangzeb, S., Aleem, M., Iqbal, M.A., Islam, M.A.: Ransomware: a survey and trends. J. Inf. Assur. Secur. 6(2), 48\u201358 (2017)","journal-title":"J. Inf. Assur. Secur."},{"key":"338_CR17","doi-asserted-by":"publisher","first-page":"465","DOI":"10.1016\/j.procs.2016.08.072","volume":"94","author":"P Zavarsky","year":"2016","unstructured":"Zavarsky, P., Lindskog, D., et al.: Experimental analysis of ransomware on windows and android platforms: evolution and characterization. Proc. Comput. Sci. 94, 465\u2013472 (2016)","journal-title":"Proc. Comput. Sci."},{"key":"338_CR18","unstructured":"Gandhi, K.A., et al.: Survey on ransomware: a new era of cyber attack. Int. J. Comput. Appl. 168(3), 38\u201341 (2017)"},{"key":"338_CR19","unstructured":"The cyber kill chain. \nhttp:\/\/www.lockheedmartin.com\/us\/what-we-do\/aerospace-defense\/cyber\/cyber-kill-chain.html\n\n. Accessed Dec 2018"},{"key":"338_CR20","unstructured":"Hutchins, E.M., Cloppert, M.J., Amin, R.M.: Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. In: Proceedings of the 6th International Conference on Information Warfare and Security (2011)"},{"key":"338_CR21","unstructured":"Ransomware on the rise: An enterprise guide to preventing ransomware attacks. Carbon Black, ebook, February 2017. \nhttp:\/\/www.bankinfosecurity.com\/whitepapers\/ransomware-on-rise-enterprise-guide-to-preventing-ransomware-attacks-w-2760\n\n. Accessed Dec 2018"},{"key":"338_CR22","first-page":"1","volume":"11","author":"S Barnum","year":"2012","unstructured":"Barnum, S.: Standardizing cyber threat intelligence information with the structured threat information expression (stix$$^{{{\\rm TM}}}$$). MITRE Corp. 11, 1\u201322 (2012)","journal-title":"MITRE Corp."},{"key":"338_CR23","unstructured":"Krikken, R.: Introducing gartner\u2019s cyber attack chain model (2014). \nhttp:\/\/blogs.gartner.com\/ramon-krikken\/2014\/08\/08\/introducing-gartners-cyber-attack-chain-model\/\n\n. Accessed Dec 2018"},{"key":"338_CR24","unstructured":"Zetter, K.: Hacker lexicon: what is a zero day? (2014). \nhttps:\/\/www.wired.com\/2014\/11\/what-is-a-zero-day\/\n\n. Accessed Dec 2018"},{"issue":"4","key":"338_CR25","first-page":"10","volume":"2","author":"M Damshenas","year":"2013","unstructured":"Damshenas, M., Dehghantanha, A., Mahmoud, R.: A survey on malware propagation, analysis, and detection. Int. J. Cyber-Secur. Digit. Forensics (IJCSDF) 2(4), 10\u201329 (2013)","journal-title":"Int. J. Cyber-Secur. Digit. Forensics (IJCSDF)"},{"key":"338_CR26","doi-asserted-by":"publisher","first-page":"394","DOI":"10.1016\/j.jocs.2017.10.020","volume":"27","author":"D Kiwia","year":"2018","unstructured":"Kiwia, D., Dehghantanha, A., Choo, K.-K.R., Slaughter, J.: A cyber kill chain based taxonomy of banking Trojans for evolutionary computational intelligence. J. Comput. Sci. 27, 394\u2013409 (2018)","journal-title":"J. Comput. Sci."},{"key":"338_CR27","unstructured":"Targeted ransomware: the next evolution in cyber extortion. Crypsis Group, White paper, Accessed 2016. \nhttp:\/\/www.crypsisgroup.com\/images\/site\/CG_WhitePaper_Ransomware_FINAL.pdf\n\n. Accessed Dec 2018"},{"key":"338_CR28","unstructured":"Pradeep, A., Natarajan, S.: Mcafee labs threats report. Institute for Critical Infrastructure Technology (2015). \nhttps:\/\/www.mcafee.com\/us\/resources\/reports\/rp-quarterly-threats-nov-2015.pdf\n\n. Accessed Dec 2018"},{"key":"338_CR29","unstructured":"Khandelwal, S.: New \u201cfileless malware\u201d targets banks and organizations spotted in the wild. The hacker news (2017). \nhttp:\/\/thehackernews.com\/2017\/02\/fileless-malware-bank.html\n\n. Accessed Dec 2018"},{"key":"338_CR30","unstructured":"GReAT: Fileless attacks against enterprise networks. Kaspersky Lab\u2019s Global Research & Analysis (2017). \nhttps:\/\/securelist.com\/blog\/research\/77403\/fileless-attacks-against-enterprise-networks\/\n\n. Accessed Dec 2018"},{"key":"338_CR31","unstructured":"An ISTR special report: ransomware and businesses 2016. Symantec (2016). \nhttps:\/\/www.symantec.com\/connect\/forums\/special-report-ransomware-and-businesses-2016-1\n\n. Accessed Dec 2018"},{"key":"338_CR32","unstructured":"FRENCH, J.: Cryptowall coming in svg files (2015). \nhttps:\/\/blog.appriver.com\/2015\/05\/cryptowall-coming-in-svg-files\/\n\n. Accessed Dec 2018"},{"key":"338_CR33","unstructured":"Cimpanu, C.: Marlboro ransomware defeated in one day (2017). \nhttps:\/\/www.bleepingcomputer.com\/news\/security\/marlboro-ransomware-defeated-in-one-day\/\n\n. Accessed Dec 2018"},{"key":"338_CR34","unstructured":"Cimpanu, C.: Spora ransomware works offline, has the most sophisticated payment site as of yet. Bleeping Computer (2017). \nhttps:\/\/www.bleepingcomputer.com\/news\/security\/spora-ransomware-works-offline-has-the-most-sophisticated-payment-site-as-of-yet\/\n\n. Accessed Dec 2018"},{"key":"338_CR35","unstructured":"Cimpanu, C.: Cerber ransomware version 6 gets anti-vm and anti-sandboxing features. Bleeping Computer (2017). \nhttps:\/\/www.bleepingcomputer.com\/news\/security\/cerber-ransomware-version-6-gets-anti-vm-and-anti-sandboxing-features\/\n\n. Accessed Dec 2018"},{"key":"338_CR36","unstructured":"From rar to javascript: Ransomware figures in the fluctuations of email attachments. Trend Micro, (2016). \nhttp:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/rar-javascript-ransomware-figures-fluctuations-email-attachments\/\n\n. Accessed Dec 2018"},{"key":"338_CR37","unstructured":"Inside petya and mischa ransomware. Avast Threat Intelligence Team (2016). \nhttps:\/\/blog.avast.com\/inside-petya-and-mischa-ransomware\n\n. Accessed Dec 2018"},{"key":"338_CR38","doi-asserted-by":"crossref","unstructured":"Palisse, A., Le Bouder, H., Lanet, J.-L., Le Guernic, C., Legay, A.: Ransomware and the legacy crypto API. In: Proceedings of the International Conference on Risks and Security of Internet and Systems. Springer, pp. 11\u201328 (2016)","DOI":"10.1007\/978-3-319-54876-0_2"},{"key":"338_CR39","unstructured":"After wannacry, uiwix ransomware and monero-mining malware follow suit. Trend Micro (2017). \nhttp:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/wannacry-uiwix-ransomware-monero-mining-malware-follow-suit\/\n\n. Accessed Dec 2018"},{"key":"338_CR40","unstructured":"Grunzweig, J., Johnston, M.: Bucbi ransomware is back with a ukrainian makeover. Paloalto (2016). \nhttps:\/\/researchcenter.paloaltonetworks.com\/2016\/05\/unit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover\/\n\n. Accessed Dec 2018"},{"key":"338_CR41","unstructured":"BISSON, D.: The four most common evasive techniques used by malware (2015). \nhttps:\/\/www.tripwire.com\/state-of-security\/security-data-protection\/the-four-most-common-evasive-techniques-used-by-malware\/\n\n. Accessed Dec 2018"},{"key":"338_CR42","unstructured":"ZAHARIA, A.: What is ransomware and 15 easy steps to keep your system protected (accessed may 26, 2017). Hemidal security (2017). \nhttps:\/\/heimdalsecurity.com\/blog\/what-is-ransomware-protection\/\n\n. Accessed Dec 2018"},{"issue":"3","key":"338_CR43","first-page":"141","volume":"11","author":"M Damshenas","year":"2015","unstructured":"Damshenas, M., Dehghantanha, A., Choo, K.-K.R., Mahmud, R.: M0droid: an android behavioral-based malware detection model. J. Inf. Priv. Secur. 11(3), 141\u2013157 (2015)","journal-title":"J. Inf. Priv. Secur."},{"key":"338_CR44","doi-asserted-by":"publisher","first-page":"382","DOI":"10.1007\/978-3-319-26362-5_18","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"Nicol\u00f3 Andronio","year":"2015","unstructured":"Andronio, N., Zanero, S., Maggi, F.: Heldroid: dissecting and detecting mobile ransomware. In: Bos, H., Monrose, F., Blanc, G. (eds) Research in Attacks, Intrusions, and Defenses. RAID 2015. Lecture Notes in Computer Science, vol. 9404, pp. 382\u2013404. Springer, Cham (2015)"},{"key":"338_CR45","unstructured":"Cryptxxx: New ransomware from the actors behind reveton, dropping via angler. proofpoint (2016). \nhttps:\/\/www.proofpoint.com\/us\/threat-insight\/post\/cryptxxx-new-ransomware-actors-behind-reveton-dropping-angler\n\n. Accessed Dec 2018"},{"key":"338_CR46","unstructured":"Cerber version 6 shows how far the ransomware has come (and how far it\u2019ll go). Trend Micro (2017). \nhttp:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/cerber-ransomware-evolution\/\n\n. Accessed Dec 2018"},{"key":"338_CR47","unstructured":"How to defend against ransomware targeting shared network drives and cloud backups (2017). \nhttps:\/\/www.cybereason.com\/labs-ransomware-looks-to-strike-it-rich-by-targeting-shared-network-drives-cloud-backup-services\/\n\n. Accessed Dec 2018"},{"key":"338_CR48","volume-title":"Practical Malware Analysis: The Hands-on Guide to Dissecting Malicious Software","author":"M Sikorski","year":"2012","unstructured":"Sikorski, M., Honig, A.: Practical Malware Analysis: The Hands-on Guide to Dissecting Malicious Software. No Starch Press, San Francisco (2012)"},{"key":"338_CR49","doi-asserted-by":"publisher","first-page":"266","DOI":"10.1016\/j.compeleceng.2017.02.013","volume":"61","author":"N Milosevic","year":"2017","unstructured":"Milosevic, N., Dehghantanha, A., Choo, K.-K.R.: Machine learning aided android malware classification. Comput. Electr. Eng. 61, 266\u2013274 (2017)","journal-title":"Comput. Electr. Eng."},{"issue":"2","key":"338_CR50","first-page":"53","volume":"54","author":"C Willems","year":"2012","unstructured":"Willems, C., Freiling, F.C.: Reverse code engineering-state of the art and countermeasures. IT-Information Technology Methoden und innovative Anwendungen der Informatik und Informationstechnik 54(2), 53\u201363 (2012)","journal-title":"IT-Information Technology Methoden und innovative Anwendungen der Informatik und Informationstechnik"},{"key":"338_CR51","unstructured":"Decrypting chimera ransomware. Malwarebytes Labs (2016). \nhttps:\/\/blog.malwarebytes.com\/cybercrime\/2016\/08\/decrypting-chimera-ransomware\/\n\n. Accessed Dec 2018"},{"key":"338_CR52","unstructured":"Windows alternate data streams. Bleeping computer (2004). \nhttps:\/\/www.bleepingcomputer.com\/tutorials\/windows-alternate-data-streams\/\n\n. Accessed Dec 2018"},{"key":"338_CR53","unstructured":"Alternate data streams overview. SANS Digital Forensics and Incident Response Blog (2008). \nhttps:\/\/digital-forensics.sans.org\/blog\/2008\/10\/24\/alternate-data-streams-overview\n\n. Accessed Dec 2018"},{"key":"338_CR54","unstructured":"Means, R.L.: Alternate data streams: out of the shadows and into the light. Tech. Rep. (2003)"},{"key":"338_CR55","unstructured":"Sela, Y.: Anatomy of cryptowall 3.0 virus \u2013 a look inside ransomware code & tactics (2015). \nhttps:\/\/sentinelone.com\/blogs\/anatomy-of-cryptowall-3-0-a-look-inside-ransomwares-tactics\/\n\n. Accessed Dec 2018"},{"key":"338_CR56","unstructured":"Ntfs streams. Microsoft. \nhttps:\/\/msdn.microsoft.com\/en-us\/library\/dn393272.aspx\n\n. Accessed Dec 2018"},{"key":"338_CR57","unstructured":"Zone.identifier stream name. Microsoft. \nhttps:\/\/msdn.microsoft.com\/en-us\/library\/dn392609.aspx\n\n. Accessed Dec 2018"},{"key":"338_CR58","unstructured":"Hor\u0306ejs\u0306\u00ed, J.: Your documents are corrupted: From image to an information stealing trojan. Avast (2013). \nhttps:\/\/blog.avast.com\/2013\/08\/12\/your-documents-are-corrupted-from-image-to-an-information-stealing-trojan\/\n\n. Accessed Dec 2018"},{"key":"338_CR59","unstructured":"Teslacrypt joins ransomware field. McAfee (2015). \nhttps:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/teslacrypt-joins-ransomware-field\/\n\n. Accessed Dec 2018"},{"key":"338_CR60","unstructured":"A closer look at the locky ransomware. Avast (2016). \nhttps:\/\/blog.avast.com\/a-closer-look-at-the-locky-ransomware\n\n. Accessed Dec 2018"},{"key":"338_CR61","unstructured":"Anti-debugging and anti-vm techniques and anti-emulation (2013). \nhttp:\/\/resources.infosecinstitute.com\/anti-debugging-and-anti-vm-techniques-and-anti-emulation\/\n\n. Accessed Dec 2018"},{"key":"338_CR62","unstructured":"Falliere, N.: Windows anti-debug reference. Symantec (2007). \nhttps:\/\/www.symantec.com\/connect\/articles\/windows-anti-debug-reference\n\n. Accessed Dec 2018"},{"key":"338_CR63","doi-asserted-by":"crossref","unstructured":"Smith, A.J., Mills, R.F., Bryant, A.R., Peterson, G.L., Grimaila, M.R.: Redir: Automated static detection of obfuscated anti-debugging techniques. In: Proceedings of the International Conference on Collaboration Technologies and Systems, ser. CTS\u201914. IEEE, pp. 173\u2013180 (2014)","DOI":"10.1109\/CTS.2014.6867561"},{"key":"338_CR64","unstructured":"OllyDbg. \nhttp:\/\/www.ollydbg.de\/\n\n. Accessed Dec 2018"},{"key":"338_CR65","unstructured":"Allievi, A., Carter, E., Tacheau, E.: Threat spotlight: Teslacrypt\u2014decrypt it yourself (2016). \nhttp:\/\/blogs.cisco.com\/security\/talos\/teslacrypt\n\n. Accessed Dec 2018"},{"key":"338_CR66","unstructured":"Sumalapao, J.: New crypto-ransomware jigsaw plays nasty games (2016). \nhttp:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/jigsaw-ransomware-plays-games-victims\/\n\n. Accessed Dec 2018"},{"key":"338_CR67","unstructured":"Roccia, T.: An overview of malware self-defense and protection. McAfee (2016). \nhttps:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/overview-malware-self-defense-protection\/\n\n. Accessed Dec 2018"},{"issue":"1","key":"338_CR68","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1109\/TIFS.2013.2290431","volume":"9","author":"V Rastogi","year":"2014","unstructured":"Rastogi, V., Chen, Y., Jiang, X.: Catch me if you can: evaluating android anti-malware against transformation attacks. IEEE Trans. Inf. Forensics Secur. 9(1), 99\u2013108 (2014)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"5","key":"338_CR69","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/MSP.2011.98","volume":"9","author":"P O\u2019Kane","year":"2011","unstructured":"O\u2019Kane, P., Sezer, S., McLaughlin, K.: Obfuscation: the hidden malware. IEEE Secur. Privacy 9(5), 41\u201347 (2011)","journal-title":"IEEE Secur. Privacy"},{"key":"338_CR70","unstructured":"Landry, J.: Sophisticated new packer identified in cryptxxx ransomware sample. SentinelOne (2016). \nhttps:\/\/sentinelone.com\/blogs\/sophisticated-new-packer-identified-in-cryptxxx-ransomware-sample\/\n\n. Accessed Dec 2018"},{"key":"338_CR71","unstructured":"The current state of ransomware: Virlock, threatfinder, crypvault and powershell-based. Sophos (2016). \nhttps:\/\/news.sophos.com\/en-us\/2016\/01\/11\/the-current-state-of-ransomware-virlock-threatfinder-crypvault-and-powershell-based\/\n\n. Accessed Dec 2018"},{"key":"338_CR72","unstructured":"Cerber spam: Tor all the things! Cisco\u2014Talos group (2016). \nhttp:\/\/blog.talosintelligence.com\/2016\/11\/cerber-spam-tor.html\n\n. Accessed Dec 2018"},{"key":"338_CR73","unstructured":"Crofford, C., McKee, D.: Ransomware families use nsis installers to avoid detection, analysis. McAfee (2017). \nhttps:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/ransomware-families-use-nsis-installers-to-avoid-detection-analysis\/\n\n. Accessed Dec 2018"},{"key":"338_CR74","unstructured":"Duncan, B.: Cryptobit: Another ransomware family gets an update. Paloalto (2016). \nhttps:\/\/researchcenter.paloaltonetworks.com\/2016\/07\/unit42-cryptobit-another-ransomware-family-gets-an-update\/\n\n. Accessed Dec 2018"},{"key":"338_CR75","unstructured":"Cerber 5.0.1 starts the horrors of christmas ransomware. TRIPWIRE (2016). \nhttps:\/\/www.tripwire.com\/state-of-security\/featured\/cerber-5-0-1-starts-horrors-christmas-ransomware\/\n\n. Accessed Dec 2018"},{"key":"338_CR76","unstructured":"Locky ransomware actors turning to xored javascript to bypass traditional defenses. Proofpoint (2016). \nhttps:\/\/www.proofpoint.com\/us\/threat-insight\/post\/Locky-Ransomware-Actors-Turning-to-XORed-JavaScript-to-Bypass-Traditional-Defenses\n\n. Accessed Dec 2018"},{"key":"338_CR77","unstructured":"Geier, E.: How to keep your pc safe with sandboxing (2012). \nhttp:\/\/www.pcworld.com\/article\/247416\/how_to_keep_your_pc_safe_with_sandboxing.html\n\n. Accessed Dec 2018"},{"key":"338_CR78","unstructured":"Ferrie, P.: Attacks on more virtual machine emulators. Symantec Technology Exchange 55 (2007)"},{"key":"338_CR79","doi-asserted-by":"crossref","unstructured":"Deng, Z., Zhang, X., Xu, D.: Spider: Stealthy binary program instrumentation and debugging via hardware virtualization. In: Proceedings of the 29th Annual Computer Security Applications Conference. ACM, pp. 289\u2013298 (2013)","DOI":"10.1145\/2523649.2523675"},{"key":"338_CR80","doi-asserted-by":"crossref","unstructured":"Comar, P.M., Liu, L., Saha, S., Tan, P.-N., Nucci, A.: Combining supervised and unsupervised learning for zero-day malware detection. In: Proceedings of International Conference on Computer Communications, ser. INFOCOM. IEEE, pp. 2022\u20132030 (2013)","DOI":"10.1109\/INFCOM.2013.6567003"},{"key":"338_CR81","unstructured":"Gibbs, P.: Intrusion detection evasion techniques and case studies. Tech. Rep. (2017)"},{"issue":"3","key":"338_CR82","first-page":"21","volume":"8","author":"K Shaerpour","year":"2013","unstructured":"Shaerpour, K., Dehghantanha, A., Mahmod, R.: Trends in android malware detection. J. Digit. Forensics Secur. Law JDFSL 8(3), 21 (2013)","journal-title":"J. Digit. Forensics Secur. Law JDFSL"},{"key":"338_CR83","volume-title":"Intrusion Detection Evasion: How Attackers Get Past the Burglar Alarm","author":"C Del Carlo","year":"2003","unstructured":"Del Carlo, C.: Intrusion Detection Evasion: How Attackers Get Past the Burglar Alarm. SANS Great Lakes, Chicago, IL (2003)"},{"key":"338_CR84","unstructured":"Hern, A.: New ransomware employs tor to stay hidden from security (2014). \nhttps:\/\/www.theguardian.com\/technology\/2014\/jul\/25\/new-ransomware-employs-tor-onion-malware\n\n. Accessed Dec 2018"},{"key":"338_CR85","unstructured":"Ransomware defense validated design guide, Cisco, White paper, September 2016 (last update 2\/2017). \nhttps:\/\/www.cisco.com\/c\/dam\/en\/us\/solutions\/collateral\/enterprise-networks\/ransomware-defense\/ransomware-defense-dig.pdf\n\n. Accessed Dec 2018"},{"key":"338_CR86","unstructured":"The current state of ransomware: Cryptowall (2015). \nhttps:\/\/news.sophos.com\/en-us\/2015\/12\/17\/the-current-state-of-ransomware-cryptowall\/\n\n. Accessed Dec 2018"},{"key":"338_CR87","unstructured":"Biasini, N.: Threat spotlight: Angler lurking in the domain shadows (2015). \nhttps:\/\/blogs.cisco.com\/security\/talos\/angler-domain-shadowing#shadowing\n\n. Accessed Dec 2018"},{"key":"338_CR88","unstructured":"Biasini, N.: Threat spotlight: Cisco talos thwarts access to massive international exploit kit generating \\$ 60m annually from ransomware alone (2015). \nhttps:\/\/talosintelligence.com\/angler-exposed\/\n\n. Accessed Dec 2018"},{"key":"338_CR89","unstructured":"Botnets overshadowed by ransomware (in media) (2017). \nhttps:\/\/www.welivesecurity.com\/2017\/06\/07\/botnets-overshadowed-Ransomware-media\/\n\n. Accessed Dec 2018"},{"key":"338_CR90","unstructured":"Granger, S.: Social engineering fundamentals, part I: hacker tactics. (2001). \nhttps:\/\/www.symantec.com\/connect\/articles\/social-engineering-fundamentals-part-i-hacker-tactics\n\n. Accessed Dec 2018"},{"key":"338_CR91","volume-title":"Social Engineering: The Art of Human Hacking","author":"C Hadnagy","year":"2010","unstructured":"Hadnagy, C.: Social Engineering: The Art of Human Hacking. Wiley, New York (2010)"},{"issue":"3","key":"338_CR92","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1016\/j.techsoc.2010.07.001","volume":"32","author":"S Abraham","year":"2010","unstructured":"Abraham, S., Chengalur-Smith, I.: An overview of social engineering malware: trends, tactics, and implications. Technol. Soc. 32(3), 183\u2013196 (2010)","journal-title":"Technol. Soc."},{"key":"338_CR93","unstructured":"STERLING, B.: Ransomware: the basics. Wired (2017). \nhttps:\/\/www.wired.com\/beyond-the-beyond\/2017\/05\/ransomware-the-basics\/\n\n. Accessed Dec 2018"},{"key":"338_CR94","unstructured":"Giandomenico, N.: What is spear-phishing? defining and differentiating spear-phishing from phishing. Digital Guardian (2017). \nhttps:\/\/digitalguardian.com\/blog\/what-is-spear-phishing-defining-and-differentiating-spear-phishing-and-phishing\n\n. Accessed Dec 2018"},{"key":"338_CR95","unstructured":"Wisniewski, C.: Nothing is certain except death, taxes\u2014and tax scams, phishing and ransomware. SOPHOS LAb (2017). \nhttps:\/\/nakedsecurity.sophos.com\/2017\/04\/11\/nothing-is-certain-except-death-taxes-and-tax-scams-phishing-and-ransomware\/\n\n. Accessed Dec 2018"},{"key":"338_CR96","unstructured":"Various malware including crypto ransomware now used in email phishing scams. Trend Micro (2016). \nhttps:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/various-malware-including-crypto-ransomware-now-used-in-email-phishing-scams\n\n. Accessed Dec 2018"},{"key":"338_CR97","unstructured":"Cryptolocker ransomware infections. US-CERT (2013, November (last update 10\/2016)). \nhttps:\/\/www.us-cert.gov\/ncas\/alerts\/TA13-309A\n\n. Accessed Dec 2018"},{"key":"338_CR98","unstructured":"New teslacrypt ransomware arrives via spam. McAfee (2016). \nhttps:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/new-teslacrypt-ransomware-arrives-via-spam\/\n\n. Accessed Dec 2018"},{"key":"338_CR99","unstructured":"Stopping cerber ransomware during runtime. Barkly Research (2017). \nhttps:\/\/blog.barkly.com\/stopping-cerber-ransomware-during-runtime\n\n. Accessed Dec 2018"},{"key":"338_CR100","unstructured":"Best practices for dealing with phishing and next-generation malware, Osterman Research, White paper (2015)"},{"key":"338_CR101","unstructured":"Snow, J.: Petya ransomware eats your hard drives (2016). \nhttps:\/\/blog.kaspersky.com\/petya-ransomware\/11715\/\n\n. Accessed Dec 2018"},{"key":"338_CR102","unstructured":"Seals, T.: Cerber learns to evade machine learning. Infosecurity magazine (2017). \nhttps:\/\/www.infosecurity-magazine.com\/news\/cerber-learns-to-evade-machine\/\n\n. Accessed Dec 2018"},{"key":"338_CR103","unstructured":"Hern, A.: Major sites including new york times and bbc hit by \u2018ransomware\u2019 malvertising, (2016). \nhttps:\/\/www.theguardian.com\/technology\/2016\/mar\/16\/major-sites-new-york-times-bbc-ransomware-malvertising\n\n. Accessed Dec 2018"},{"key":"338_CR104","unstructured":"Savage, K., Coogan, P., Lau, H.: The evolution of ransomware, symantec security response. Tech. Rep. (2015)"},{"key":"338_CR105","unstructured":"Web-based malware distribution channels: A look at traffic redistribution systems. Symantec (2011). \nhttps:\/\/www.symantec.com\/connect\/blogs\/web-based-malware-distribution-channels-look-traffic-redistribution-systems\n\n. Accessed Dec 2018"},{"key":"338_CR106","unstructured":"C. P. T. I. . Research: Inside nuclear\u2019s core: Unraveling a ransomware-as-a-service infrastructure, (2016). \nhttps:\/\/blog.checkpoint.com\/2016\/05\/17\/inside-nuclears-core-unraveling-a-ransomware-as-a-service-infrastructure\/\n\n. Accessed Dec 2018"},{"key":"338_CR107","unstructured":"Exploit kit. Trend Micro. \nhttps:\/\/www.trendmicro.com\/vinfo\/us\/security\/definition\/exploit-kit\n\n. Accessed Dec 2018"},{"key":"338_CR108","doi-asserted-by":"crossref","unstructured":"Hopkins, M., Dehghantanha, A.: Exploit kits: the production line of the cybercrime economy? In: Proceedings of the International Conference on Information Security and Cyber Forensics, ser. InfoSec. IEEE, pp. 23\u201327 (2015)","DOI":"10.1109\/InfoSec.2015.7435501"},{"key":"338_CR109","unstructured":"C. P. R. Team: Inside nuclear\u2019s core: analyzing the nuclear exploit kit infrastructure\u2014part I. Check Point (2016). \nhttps:\/\/blog.checkpoint.com\/wp-content\/uploads\/2016\/04\/Inside-Nuclear-1-2.pdf\n\n. Accessed Dec 2018"},{"key":"338_CR110","unstructured":"Cabrera, E.: Exploits as a service: How the exploit kit ransomware tandem affects a company\u2019s bottom line. Trend Micro (2016). \nhttp:\/\/blog.trendmicro.com\/exploits-service-exploit-kit-ransomware-tandem-affects-companys-bottom-line\/\n\n. Accessed Dec 2018"},{"key":"338_CR111","unstructured":"Howard, F.: Exploring the blackhole exploit kit. Sophos Labs (2016). \nhttps:\/\/nakedsecurity.sophos.com\/exploring-the-blackhole-exploit-kit\/#Contents\n\n. Accessed Dec 2018"},{"key":"338_CR112","unstructured":"Beek, C., Furtak, A.: Targeted ransomware no longer a future threat. Intel, White paper (2016). \nhttp:\/\/www.intelsecurity.com\/advanced-threat-research\/content\/Analysis_SamSa_Ransomware.pdf\n\n. Accessed Dec 2018"},{"key":"338_CR113","unstructured":"These are the known targets in the petya ransomware attack so far (2017). \nhttp:\/\/fortune.com\/2017\/06\/27\/petya-ransomware-cyber-attack-targets\/\n\n. Accessed Dec 2018"},{"key":"338_CR114","doi-asserted-by":"crossref","unstructured":"Doh! new \u201cbart\u201d ransomware from threat actors spreading dridex and locky. Proofpoint (2016). \nhttps:\/\/www.proofpoint.com\/us\/threat-insight\/post\/New-Bart-Ransomware-from-Threat-Actors-Spreading-Dridex-and-Locky\n\n. Accessed Dec 2018","DOI":"10.1016\/S1353-4858(16)30097-6"},{"key":"338_CR115","unstructured":"S. security center: Ransom.hddcryptor (2016). \nhttps:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2016-091623-0636-99\n\n. Accessed Dec 2018"},{"key":"338_CR116","unstructured":"S. affairs wordpress: Mamba: The new full disk encryption ransomware family member (2016). \nhttp:\/\/securityaffairs.co\/wordpress\/51314\/malware\/mamba-ransomware.html\n\n. Accessed Dec 2018"},{"key":"338_CR117","unstructured":"Titova, V.: Satana: Ransomware from hell (2016). \nhttps:\/\/blog.kaspersky.com\/satana-ransomware\/12558\/\n\n. Accessed Dec 2018"},{"key":"338_CR118","unstructured":"Abrams, L.: Padcrypt: The first ransomware with live support chat and an uninstaller. Bleepingcomputer (2016). \nhttps:\/\/www.bleepingcomputer.com\/news\/security\/padcrypt-the-first-ransomware-with-live-support-chat-and-an-uninstaller\/\n\n. Accessed Dec 2018"},{"key":"338_CR119","unstructured":"What is the difference: viruses, worms, trojans, and bots? Cisco. \nhttp:\/\/www.cisco.com\/c\/en\/us\/about\/security-center\/virus-differences.html\n\n. Accessed Dec 2018"},{"key":"338_CR120","unstructured":"Connect to another computer using remote desktop connection. Microsoft. \nhttps:\/\/support.microsoft.com\/en-us\/help\/17463\/windows-7-connect-to-another-computer-remote-desktop-connection\n\n. Accessed Dec 2018"},{"key":"338_CR121","unstructured":"Paganini, P.: Teamxrat spreads ransomware via RDP brute-force attacks. Securityaffair (2016). \nhttp:\/\/securityaffairs.co\/wordpress\/51840\/cyber-crime\/teamxrat-rdp-ransomware.html\n\n. Accessed Dec 2018"},{"key":"338_CR122","unstructured":"Yaneza, J.: Brute force rdp attacks plant crysis ransomware. Trend Micro (2017). \nhttp:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/brute-force-rdp-attacks-plant-crysis-ransomware\/\n\n. Accessed Dec 2018"},{"key":"338_CR123","unstructured":"Microsoft security bulletin ms17-010\u2014critical. Microsoft. \nhttps:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx\n\n. Accessed Dec 2018"},{"key":"338_CR124","unstructured":"Wannacry\/wcry ransomware: How to defend against it. Trend Micro (2017). \nhttps:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/wannacry-wcry-ransomware-how-to-defend-against-it\n\n. Accessed Dec 2018"},{"key":"338_CR125","unstructured":"Kroustek, J.: Petya-based ransomware using eternalblue to infect computers around the world. Avast (2017). \nhttps:\/\/blog.avast.com\/petya-based-ransomware-using-eternalblue-to-infect-computers-around-the-worldboneidleware2016sophos\n\n. Accessed Dec 2018"},{"key":"338_CR126","unstructured":"Plohmann, D., Yakdan, K., Klatt, M., Bader, J., Gerhards-Padilla, E.: A comprehensive measurement study of domain generating malware. In: USENIX Security Symposium, pp. 263\u2013278 (2016)"},{"issue":"2","key":"338_CR127","doi-asserted-by":"publisher","first-page":"898","DOI":"10.1109\/SURV.2013.091213.00134","volume":"16","author":"S Khattak","year":"2014","unstructured":"Khattak, S., Ramay, N.R., Khan, K.R., Syed, A.A., Khayam, S.A.: A taxonomy of botnet behavior, detection, and defense. IEEE Commun. Surv. Tutor. 16(2), 898\u2013924 (2014)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"338_CR128","unstructured":"CHIPURICI, C.: What is a botnet and how to prevent your pc from being enslaved (2016). \nhttps:\/\/heimdalsecurity.com\/blog\/all-about-botnets\/\n\n. Accessed Dec 2018"},{"key":"338_CR129","unstructured":"Threat spotlight: Mighty morphin malware purveyors: Locky returns via necurs. Cisco - Talos group (2017). \nhttps:\/\/blogs.cisco.com\/security\/talos\/locky-returns-necurs\n\n. Accessed Dec 2018"},{"key":"338_CR130","unstructured":"Barth, B.: New jaff ransomware makes bold entrance via necurs spam campaign (2017). \nhttps:\/\/www.scmagazine.com\/new-jaff-ransomware-makes-bold-entrance-via-necurs-spam-campaign\/article\/661205\/\n\n. Accessed Dec 2018"},{"key":"338_CR131","unstructured":"Kelihos botnet delivering shade (troldesh) ransomware with no\\_more\\_ransom extension. Bleeping Computer (2016). \nhttps:\/\/www.bleepingcomputer.com\/news\/security\/kelihos-botnet-delivering-shade-troldesh-ransomware-with-no-more-ransom-extension\/\n\n. Accessed Dec 2018"},{"key":"338_CR132","unstructured":"Leong, R.: Understanding ransomware and strategies to defeat it. White paper"},{"key":"338_CR133","unstructured":"Danchev, D.: New ransomware locks pcs, demands premium sms for removal. ZDNet (2009). \nhttp:\/\/www.zdnet.com\/article\/new-ransomware-locks-pcs-demands-premium-sms-for-removal\/\n\n. Accessed Dec 2018"},{"key":"338_CR134","unstructured":"Lord, N.: A history of ransomware attacks: the biggest and worst ransomware attacks of all time. Digital Guardian (2017). \nhttps:\/\/digitalguardian.com\/blog\/history-ransomware-attacks-biggest-and-worst-ransomware-attacks-all-time\n\n. Accessed Dec 2018"},{"key":"338_CR135","unstructured":"Ducklin, P.: Ransomware that demands money and gives you back... nothing! (2016). \nhttps:\/\/nakedsecurity.sophos.com\/2016\/07\/13\/ransomware-that-demands-money-and-gives-you-back-nothing\/\n\n. Accessed Dec 2018"},{"key":"338_CR136","unstructured":"Ransomware recap: Tougher tactics and evasion techniques. Trend Micro (2017). \nhttps:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/ransomware-recap-tougher-tactics-and-evasion-techniques\n\n. Accessed Dec 2018"},{"key":"338_CR137","doi-asserted-by":"crossref","unstructured":"Kharraz, A., Kirda, E.: Redemption: Real-time protection against ransomware at end-hosts. In: Proceedings of the International Symposium on Research in Attacks, Intrusions, and Defenses, ser. RAID\u201917. Springer, pp. 98\u2013119 (2017)","DOI":"10.1007\/978-3-319-66332-6_5"},{"key":"338_CR138","unstructured":"Leveille, M.-E.M.: TorrentLocker: Ransomware in a country near you. ESET (2014). \nhttps:\/\/www.welivesecurity.com\/wp-content\/uploads\/2014\/12\/torrent_locker.pdf\n\n. Accessed Dec 2018"},{"key":"338_CR139","unstructured":"Crypt0l0cker and torrentlocker ransomware information guide and faq (2014). \nhttps:\/\/www.bleepingcomputer.com\/virus-removal\/torrentlocker-crypt0l0cker-ransomware-information#TorrentLocker\n\n. Accessed Dec 2018"},{"key":"338_CR140","unstructured":"Torrentlocker ransomware (2016). \nhttps:\/\/www.kaspersky.com\/resource-center\/threats\/torrentlocker-malware\n\n. Accessed Dec 2018"},{"key":"338_CR141","doi-asserted-by":"crossref","unstructured":"Mbol, F., Robert, J.-M., Sadighian, A.: An efficient approach to detect torrentlocker ransomware in computer systems. In: International Conference on Cryptology and Network Security. Springer, pp. 532\u2013541 (2016)","DOI":"10.1007\/978-3-319-48965-0_32"},{"key":"338_CR142","unstructured":"Padcrypt. NJCCIC (2016). \nhttps:\/\/www.cyber.nj.gov\/threat-profiles\/ransomware-variants\/padcrypt\n\n. Accessed Dec 2018"},{"key":"338_CR143","unstructured":"Abrams, L.: Padcrypt: The first ransomware with live support chat and an uninstaller (2016). \nhttps:\/\/www.bleepingcomputer.com\/news\/security\/padcrypt-the-first-ransomware-with-live-support-chat-and-an-uninstaller\/\n\n. Accessed Dec 2018"},{"key":"338_CR144","unstructured":"Marcos, M.: Ctb-locker ransomware spoofs chrome and facebook emails as lures, linked to phishing. TREND Micro (2015). \nhttps:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/ctb-locker-ransomware-spoofs-chrome-and-facebook-emails-as-lures-linked-to-phishing\/\n\n. Accessed Dec 2018"},{"key":"338_CR145","unstructured":"Ctb-locker ransomware includes freemium feature, extends deadline. TREND Micro (2015). \nhttps:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/ctb-locker-ransomware-includes-freemium-feature-extends-deadline\/\n\n. Accessed Dec 2018"},{"key":"338_CR146","unstructured":"Doevan, J.: About ctb locker\u2014another member from the family of crypto malware. TREND Micro (2017). \nhttps:\/\/www.2-spyware.com\/remove-ctb-locker-virus.html\n\n. Accessed Dec 2018"},{"key":"338_CR147","unstructured":"Altares, E.: New crypto-ransomware emerge in the wild. TREND Micro (2014). \nhttps:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/new-crypto-ransomware-emerge-in-the-wild\/\n\n. Accessed Dec 2018"},{"key":"338_CR148","unstructured":"Zahara, A.: What you need to know about ctb locker, a new generation ransomware [updated] (2015). \nhttps:\/\/heimdalsecurity.com\/blog\/ctb-locker-ransomware\/\n\n. Accessed Dec 2018"},{"key":"338_CR149","unstructured":"Paz, R.D.: Fakben team ransomware uses open source \u201cidden tear\u201d code (2015). \nhttps:\/\/www.fortinet.com\/blog\/threat-research\/fakben-team-ransomware-uses-open-source-hidden-tear-code.html\n\n. Accessed Dec 2018"},{"key":"338_CR150","unstructured":"Fakben ransomware. VinRansomware. \nhttp:\/\/www.vinransomware.com\/fakben-ransomware\n\n. Accessed Dec 2018"},{"key":"338_CR151","unstructured":"Paycrypt ransomware description. EnigmaSoft (2016). \nhttps:\/\/www.enigmasoftware.com\/paycryptransomware-removal\/\n\n. Accessed Dec 2018"},{"key":"338_CR152","unstructured":"Woods, A.: The important information about paycrypt virus (2016). \nhttps:\/\/www.2-spyware.com\/remove-paycrypt-ransomware-virus.html\n\n. Accessed Dec 2018"},{"key":"338_CR153","unstructured":"Geater, J.: How to remove PayCrypt. SolvuSoft (2016). \nhttps:\/\/www.solvusoft.com\/en\/malware\/ransomware\/paycrypt\/\n\n. Accessed Dec 2018"},{"key":"338_CR154","unstructured":"Esjay, C.: Remove paycrypt virus and decrypt files (2016). \nhttps:\/\/malwarefixes.com\/remove-paycrypt-virus-and-decrypt-files\/\n\n. Accessed Dec 2018"},{"key":"338_CR155","unstructured":"Krastev, V.: Remove paycrypt ransomware and restore id encrypted files (2016). \nhttps:\/\/sensorstechforum.com\/remove-paycrypt-ransomware-and-restore-id-encrypted-files\/\n\n. Accessed Dec 2018"},{"key":"338_CR156","unstructured":"Ransom:win32\/dmalocker (2016). \nhttps:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Ransom:Win32\/DMALocker&ThreatID=-2147258260\n\n. Accessed Dec 2018"},{"key":"338_CR157","unstructured":"Dma locker (2016). \nhttps:\/\/www.cyber.nj.gov\/threat-profiles\/ransomware-variants\/dma-locker\n\n. Accessed Dec 2018"},{"key":"338_CR158","unstructured":"Morelli, O.: Sage ransomware gets active online again (2017). \nhttps:\/\/www.2-spyware.com\/remove-sage-ransomware-virus.html\n\n. Accessed Dec 2018"},{"key":"338_CR159","unstructured":"Paganini, P.: Experts spotted a new strain of the Sage Ransomware that implements Anti-Analysis capabilities (2017). \nhttps:\/\/securityaffairs.co\/wordpress\/65021\/malware\/sage-ransomware-anti-analysis.html\n\n. Accessed Dec 2018"},{"key":"338_CR160","unstructured":"GoldSparrow: Paycrypt ransomware description (2016). \nhttps:\/\/www.enigmasoftware.com\/paycryptransomware-removal\/\n\n. Accessed Dec 2018"},{"key":"338_CR161","unstructured":"Kiguolis, L.: Globeimposter 2.0 ransomware receives yet another update in 2018 (2019). \nhttps:\/\/www.2-spyware.com\/remove-globeimposter-2-0-ransomware-virus.html\n\n. Accessed Dec 2018"},{"key":"338_CR162","unstructured":"Zhang, X.: Analysis of new globeimposter ransomware variant (2017). \nhttps:\/\/www.fortinet.com\/blog\/threat-research\/analysis-of-new-globeimposter-ransomware-variant.html\n\n. Accessed Dec 2018"},{"key":"338_CR163","unstructured":"Globeimposter ransomware payment and decryption statistics (2019). \nhttps:\/\/www.coveware.com\/globelmposter-ransomware\n\n. Accessed Dec 2018"},{"key":"338_CR164","unstructured":"Moench, B.: Ransom.globeimposter. Symantec (2017). \nhttps:\/\/www.symantec.com\/security-center\/writeup\/2017-052604-1409-99\n\n. Accessed Dec 2018"},{"key":"338_CR165","unstructured":"Incidents of ransomware on the rise\u2014protect yourself and your organization (2016). \nhttps:\/\/www.fbi.gov\/news\/stories\/incidents-of-ransomware-on-the-rise\n\n. Accessed Dec 2018"},{"issue":"4","key":"338_CR166","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1080\/10658980701576412","volume":"16","author":"X Luo","year":"2007","unstructured":"Luo, X., Liao, Q.: Awareness education as the key to ransomware prevention. Inf. Syst. Secur. 16(4), 195\u2013202 (2007)","journal-title":"Inf. Syst. Secur."},{"issue":"2","key":"338_CR167","doi-asserted-by":"publisher","first-page":"624","DOI":"10.4338\/ACI-2016-04-SOA-0064","volume":"7","author":"DF Sittig","year":"2016","unstructured":"Sittig, D.F., Singh, H.: A socio-technical approach to preventing, mitigating, and recovering from ransomware attacks. Appl. Clin. Inf. 7(2), 624 (2016)","journal-title":"Appl. Clin. Inf."},{"key":"338_CR168","doi-asserted-by":"crossref","unstructured":"Al-rimy, B.A.S., Maarof, M.A., Shaid, S.Z.M.: A 0-day aware crypto-ransomware early behavioral detection framework. In: Proceedings of the International Conference of Reliable Information and Communication Technology. Springer, pp. 758\u2013766 (2017)","DOI":"10.1007\/978-3-319-59427-9_78"},{"key":"338_CR169","doi-asserted-by":"crossref","unstructured":"Continella, A., Guagnelli, A., Zingaro, G., De Pasquale, G., Barenghi, A., Zanero, S., Maggi, F.: Shieldfs: a self-healing, ransomware-aware filesystem. In: Proceedings of the 32nd Annual Conference on Computer Security Applications, ser. ACSAC\u201916. ACM, pp. 336\u2013347 (2016)","DOI":"10.1145\/2991079.2991110"},{"key":"338_CR170","doi-asserted-by":"crossref","unstructured":"Ahmadian, M.M., Shahriari, H.R., Ghaffarian, S.M.: Connection-monitor & connection-breaker: a novel approach for prevention and detection of high survivable ransomwares. In: Proceedings of the International Iranian Society of Cryptology Conference on Information Security and Cryptology, ser. ISCISC\u201915. IEEE, pp. 79\u201384 (2015)","DOI":"10.1109\/ISCISC.2015.7387902"},{"key":"338_CR171","unstructured":"Sgandurra, D., Mu\u00f1oz-Gonz\u00e1lez, L., Mohsen, R., Lupu, E.C.: Automated dynamic analysis of ransomware: Benefits, limitations and use for detection (2016). arXiv preprint \narXiv:1609.03020"},{"issue":"7","key":"338_CR172","doi-asserted-by":"publisher","first-page":"3065","DOI":"10.1007\/s11227-016-1825-5","volume":"73","author":"JK Lee","year":"2017","unstructured":"Lee, J.K., Moon, S.Y., Park, J.H.: Cloudrps: a cloud analysis based enhanced ransomware prevention system. J. Supercomput. 73(7), 3065\u20133084 (2017)","journal-title":"J. Supercomput."},{"key":"338_CR173","doi-asserted-by":"crossref","unstructured":"Moore, C.: Detecting ransomware with honeypot techniques. In: Proceedings of the Cybersecurity and Cyberforensics Conference, ser. CCC\u201916. IEEE. pp. 77\u201381 (2016)","DOI":"10.1109\/CCC.2016.14"},{"key":"338_CR174","unstructured":"Etsi tr 103 305-1 v2.1.1\u2014cyber; critical security controls for effective cyber defence; part 1: the critical security controls, 2016, Technical Report (2014)"},{"key":"338_CR175","doi-asserted-by":"crossref","unstructured":"Kolodenker, E., Koch, W., Stringhini, G., Egele, M.: Paybreak: Defense against cryptographic ransomware. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ser. AsiaCCS\u201917. ACM, pp. 599\u2013611 (2017)","DOI":"10.1145\/3052973.3053035"},{"issue":"6","key":"338_CR176","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/MNET.2016.1600110NM","volume":"30","author":"K Cabaj","year":"2016","unstructured":"Cabaj, K., Mazurczyk, W.: Using software-defined networking for ransomware mitigation: the case of cryptowall. IEEE Netw. 30(6), 14\u201320 (2016)","journal-title":"IEEE Netw."},{"key":"338_CR177","unstructured":"Yang, T., Yang, Y., Qian, K., Lo, D.C.-T., Qian, Y., Tao, L.: Automated detection and analysis for android ransomware. In: Proceedings of the 17th International Conference on High Performance Computing and Communications, ser. HPCC,CSS,ICESS\u201915. IEEE, pp. 1338\u20131343 (2015)"},{"key":"338_CR178","doi-asserted-by":"crossref","unstructured":"Mercaldo, F., Nardone, V., Santone, A., Visaggio, C.A.: Ransomware steals your phone. formal methods rescue it. In: Proceedings of the International Conference on Formal Techniques for Distributed Objects, Components, and Systems, ser. Forte\u201916. Springer, pp. 212\u2013221 (2016)","DOI":"10.1007\/978-3-319-39570-8_14"},{"key":"338_CR179","doi-asserted-by":"crossref","unstructured":"Mercaldo, F., Nardone, V., Santone, A.: Ransomware inside out. In: Proceedings of the 11th International Conference on Availability, Reliability and Security, ser. ARES\u201916. IEEE, pp. 628\u2013637 (2016)","DOI":"10.1109\/ARES.2016.35"},{"key":"338_CR180","unstructured":"Hong, S., Liu, C., Ren, B., Chen, J.: Sdguard: An android application implementing privacy protection and ransomware detection. In: Proceedings of the International Conference on Mobile Systems, Applications, and Services, ser. MobiSys\u201917. ACM, pp. 149\u2013149 (2017)"},{"key":"338_CR181","doi-asserted-by":"crossref","unstructured":"Maiorca, D., Mercaldo, F., Giacinto, G., Visaggio, C.A., Martinelli, F.: R-packdroid: Api package-based characterization and detection of mobile ransomware. In: Proceedings of the Symposium on Applied Computing, ser. SAC\u201917. ACM, pp. 1718\u20131723 (2017)","DOI":"10.1145\/3019612.3019793"},{"key":"338_CR182","doi-asserted-by":"publisher","first-page":"144","DOI":"10.1016\/j.cose.2018.01.001","volume":"74","author":"BAS Al-rimy","year":"2018","unstructured":"Al-rimy, B.A.S., Maarof, M.A., Shaid, S.Z.M.: Ransomware threat success factors, taxonomy, and countermeasures: a survey and research directions. Comput. Secur. 74, 144\u2013166 (2018)","journal-title":"Comput. Secur."},{"key":"338_CR183","unstructured":"Kevin, S., Coogan, P., Lau, H.: The evolution of ransomware. Symantec, White paper (2015). \nhttp:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/the-evolution-of-ransomware.pdf"},{"issue":"9","key":"338_CR184","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1353-4858(16)30086-1","volume":"2016","author":"R Brewer","year":"2016","unstructured":"Brewer, R.: Ransomware attacks: detection, prevention and cure. Netw. Secur. 2016(9), 5\u20139 (2016)","journal-title":"Netw. Secur."},{"issue":"5","key":"338_CR185","first-page":"4115","volume":"2","author":"TT Gotora","year":"2014","unstructured":"Gotora, T.T., Zvarevashe, K., Nandan, P.: A survey on the security fight against ransomware and trojans in android. Int. J. Innov. Res. Comput. Commun. Eng. 2(5), 4115\u20134123 (2014)","journal-title":"Int. J. Innov. Res. Comput. Commun. Eng."},{"issue":"4","key":"338_CR186","doi-asserted-by":"publisher","first-page":"2242","DOI":"10.1109\/COMST.2015.2457491","volume":"17","author":"N Hoque","year":"2015","unstructured":"Hoque, N., Bhattacharyya, D.K., Kalita, J.K.: Botnet in ddos attacks: trends and challenges. IEEE Commun. Surv. Tutor. 17(4), 2242\u20132270 (2015)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"338_CR187","doi-asserted-by":"publisher","first-page":"2768","DOI":"10.1109\/COMST.2017.2749442","volume":"19","author":"G Vormayr","year":"2017","unstructured":"Vormayr, G., Zseby, T., Fabini, J.: Botnet communication patterns. IEEE Commun. Surv. Tutor. 19, 2768\u20132796 (2017)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"338_CR188","unstructured":"Rutkowska, J.: Introducing stealth malware taxonomy. COSEINC Advanced Malware Labs 1\u20139 (2006)"},{"issue":"3","key":"338_CR189","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1007\/s11416-008-0086-0","volume":"4","author":"G Jacob","year":"2008","unstructured":"Jacob, G., Debar, H., Filiol, E.: Behavioral detection of malware: from a survey towards an established taxonomy. J. Comput. Virol. 4(3), 251\u2013266 (2008)","journal-title":"J. Comput. Virol."},{"key":"338_CR190","doi-asserted-by":"publisher","first-page":"756","DOI":"10.1016\/j.cose.2017.09.013","volume":"77","author":"P Black","year":"2017","unstructured":"Black, P., Gondal, I., Layton, R.: A survey of similarities in banking malware behaviours. Comput. Secur. 77, 756\u2013772 (2017)","journal-title":"Comput. Secur."},{"issue":"3","key":"338_CR191","doi-asserted-by":"publisher","first-page":"891","DOI":"10.1007\/s11219-017-9368-4","volume":"26","author":"P Yan","year":"2018","unstructured":"Yan, P., Yan, Z.: A survey on dynamic mobile malware detection. Softw. Qual. J. 26(3), 891\u2013919 (2018)","journal-title":"Softw. Qual. J."},{"key":"338_CR192","unstructured":"New ransomware to target industrial systems (2017). \nhttp:\/\/www.informationsecuritybuzz.com\/expert-comments\/new-ransomware-target-industrial-systems\/\n\n. Accessed Dec 2018"},{"key":"338_CR193","unstructured":"Khandelwal, S.: This ransomware malware could poison your water supply if not paid (2017). \nhttp:\/\/thehackernews.com\/2017\/02\/scary-scada-ransomware.html\n\n. Accessed Dec 2018"},{"key":"338_CR194","unstructured":"Khandelwal, S.: Android ransomware now targets your smart tv, too! The hacker news (2016). \nhttp:\/\/thehackernews.com\/2016\/06\/smart-tv-ransomware.html\n\n. Accessed Dec 2018"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-019-00338-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-019-00338-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-019-00338-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,8,5]],"date-time":"2020-08-05T23:48:22Z","timestamp":1596671302000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-019-00338-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,8,7]]},"references-count":194,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2019,12]]}},"alternative-id":["338"],"URL":"https:\/\/doi.org\/10.1007\/s11416-019-00338-7","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,8,7]]},"assertion":[{"value":"24 December 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 July 2019","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 August 2019","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}