{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,24]],"date-time":"2026-08-24T00:19:50Z","timestamp":1787530790476,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":48,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,4,2]],"date-time":"2017-04-02T00:00:00Z","timestamp":1491091200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-15-1-2948"],"award-info":[{"award-number":["N00014-15-1-2948"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"name":"EPSRC","award":["EP\/N008448\/1"],"award-info":[{"award-number":["EP\/N008448\/1"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,4,2]]},"DOI":"10.1145\/3052973.3053035","type":"proceedings-article","created":{"date-parts":[[2017,3,31]],"date-time":"2017-03-31T08:22:54Z","timestamp":1490948574000},"page":"599-611","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":165,"title":["PayBreak"],"prefix":"10.1145","author":[{"given":"Eugene","family":"Kolodenker","sequence":"first","affiliation":[{"name":"Boston University &amp; MITRE, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"William","family":"Koch","sequence":"additional","affiliation":[{"name":"Boston University, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gianluca","family":"Stringhini","sequence":"additional","affiliation":[{"name":"University College London, London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Manuel","family":"Egele","sequence":"additional","affiliation":[{"name":"Boston University, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2017,4,2]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Alma ransomware: Analysis of a new ransomware threat (and a decrypter!). https:\/\/info.phishlabs.com\/blog\/alma-ransomware-analysis-of-a-new-ransomware-threat-and-a-decrypter.  Alma ransomware: Analysis of a new ransomware threat (and a decrypter!). https:\/\/info.phishlabs.com\/blog\/alma-ransomware-analysis-of-a-new-ransomware-threat-and-a-decrypter."},{"key":"e_1_3_2_1_2_1","unstructured":"Cryptowall teslacrypt and locky: A statistical perspective. http:\/\/blog.fortinet.com\/post\/cryptowall-teslacrypt-and-locky-a-statistical-perspective.  Cryptowall teslacrypt and locky: A statistical perspective. http:\/\/blog.fortinet.com\/post\/cryptowall-teslacrypt-and-locky-a-statistical-perspective."},{"key":"e_1_3_2_1_3_1","unstructured":"Cybercriminals rake in$325m from cryptowall ransomware: report. http:\/\/www.washingtontimes.com\/news\/2015\/nov\/2\/cybercriminals-rake-in-325m-cryptowall-ransomware\/.  Cybercriminals rake in$325m from cryptowall ransomware: report. http:\/\/www.washingtontimes.com\/news\/2015\/nov\/2\/cybercriminals-rake-in-325m-cryptowall-ransomware\/."},{"key":"e_1_3_2_1_4_1","unstructured":"Downloading and using the trend micro ransomware file decryptor. https:\/\/success.trendmicro.com\/solution\/1114221.  Downloading and using the trend micro ransomware file decryptor. https:\/\/success.trendmicro.com\/solution\/1114221."},{"key":"e_1_3_2_1_5_1","unstructured":"Dxxd ransomware decrypter. https:\/\/github.com\/eugenekolo\/dxxd-decrypter.  Dxxd ransomware decrypter. https:\/\/github.com\/eugenekolo\/dxxd-decrypter."},{"key":"e_1_3_2_1_6_1","unstructured":"Fbi suggests ransomware victims to pay ransom money. http:\/\/thehackernews.com\/2015\/10\/fbi-ransomware-malware.html.  Fbi suggests ransomware victims to pay ransom money. http:\/\/thehackernews.com\/2015\/10\/fbi-ransomware-malware.html."},{"key":"e_1_3_2_1_7_1","unstructured":"Ida f.l.i.r.t. https:\/\/hex-rays.com\/products\/ida\/tech\/flirt\/.  Ida f.l.i.r.t. https:\/\/hex-rays.com\/products\/ida\/tech\/flirt\/."},{"key":"e_1_3_2_1_8_1","unstructured":"Kaspersky announces 'death' of coinvault bitcryptor ransomware. http:\/\/www.theregister.co.uk\/2015\/11\/02\/kaspersky_announces_ death_of_coinvault_bitcryptor_ransomware\/.  Kaspersky announces 'death' of coinvault bitcryptor ransomware. http:\/\/www.theregister.co.uk\/2015\/11\/02\/kaspersky_announces_ death_of_coinvault_bitcryptor_ransomware\/."},{"key":"e_1_3_2_1_9_1","unstructured":"Pokemongo ransomware comes with some clever tricks. https:\/\/blog.malwarebytes.com\/threat-analysis\/2016\/08\/pokemongo-ransomware-comes-with-some-clever-tricks\/.  Pokemongo ransomware comes with some clever tricks. https:\/\/blog.malwarebytes.com\/threat-analysis\/2016\/08\/pokemongo-ransomware-comes-with-some-clever-tricks\/."},{"key":"e_1_3_2_1_10_1","unstructured":"Ransomware. http:\/\/www.trendmicro.com\/vinfo\/us\/security\/definition\/ransomware#List_of_Known_Ransomware_Families.  Ransomware. http:\/\/www.trendmicro.com\/vinfo\/us\/security\/definition\/ransomware#List_of_Known_Ransomware_Families."},{"key":"e_1_3_2_1_11_1","unstructured":"Remove gerkaman@aol.com ransomware. http:\/\/www.virusresearch.org\/remove-gerkamanaol-com-ransomware\/.  Remove gerkaman@aol.com ransomware. http:\/\/www.virusresearch.org\/remove-gerkamanaol-com-ransomware\/."},{"key":"e_1_3_2_1_12_1","unstructured":"Researchers break encryption of marsjoke ransomware. http:\/\/www.securityweek.com\/researchers-break-encryption-marsjoke-ransomware.  Researchers break encryption of marsjoke ransomware. http:\/\/www.securityweek.com\/researchers-break-encryption-marsjoke-ransomware."},{"key":"e_1_3_2_1_13_1","unstructured":"The story of yet another ransom-fail-ware. http:\/\/esec-lab.sogeti.com\/posts\/2016\/06\/07\/the-story-of-yet-another-ransomfailware.html.  The story of yet another ransom-fail-ware. http:\/\/esec-lab.sogeti.com\/posts\/2016\/06\/07\/the-story-of-yet-another-ransomfailware.html."},{"key":"e_1_3_2_1_14_1","unstructured":"Themida. http:\/\/www.oreans.com\/themida.php.  Themida. http:\/\/www.oreans.com\/themida.php."},{"key":"e_1_3_2_1_15_1","unstructured":"This weird ransomware strain spreads like a virus in the cloud. https:\/\/blog.knowbe4.com\/new-virlock-ransomware-strain-spreads-stealthily-via-cloud-storage.  This weird ransomware strain spreads like a virus in the cloud. https:\/\/blog.knowbe4.com\/new-virlock-ransomware-strain-spreads-stealthily-via-cloud-storage."},{"key":"e_1_3_2_1_16_1","unstructured":"Threat spotlight: Teslacrypt -- decrypt it yourself. http:\/\/blogs.cisco.com\/security\/talos\/teslacrypt.  Threat spotlight: Teslacrypt -- decrypt it yourself. http:\/\/blogs.cisco.com\/security\/talos\/teslacrypt."},{"key":"e_1_3_2_1_17_1","unstructured":"Zynamics bindiff. https:\/\/www.zynamics.com\/bindiff.html.  Zynamics bindiff. https:\/\/www.zynamics.com\/bindiff.html."},{"key":"e_1_3_2_1_18_1","volume-title":"IEEE 36th International Conference on Distributed Computing Systems","year":"2016"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/1815744.1815746"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2430553.2430557"},{"key":"e_1_3_2_1_21_1","volume-title":"Usenix security symposium","author":"Caballero J.","year":"2011"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653737"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"crossref","unstructured":"J. Callas L. Donnerhacke H. Finney and R. Thayer. RFC2440: OpenPGP Message Format 1998.   J. Callas L. Donnerhacke H. Finney and R. Thayer. RFC2440: OpenPGP Message Format 1998.","DOI":"10.17487\/rfc2440"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382217"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991110"},{"key":"e_1_3_2_1_26_1","unstructured":"Darren Pauli. Cryptowall 4.0: Update makes world's worst ransomware worse still - The Register. http:\/\/www.theregister.co.uk\/2015\/11\/09\/cryptowall_40\/.  Darren Pauli. Cryptowall 4.0: Update makes world's worst ransomware worse still - The Register. http:\/\/www.theregister.co.uk\/2015\/11\/09\/cryptowall_40\/."},{"key":"e_1_3_2_1_27_1","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Egele M.","year":"2014"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"S. Garfinkel P. Farrell V. Roussev and G. Dinolt. Bringing science to digital forensics with standardized forensic corpora 2009.  S. Garfinkel P. Farrell V. Roussev and G. Dinolt. Bringing science to digital forensics with standardized forensic corpora 2009.","DOI":"10.1016\/j.diin.2009.06.016"},{"key":"e_1_3_2_1_29_1","unstructured":"A. Gazet. Comparative analysis of various ransomware virii. Computer virology.  A. Gazet. Comparative analysis of various ransomware virii. Computer virology."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382283"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23644-0_3"},{"key":"e_1_3_2_1_32_1","unstructured":"High-Tech Bridge Security Research. RansomWeb: emerging website threat that may outshine DDoS data theft and defacements? https:\/\/www.htbridge.com\/blog\/ransomweb\\_emerging\\_website\\_threat.html.  High-Tech Bridge Security Research. RansomWeb: emerging website threat that may outshine DDoS data theft and defacements? https:\/\/www.htbridge.com\/blog\/ransomweb\\_emerging\\_website\\_threat.html."},{"key":"e_1_3_2_1_33_1","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Kharraz A.","year":"2016"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-20550-2_1"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2714576.2714639"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1080\/10658980701576412"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1476589.1476628"},{"key":"e_1_3_2_1_38_1","unstructured":"D. Nazarov and O. Emelyanova. Blackmailer: The story of gpcode. https:\/\/securelist.com\/analysis\/publications\/36089\/blackmailer-the-story-of-gpcode\/.  D. Nazarov and O. Emelyanova. Blackmailer: The story of gpcode. https:\/\/securelist.com\/analysis\/publications\/36089\/blackmailer-the-story-of-gpcode\/."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"B. Ramsdell. RFC3851: Secure\/Multipurpose Internet Mail Extensions (S\/MIME) Version 3.1 Message Specification 2004.  B. Ramsdell. RFC3851: Secure\/Multipurpose Internet Mail Extensions (S\/MIME) Version 3.1 Message Specification 2004.","DOI":"10.17487\/rfc3851"},{"key":"e_1_3_2_1_40_1","unstructured":"G. Saito and G. Stringhini. Master of puppets: Analyzing and attacking a botnet for fun and profit. arXiv preprint arXiv:1511.06090 2015.  G. Saito and G. Stringhini. Master of puppets: Analyzing and attacking a botnet for fun and profit. arXiv preprint arXiv:1511.06090 2015."},{"key":"e_1_3_2_1_41_1","unstructured":"K. Savage P. Coogan and H. Lau. The evolution of ransomware. http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/the-evolution-of-ransomware.pdf.  K. Savage P. Coogan and H. Lau. The evolution of ransomware. http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/the-evolution-of-ransomware.pdf."},{"key":"e_1_3_2_1_42_1","unstructured":"B. Schneier. Memo to the Amateur Cipher Designer.  B. Schneier. Memo to the Amateur Cipher Designer."},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings of Network and Distributed Systems Security Symposium (NDSS)","author":"Sharif M. I.","year":"2008"},{"key":"e_1_3_2_1_44_1","unstructured":"L. Sun. Reform: A framework for malware packer analysis using information theory and statistical methods 2010.  L. Sun. Reform: A framework for malware packer analysis using information theory and statistical methods 2010."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.5555\/1813084.1813102"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.5555\/1947337.1947357"},{"key":"e_1_3_2_1_47_1","volume-title":"John Wiley & Sons","author":"Young A.","year":"2004"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"crossref","unstructured":"A. L. Young and M. M. Yung. An implementation of cryptoviral extortion using microsoft's crypto api. 2005.  A. L. Young and M. M. Yung. An implementation of cryptoviral extortion using microsoft's crypto api. 2005.","DOI":"10.1007\/s10207-006-0082-7"}],"event":{"name":"ASIA CCS '17: ACM Asia Conference on Computer and Communications Security","location":"Abu Dhabi United Arab Emirates","acronym":"ASIA CCS '17","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3052973.3053035","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3052973.3053035","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3052973.3053035","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:03:35Z","timestamp":1750201415000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3052973.3053035"}},"subtitle":["Defense Against Cryptographic Ransomware"],"short-title":[],"issued":{"date-parts":[[2017,4,2]]},"references-count":48,"alternative-id":["10.1145\/3052973.3053035","10.1145\/3052973"],"URL":"https:\/\/doi.org\/10.1145\/3052973.3053035","relation":{},"subject":[],"published":{"date-parts":[[2017,4,2]]},"assertion":[{"value":"2017-04-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}