Claim Missing Document
Check
Articles

Found 2 Documents
Search
Journal : CogITo Smart Journal

LockBit 2.0 Ransomware: Analysis of infection, persistence, prevention mechanism Eliando Eliando; Yunianto Purnomo
CogITo Smart Journal Vol. 8 No. 1 (2022): Cogito Smart Journal
Publisher : Fakultas Ilmu Komputer, Universitas Klabat

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.31154/cogito.v8i1.356.232-243

Abstract

This research was carried out due to the prevalence of ransomware attacks, especially in Indonesia against data located at Endpoints, in early 2022 ransomware was enough to horrify the news in cyberspace and one of the ransomware that is quite worrying in Indonesia is LockBit 2.0 ransomware, so research is needed against the ransomware. The method used to research the ransomware is static analysis and dynamic analysis which will show the infection and persistence of the LockBit 2.0 ransomware, the static analysis method is used by reverse engineering the portable executable (PE) file and the dynamic analysis method is carried out by running the ransomware. then look at the operating activities, the resources used, and including the network activities carried out by the ransomware and its impact on the affected operating system, so that a scenario for prevention methods can be made, where in this study we can see the real impact of the attacks carried out by the LockBit 2.0 ransomware which is also part of ransomware-as-a-services (Raas), as well as 5 steps that can be taken to avoid it and can make anyone aware with ransomware attacks that’s why create artificial intelligence that accommodates such vigilance is important.Keywords—Ransomware, LockBit 2.0, Infection, Persistence, Prevention
Ransomware Lockbit Black di Dalam Reverse Shell: Analisis Infeksi Eliando Eliando; Ary Budi Warsito
CogITo Smart Journal Vol. 9 No. 2 (2023): Cogito Smart Journal
Publisher : Fakultas Ilmu Komputer, Universitas Klabat

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.31154/cogito.v9i2.494.228-240

Abstract

 This research was conducted due to the widespread occurrence of ransomware attacks, especially in Indonesia, against data that is at the endpoint and has even reached the banking sector. to estimate the likelihood of future ransomware infections. LockBit 3 ransomware aka LockBit Black is ransomware that has penetrated one of the banks in Indonesia, along with a reverse shell which is an infection method that cannot be recognized by every protection so that when combined it can penetrate all sides of protection. The method used to research the combination of ransomware and reverse shell is a hybrid analysis with a combination of static and dynamic analysis, to see every capability that can be carried out by the LockBit Black ransomware and channeled through the reverse shell. In this research, we can see the real impact of the attack and estimate protection in the future from the results of this analysis so that variant ransomware attacks from LockBit can be overcome.