RANSOMWARE KEY EXTRACTOR AND RECOVERY SYSTEM

    公开(公告)号:US20180114020A1

    公开(公告)日:2018-04-26

    申请号:US15334311

    申请日:2016-10-26

    CPC classification number: G06F21/566 G06F2221/034 G06F2221/2107

    Abstract: In one embodiment, a system includes a central processing unit (CPU) to identify a ransomware process which encrypted a plurality of files yielding a plurality of encrypted files, in response to identifying the ransomware process, dump a memory space and a state of the CPU yielding a memory dump, and search the memory dump for a plurality of candidate encryption keys, and a decryption engine to attempt to decrypt at least one encrypted file of the plurality of encrypted files with different candidate encryption keys of the plurality of candidate encryption keys until the at least one encrypted file is successfully decrypted with one candidate encryption key of the different candidate encryption keys, and decrypt the plurality of encrypted files using the one candidate encryption key. Related apparatus and methods are also described.

Patent Agency Ranking