US 11,888,892 B2
Cryptocurrency based malware and ransomware detection systems and methods
David Jevans, Menlo Park, CA (US); and Rudi Cilibrasi, Los Gatos, CA (US)
Assigned to CipherTrace, Inc., Purchase, NY (US)
Filed by CipherTrace, Inc., Purchase, NY (US)
Filed on Dec. 3, 2022, as Appl. No. 18/061,460.
Application 18/061,460 is a continuation of application No. 16/685,928, filed on Nov. 15, 2019, granted, now 11,546,373.
Claims priority of provisional application 62/770,113, filed on Nov. 20, 2018.
Claims priority of provisional application 62/770,109, filed on Nov. 20, 2018.
Prior Publication US 2023/0095875 A1, Mar. 30, 2023
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01); G06F 16/955 (2019.01); G06Q 20/10 (2012.01)
CPC H04L 63/145 (2013.01) [G06F 16/955 (2019.01); G06Q 20/102 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method for cryptocurrency-based malware detection, the method comprising:
analyzing a screenshot of a ransomware note displayed on an end user device, associated with a cryptocurrency-based malware or ransomware attack;
based on the analyzing:
identifying a uniform resource locator (URL) of a decryptor download site of the cryptocurrency-based malware or ransomware attack; and
identifying a cryptocurrency payment address of the cryptocurrency-based malware or ransomware attack;
identifying additional cryptocurrency addresses included in a sample code of the cryptocurrency-based malware or ransomware attack;
storing the additional cryptocurrency addresses to a malware or ransomware attack database;
tracing a ransom payment paid to the cryptocurrency payment address in response to the cryptocurrency-based malware or ransomware attack;
based on the tracing of the ransom payment paid to the cryptocurrency payment address, storing the cryptocurrency payment address in the malware or ransomware attack database; and
identifying a proposed cryptocurrency transaction that includes an address that is included in the malware or ransomware attack database.