CPC H04L 63/145 (2013.01) [G06F 16/955 (2019.01); G06Q 20/102 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01)] | 20 Claims |
1. A method for cryptocurrency-based malware detection, the method comprising:
analyzing a screenshot of a ransomware note displayed on an end user device, associated with a cryptocurrency-based malware or ransomware attack;
based on the analyzing:
identifying a uniform resource locator (URL) of a decryptor download site of the cryptocurrency-based malware or ransomware attack; and
identifying a cryptocurrency payment address of the cryptocurrency-based malware or ransomware attack;
identifying additional cryptocurrency addresses included in a sample code of the cryptocurrency-based malware or ransomware attack;
storing the additional cryptocurrency addresses to a malware or ransomware attack database;
tracing a ransom payment paid to the cryptocurrency payment address in response to the cryptocurrency-based malware or ransomware attack;
based on the tracing of the ransom payment paid to the cryptocurrency payment address, storing the cryptocurrency payment address in the malware or ransomware attack database; and
identifying a proposed cryptocurrency transaction that includes an address that is included in the malware or ransomware attack database.
|