Text
DETEKSI REMCOS REMOTE ACCESS TROJAN (RAT) PADA PHISHING EMAIL CORONA VIRUS DENGAN METODE REVERSE ENGINEERING
Remote Access Trojan (RAT) is a special type of remote access software commonly used for malicious purposes, in which the installation is performed without the user's consent, the remote control then performed silently, and the program hides in the system to avoid detection. Cyber attackers send phishing emails based on COVID-19 themes that attached with malware to disable networks or to steal data and credentials. This study uses reverse engineering and dynamic analysis methods to detect Remcos RAT malware. The results of this study indicate that the Remcos RAT malware used to control remote target computers. The malware infection method uses the TLSv1.2 protocol with RC4 encryption on port 1234 to communicate with the target computer. Malware activity then retrieves target computer information and the capabilities of creating, writing, deleting files, taking screenshots, and recording audio.
Inventory Code | Barcode | Call Number | Location | Status |
---|---|---|---|---|
2307000286 | T86157 | T861572023 | Central Library (Referens) | Available but not for loan - Not for Loan |
No other version available