Files
de_Jamblinne_07151900_2025.pdf
Open access - Adobe PDF
- 1.15 MB
Details
- Supervisors
- Faculty
- Degree label
- Abstract
- This thesis explores the application of symbolic execution to malware analysis, focusing on the WannaCry and GonnaCry ransomware families. Using the SEMA toolchain in combination with Ghidra, we analyzed these ransomware samples both statically and symbolically to investigate their behavior and identify external function calls. While we successfully achieved full path coverage for GonnaCry and one of the three components of WannaCry, the analysis also revealed several limitations and challenges associated with symbolic execution. To support this effort, we implemented nearly one hundred custom SimProcedures, developed a custom plugin, and integrated an additional plugin from a different version of the toolchain. Furthermore, we proposed several improvements aimed at enhancing symbolic execution capabilities and addressing the identified shortcomings. Our findings highlight both the potential and the limitations of symbolic analysis in the context of ransomware research, offering insights into its effectiveness and areas for future development.