Ares Galaxy: analysis of the behavior and the source code
Abstract
Ares Galaxy is one of the most popular programs used to download music files and videos, among others. These types of programs are based on the architecture of communication Peer to Peer that allows the exchange of information among the computers of the network. File download programs are very popular and easy to use. However, many times users are unaware that this type of information exchange has risks, such as favoring the trafficking of child pornography. Therefore, it is important to investigate whether Ares Galaxy makes modifications to the operating system without the user's consent.
To detect possible modifications to the operating system registry and its configuration, three paths were followed. The files generated and modified during the installation and use of Ares Galaxy were observed, and then, analyzed with forensics software to understand the content of encrypted files. The behavior of Ares Galaxy was also examined from its source code.
Some of the tools used in this project of the Compiladores subject were: Delphi grammar, regular expressions for the detection of elements of interest within the program and other tools related to compilers and translators
Downloads
This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.