This post is by a banned member (madris06) - Unhide
29 July, 2022 - 08:03 PM
Reply
(05 June, 2021 - 10:37 AM)Redm00n Wrote: Show MoreThis is a proof of concept of how a ransomware works, and some techniques that we usually use to hijack our files. This project is written in C# using the net-core application framework 3.1.The main idea of the code is to make it as readable as possible so that people have an idea of how this type of malware acts and works.
Baphomet features
AES algorithm for file encryption.
RSA encryption to encrypt key.
Automatic propagation via USB.
Hybrid encryption technique.
Enumeration of processes to kill those selected.
Internet connection test.
victim information submissions (Public IP, Domainname, Country, OS.version, City, Machine name, etc).
Program to decrypt the encryption key.
Program to decrypt encrypted data.
Hostname list to send the victim's data (redundancy).
Doesn't detected to antivirus programs (Date: 11/30/2020 12:25pm).
Hardcode image in base64 to change wallpaper (Baphomet image).
GIVE LIKES DON'T LEECH
thenks brther
This post is by a banned member (woo09787878) - Unhide
30 July, 2022 - 07:37 PM
Reply
[font][font]thanks[/font][/font]
This post is by a banned member (MadrisAkb) - Unhide
31 July, 2022 - 01:15 AM
Reply
(05 June, 2021 - 10:37 AM)Redm00n Wrote: Show MoreThis is a proof of concept of how a ransomware works, and some techniques that we usually use to hijack our files. This project is written in C# using the net-core application framework 3.1.The main idea of the code is to make it as readable as possible so that people have an idea of how this type of malware acts and works.
Bapthebkshomet features
AES algorithm for file encryption.
RSA encryption to encrypt key.
Automatic propagation via USB.
Hybrid encryption technique.
Enumeration of processes to kill those selected.
Internet connection test.
victim information submissions (Public IP, Domainname, Country, OS.version, City, Machine name, etc).
Program to decrypt the encryption key.
Program to decrypt encrypted data.
Hostname list to send the victim's data (redundancy).
Doesn't detected to antivirus programs (Date: 11/30/2020 12:25pm).
Hardcode image in base64 to change wallpaper (Baphomet image).
GIVE LIKES DON'T LEECH
Thenks bey
This post is by a banned member (Kinu2) - Unhide
01 August, 2022 - 09:32 PM
Reply
This post is by a banned member (bouraq9) - Unhide
03 August, 2022 - 08:52 PM
Reply
This post is by a banned member (accta) - Unhide
07 August, 2022 - 05:10 PM
Reply
This post is by a banned member (rani5533) - Unhide
09 August, 2022 - 09:49 AM
Reply
This post is by a banned member (NWYoda1) - Unhide
14 August, 2022 - 03:17 AM
Reply