Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



 18378

Baphomet Ransomware (Author Not responsible for illegal use)

by Redm00n - 05 June, 2021 - 10:37 AM
This post is by a banned member (madris06) - Unhide
madris06  
Registered
59
Posts
0
Threads
4 Years of service
#65
(05 June, 2021 - 10:37 AM)Redm00n Wrote: Show More
This is a proof of concept of how a ransomware works, and some techniques that we usually use to hijack our files. This project is written in C# using the net-core application framework 3.1.The main idea of the code is to make it as readable as possible so that people have an idea of how this type of malware acts and works.

Baphomet features

AES algorithm for file encryption.
RSA encryption to encrypt key.
Automatic propagation via USB.
Hybrid encryption technique.
Enumeration of processes to kill those selected.
Internet connection test.
victim information submissions (Public IP, Domainname, Country, OS.version, City, Machine name, etc).
Program to decrypt the encryption key.
Program to decrypt encrypted data.
Hostname list to send the victim's data (redundancy).
Doesn't detected to antivirus programs (Date: 11/30/2020 12:25pm).
Hardcode image in base64 to change wallpaper (Baphomet image).


GIVE LIKES DON'T LEECH

thenks brther
This post is by a banned member (woo09787878) - Unhide
8
Posts
0
Threads
2 Years of service
#66
[font][font]thanks[/font][/font]
This post is by a banned member (MadrisAkb) - Unhide
MadrisAkb  
Registered
42
Posts
0
Threads
2 Years of service
#67
(05 June, 2021 - 10:37 AM)Redm00n Wrote: Show More
This is a proof of concept of how a ransomware works, and some techniques that we usually use to hijack our files. This project is written in C# using the net-core application framework 3.1.The main idea of the code is to make it as readable as possible so that people have an idea of how this type of malware acts and works.

Bapthebkshomet features

AES algorithm for file encryption.
RSA encryption to encrypt key.
Automatic propagation via USB.
Hybrid encryption technique.
Enumeration of processes to kill those selected.
Internet connection test.
victim information submissions (Public IP, Domainname, Country, OS.version, City, Machine name, etc).
Program to decrypt the encryption key.
Program to decrypt encrypted data.
Hostname list to send the victim's data (redundancy).
Doesn't detected to antivirus programs (Date: 11/30/2020 12:25pm).
Hardcode image in base64 to change wallpaper (Baphomet image).


GIVE LIKES DON'T LEECH

Thenks bey
This post is by a banned member (Kinu2) - Unhide
This post is by a banned member (bouraq9) - Unhide
This post is by a banned member (accta) - Unhide
accta  
Registered
14
Posts
0
Threads
2 Years of service
#70
thanks
This post is by a banned member (rani5533) - Unhide
This post is by a banned member (NWYoda1) - Unhide
NWYoda1  
Registered
28
Posts
0
Threads
2 Years of service
#72
thanks friend

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 3 Guest(s)