OP 06 May, 2020 - 06:11 PM
First, the script checks if it's in a sandbox, debugger, vm, etc, and try bypass it.
It then encrypts all files starting with the defined directory on the line 60 in deathransom.py.
Then, downloads the ransom request script, disable cmd, taskmanager and the registry tools. And starts the counter to delete the files.
LIKE+REP IF YOU WANT ME TO BE A CONTRIBUTOR
DONATE BTC - 1HdbjkNwgK24XHJKw8ggB2ZL7GNC6W7z9V
It then encrypts all files starting with the defined directory on the line 60 in deathransom.py.
Then, downloads the ransom request script, disable cmd, taskmanager and the registry tools. And starts the counter to delete the files.
LIKE+REP IF YOU WANT ME TO BE A CONTRIBUTOR
DONATE BTC - 1HdbjkNwgK24XHJKw8ggB2ZL7GNC6W7z9V