ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

Targeted Private Ransomware Builder


  • Please log in to reply
Targeted Private Ransomware Builder

#41

Capitao7
Capitao7
    Offline
    0
    Rep
    1
    Likes

    Lurker

Posts: 1
Threads: 0
Joined: Aug 29, 2022
Credits: 0
One year registered
#41

looks like im not the only one zagala screwed. guy should learn beter opsec in his next career. See vid..

 

)....https://www.youtube....h?v=pJCJTVRvQh0

 

 

 

 

Characteristics:

 

--Small file size client.

--Builder can steal icons from another executable or load any png or ico file.

--Low antivirus detection without encryption.

--Self delete client after encryption is done.

--Encryption key is erased after encryption which makes very hard to recover the key.

--Strong encryption algorithm.

--File extensions to be encrypted can be configured.

--Decryptor is provided (requires encryption key used at the moment of building).

--Totally configurable: client name, ransom message, ransom filename, encrypted extension, directories to be attacked, BTC address, special directories to be attacked.

--Automatic internet updates.

--Fully Tested in Windows 10.

 

Some technical facts:

 

Functional wise all occurs automatically behind cameras, when the builder is first opened a random key is generated automatically there's a button to change it though if you need to create several ransom files a log file is created containing all created ransom executables info and also each individual decryption key. It is also possible to customize the directories to attack or let the malware encrypt all.
In targeted attacks you could happen to know which directory or directories are better to encrypt and in such case is better to set only those directories because encryption will be faster and the user will have less time to react.
The builder let you also configure the encryption extension so you can add a personal touch to the process like .die or .death or whatever encryption extension you wish to set.
it is also possible to change the note filename and its content however default values are good enough. This builder creates targeted clients.

 

 

 

 

LAN SPREADING READY:

 

malware-worms-blog-banner-730x300.png

 

Without encryption:

 

XUaFNvfdRX04.png

 

2019-10-12-22-31-14-Window.png

 

2019-10-12-22-31-31-Window.png

 

 


  • 1

#42

theroblox
theroblox
    Offline
    0
    Rep
    0
    Likes

    Advanced Member

  • PipPipPipPip
Posts: 90
Threads: 0
Joined: Feb 11, 2022
Credits: 0
Two years registered
#42
Thanks for sharing bro

  • 0

#43

Ralph123
Ralph123
    Offline
    0
    Rep
    0
    Likes

    New Member

  • PipPip
Posts: 23
Threads: 0
Joined: Jan 28, 2020
Credits: 0
Four years registered
#43
wowww

  • 0


 Users browsing this thread: