[active development] custom wiper / ransomware
by - Thursday, January 1, 1970 at 12:00 AM
(November 9, 2022, 03:15 AM)SafeSig Wrote: Pretty nice and development is going fast! How the retrieval of files would work? Through tor? TLS? would be also nice to automatically retrieve specific extension files to save space.

Probably through TLS. tor is funky and doesnt work as fast as youd like it to.
Reply
(November 9, 2022, 03:19 AM)IntelBroker Wrote:
(November 9, 2022, 03:15 AM)SafeSig Wrote: Pretty nice and development is going fast! How the retrieval of files would work? Through tor? TLS? would be also nice to automatically retrieve specific extension files to save space.

Probably through TLS. tor is funky and doesnt work as fast as youd like it to.

Yeah exactly also imagine needing to download 50gb or more of data, would take forever. tls is great tho, keep it up <3
Reply
Adding new suggestion: It will great if the ransomware can get into BIOS and boot every time in the memory. This will prevent ransomware from getting erased when someone wipe their HDD or any storage device. Even they do our ransomware will always there in the BIOS and boot every time on the startup with memory. Thanks!
Reply
(November 9, 2022, 05:25 AM)expgods Wrote: Adding new suggestion: It will great if the ransomware can get into BIOS and boot every time in the memory. This will prevent ransomware from getting erased when someone wipe their HDD or any storage device. Even they do our ransomware will always there in the BIOS and boot every time on the startup with memory. Thanks!

an optional wiper will fix that and has already been placed in the to-do
Reply
Add XMR miner function..
Reply
(November 10, 2022, 02:30 PM)Hotspotbruh Wrote: Add XMR miner function..

no.
Reply
i love this guy
Reply
I have seen some people implementing features for stopping people from opening task manager. Is this in the list?

between other features that I think could be useful
-Try to counter WinPE STRELEC repairs, if you're not already. 
-Remove or encrypt windows restore points? Also, if you're not already doing this.
Reply
(November 11, 2022, 12:37 AM)4br4x4s Wrote: I have seen some people implementing features for stopping people from opening task manager. Is this in the list?

between other features that I think could be useful
-Try to counter WinPE STRELEC repairs, if you're not already. 
-Remove or encrypt windows restore points? Also, if you're not already doing this.

will add now. and yes. i have to setup blacklisted apps to prevent running or just killing.
Reply
I am unsure on how useful this bit of information could be, but maybe try avoiding people from popping up command lines to try to terminate your software.
I like running FTP with win + R and then using ! to execute commands on some corporate computers that I have the misfortune of having to use. (let me play tetris dammit!)
Considering few people in the general population are technically literate enough to pull this off, I do not know if this is worthwhile, but I guess it could be something useful for you to know? 

here are the different ways that people spawn CMD
https://www.howtogeek.com/235101/10-ways-to-open-the-command-prompt-in-windows-10/
probably just stopping CMD from running altogether could work
here is a source for different ways people can spawn shells in windows
https://www.infosecmatter.com/19-ways-to-bypass-software-restrictions-and-spawn-a-shell/

If I am spewing out a bunch of nonsense, don't pay me any attention. I am still new in the field!
Reply


 Users viewing this thread: [active development] custom wiper / ransomware: No users currently viewing.