tarcisio-marinho / gonnacry Goto Github PK
View Code? Open in Web Editor NEWA Linux Ransomware
Home Page: https://medium.com/@tarcisioma/ransomware-encryption-techniques-696531d07bb9
License: GNU General Public License v2.0
A Linux Ransomware
Home Page: https://medium.com/@tarcisioma/ransomware-encryption-techniques-696531d07bb9
License: GNU General Public License v2.0
I am trying to compile C (Older version) version of GonnaCry but I am running into a problem. I understand this is an older version but would like to request for your help.
lib/struct.c: In function ‘destroy’: lib/struct.c:61:27: warning: assignment makes integer from pointer without a cast [-Wint-conversion] *aux->info[i] = "random_string"; ^ gcc -c lib/func.c -o lib/func.o gcc lib/gonnacry.o lib/crypto.o lib/struct.o lib/func.o -o bin/gonnacry -lcrypto
mostly no problem with using python3 except for few packages being deprecated in some way or another. Probably create a new branch with compatible with the packages?
I got segmentation fault when I run C version,can you tell me your environment?
I am having difficulty in executing this ransomware. I have installed all the dependencies and have built binaries. After that, I am unable to understand what to do. I ran main.py and got this error
Traceback (most recent call last):
File "main.py", line 148, in <module>
menu()
File "main.py", line 110, in menu
aes_keys_and_base64_path= start_encryption(files)
File "main.py", line 69, in start_encryption
base64_new_file_name = base64.b64encode(new_file_name)
File "/usr/lib/python3.6/base64.py" , line 58, in b64encode
encoded = binascii.b2a_base64(s, newline=False )
TypeError: a bytes-like object is required, not 'str'
Can someone provide step by step procedure to execute this ransomware correctly?
Thanks in advance
Need help implementing linux persistence.
https://resources.infosecinstitute.com/common-malware-persistence-mechanisms/#gref
https://www.andreafortuna.org/dfir/malware-persistence-techniques/
Error running under Python 3.10
./GonnaCry
generated = Crypto.Random.OSRNG.posix.DevURandomRNG()
AttributeError: module 'Crypto.Random' has no attribute 'OSRNG'
The function is deprecated. Can you suggest what I should replace with here.
`import base64
import Crypto.Random
def generate_key(bits, encode=False):
generated = Crypto.Random.OSRNG.posix.DevURandomRNG()
content = generated.read(bits)
#generated = Crypto.Random.urandom(7675675676)
#content = generated
#content = ''.join(format(ord(i), '08b') for i in generated)
if(encode):
return base64.b64encode(content)
return content
if name == "main":
print(generate_key(32))`
Need help implementing code obfuscation.
https://pdfs.semanticscholar.org/4248/b2b6f8a6389371ce20ec065853b4ef1c4b04.pdf
https://anti-reversing.com/Downloads/Anti-Reversing/The_Ultimate_Anti-Reversing_Reference.pdf
https://github.com/a0rtega/pafish
https://www.apriorit.com/dev-blog/367-anti-reverse-engineering-protection-techniques-to-use-before-releasing-software
Need to implement some features.
Windows and linux :
os version
check for valuable information - games saves, steam info, imgs, databases, pdfs, docs, txts
check firewall
check antivirus
check open ports
check known vulnerabilities
The dropper is inside this directory: https://github.com/tarcisio-marinho/GonnaCry/Python/Dropper
These are my ways of dealing with such problems
Solution:
Add the Picture as an Resource in the Binary and Extracting it in the Process.
Solution:
Convert the Picture into C and including it in the solution as an HeaderFile (.h), then using [CreateFile] and [WriteFile] to write the Picture into a Directory.
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.