@
mothered ,
shitty ransomware, interacts with regedit & can brick windows after the timer of 30 minutes runs out
Virustotal Scan [4/72] (Original)
i will post the original app's code on my github
App Info:
Code:
IsObfuscated: False
.NETFrameworkVersion: 4.7.2
Architechture: x64 only
ActualEntrypoint: P4YME.Pay.Pay()
Unused files:
Code:
WThreads.dll
System.Windows.Forms.dll
System.Drawing.dll
System.dll
MimeKit.dll
MailKit.dll
Mail.dll
HtmlAgilityPack.dll
# TL;DR: Only "All Checker.exe" is used, it does not need any files that it came bundled with #
Malicious Code Location:
Code:
# All Checker.exe (used dnSpy)#
|- P4YME
|- Create
|- CreateRestart()
|- Pay
|- StopProcess()
|- Button1_Click()
|- countdown_Tick()
|- PayShown()
The application adds regedit values to:
- adds itself on startup
- EnableLUA (?)
- Shutdown without logon
- Prevent explorer.exe to close (NoClose)
It also restarts the computer & deletes all shadow copies (idk what are those)
After the timer has finished, it will delete the boot entry of the current OS (via bcedit) & restarts your computer to make the user unable to use their computer
The application also disconnects yourself from the internet on start (& only once),it will also close the following processes:
Code:
cmd
Taskmgr
FireFox
edge
Telegram
explorer
chrome
# They will always be closed since it is contained in an infinite loop #
To submit a valid password, just create a text file in the same folder the application is & inside of the text file, add the password you want.
I've edited the application so people can try this "ransomware" without actually getting their windows bricked.
Edits:
Code:
- No UAC
- Malicious code removed
- No Timer