This post is by a banned member (super_hockey) - Unhide
02 June, 2024 - 05:39 PM
Reply
(06 May, 2020 - 06:11 PM)MiNdFuCkErY_1337skid Wrote: Show MoreFirst, the script checks if it's in a sandbox, debugger, vm, etc, and try bypass it.
It then encrypts all files starting with the defined directory on the line 60 in deathransom.py.
Then, downloads the ransom request script, disable cmd, taskmanager and the registry tools. And starts the counter to delete the files.
![[Image: 68747470733a2f2f696d672e796f75747562652e...742e6a7067]](https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fcamo.githubusercontent.com%2F1b0b6e44edd320851a224100c95c43b3ea49ad7f%2F68747470733a2f2f696d672e796f75747562652e636f6d2f76692f4e334b6d2d5470504270302f6d617872657364656661756c742e6a7067)
sfdsdfsdfsdfsfsdsfdsdfsdf
This post is by a banned member (vimour22) - Unhide
11 June, 2024 - 11:38 AM
Reply
This post is by a banned member (asdqwdqwd1) - Unhide
09 August, 2024 - 09:05 AM
Reply
(06 May, 2020 - 06:11 PM)MiNdFuCkErY_1337skid Wrote: Show MoreFirst, the script checks if it's in a sandbox, debugger, vm, etc, and try bypass it.
It then encrypts all files starting with the defined directory on the line 60 in deathransom.py.
Then, downloads the ransom request script, disable cmd, taskmanager and the registry tools. And starts the counter to delete the files.
![[Image: 68747470733a2f2f696d672e796f75747562652e...742e6a7067]](https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fcamo.githubusercontent.com%2F1b0b6e44edd320851a224100c95c43b3ea49ad7f%2F68747470733a2f2f696d672e796f75747562652e636f6d2f76692f4e334b6d2d5470504270302f6d617872657364656661756c742e6a7067) x1x1x1x1wdc13wxc
This post is by a banned member (Fe4r11222) - Unhide
06 October, 2024 - 12:56 PM
Reply
(06 May, 2020 - 06:11 PM)MiNdFuCkErY_1337skid Wrote: Show MoreFirst, the script checks if it's in a sandbox, debugger, vm, etc, and try bypass it.
It then encrypts all files starting with the defined directory on the line 60 in deathransom.py.
Then, downloads the ransom request script, disable cmd, taskmanager and the registry tools. And starts the counter to delete the files.
![[Image: 68747470733a2f2f696d672e796f75747562652e...742e6a7067]](https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fcamo.githubusercontent.com%2F1b0b6e44edd320851a224100c95c43b3ea49ad7f%2F68747470733a2f2f696d672e796f75747562652e636f6d2f76692f4e334b6d2d5470504270302f6d617872657364656661756c742e6a7067)
ezzzzzzzzzzzzzzzzzzzsz
This post is by a banned member (Davitest) - Unhide
07 October, 2024 - 05:07 PM
Reply
(06 May, 2020 - 06:11 PM)MiNdFuCkErY_1337skid Wrote: Show MoreFirst, the script checks if it's in a sandbox, debugger, vm, etc, and try bypass it.
It then encrypts all files starting with the defined directory on the line 60 in deathransom.py.
Then, downloads the ransom request script, disable cmd, taskmanager and the registry tools. And starts the counter to delete the files.
![[Image: 68747470733a2f2f696d672e796f75747562652e...742e6a7067]](https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fcamo.githubusercontent.com%2F1b0b6e44edd320851a224100c95c43b3ea49ad7f%2F68747470733a2f2f696d672e796f75747562652e636f6d2f76692f4e334b6d2d5470504270302f6d617872657364656661756c742e6a7067)
thanks
This post is by a banned member (Nexa84) - Unhide
07 October, 2024 - 05:15 PM
Reply
I will adjust it to my preferences, thank you
This post is by a banned member (tiit0) - Unhide
12 May, 2025 - 02:35 PM
Reply
(06 May, 2020 - 06:11 PM)MiNdFuCkErY_1337skid Wrote: Show MoreFirst, the script checks if it's in a sandbox, debugger, vm, etc, and try bypass it.
It then encrypts all files starting with the defined directory on the line 60 in deathransom.py.
Then, downloads the ransom request script, disable cmd, taskmanager and the registry tools. And starts the counter to delete the files.
![[Image: 68747470733a2f2f696d672e796f75747562652e...742e6a7067]](https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fcamo.githubusercontent.com%2F1b0b6e44edd320851a224100c95c43b3ea49ad7f%2F68747470733a2f2f696d672e796f75747562652e636f6d2f76692f4e334b6d2d5470504270302f6d617872657364656661756c742e6a7067) Thanks for sharing brother this is awesome
This post is by a banned member (PunchmadeAer) - Unhide
16 June, 2025 - 05:56 PM
Reply
|