RansomLord v3 - Anti-Ransomware Exploitation Tool / New Release

2024.05.07
Credit: malvuln
Risk: High
Local: Yes
Remote: No
CVE: N/A
CWE: N/A

Proof-of-concept tool that automates the creation of PE files, used to exploit Ransomware pre-encryption. Updated v3: https://github.com/malvuln/RansomLord/releases/tag/v3 Lang: C SHA256: 83f56d14671b912a9a68da2cd37607cac3e5b31560a6e30380e3c6bd093560f5 Video PoC (old v2): https://www.youtube.com/watch?v=_Ho0bpeJWqI RansomLord generated PE files are saved to disk in the x32 or x64 directories where the program is run from. Goal is to exploit vulnerabilities inherent in certain strains of Ransomware by deploying exploits that defend the network! The DLLs may also provide additional coverage against generic and info stealer malwares. RansomLord v3 release notes: Adding six more Ransomware to the victim list for a grand total of 49 StopCrypt, RisePro, RuRansom, MoneyMessage, CryptoFortress and Onyx. Windows event log now includes SHA256 hash of the intercepted malware. https://github.com/malvuln/RansomLord MALVULN


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top