{"id":15009020,"url":"https://github.com/tarcisio-marinho/gonnacry","last_synced_at":"2025-04-14T03:57:03.069Z","repository":{"id":46753532,"uuid":"91137352","full_name":"tarcisio-marinho/GonnaCry","owner":"tarcisio-marinho","description":"A Linux Ransomware","archived":false,"fork":false,"pushed_at":"2025-01-24T13:39:57.000Z","size":128945,"stargazers_count":717,"open_issues_count":11,"forks_count":401,"subscribers_count":39,"default_branch":"master","last_synced_at":"2025-04-07T01:01:36.147Z","etag":null,"topics":["aes","aes-encryption","c","crypto-library","cryptography","decryption","encryption","linux","linux-ransomware","malware","malware-analysis","malware-development","openssl","python","python-2","ransom-worm","ransomware","ransomware-prevention","rsa-cryptography","rsa-key-encryption"],"latest_commit_sha":null,"homepage":"https://medium.com/@tarcisioma/ransomware-encryption-techniques-696531d07bb9","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tarcisio-marinho.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2017-05-12T23:46:28.000Z","updated_at":"2025-04-01T22:37:40.000Z","dependencies_parsed_at":"2024-12-08T08:03:31.863Z","dependency_job_id":"f071bbed-e337-4fea-86c2-e2a730c7245e","html_url":"https://github.com/tarcisio-marinho/GonnaCry","commit_stats":{"total_commits":452,"total_committers":6,"mean_commits":75.33333333333333,"dds":"0.026548672566371723","last_synced_commit":"a11630c94058dd1c2c91923b201be12f109541ec"},"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tarcisio-marinho%2FGonnaCry","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tarcisio-marinho%2FGonnaCry/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tarcisio-marinho%2FGonnaCry/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tarcisio-marinho%2FGonnaCry/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tarcisio-marinho","download_url":"https://codeload.github.com/tarcisio-marinho/GonnaCry/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248819379,"owners_count":21166476,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aes","aes-encryption","c","crypto-library","cryptography","decryption","encryption","linux","linux-ransomware","malware","malware-analysis","malware-development","openssl","python","python-2","ransom-worm","ransomware","ransomware-prevention","rsa-cryptography","rsa-key-encryption"],"created_at":"2024-09-24T19:22:26.776Z","updated_at":"2025-04-14T03:57:03.048Z","avatar_url":"https://github.com/tarcisio-marinho.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# GonnaCry Ransomware\n\nOriginal Repository of the GonnaCry Ransomware.\n\nGonnaCry is a linux ransomware that encrypts all the user files with a strong encryption scheme.\n\nThis project is OpenSource, feel free to use, study and/or send pull request.\n\n\n[![Travis branch](https://img.shields.io/travis/rust-lang/rust/master.svg)](https://github.com/tarcisio-marinho/GonnaCry)\n[![Travis branch](https://img.shields.io/cran/l/devtools.svg)](https://github.com/tarcisio-marinho/GonnaCry/blob/master/LICENSE)\n[![Travis branch](https://img.shields.io/badge/made%20with-%3C3-red.svg)](https://github.com/tarcisio-marinho/GonnaCry)\n[![Travis branch](https://img.shields.io/github/stars/tarcisio-marinho/GonnaCry.svg)](https://github.com/tarcisio-marinho/GonnaCry/stargazers)\n    \n-------------\n\n**Ransomware Impact on industry**\n\nhttps://medium.com/@tarcisioma/how-can-a-malware-encrypt-a-company-existence-c7ed584f66b3\n\n**How this ransomware encryption scheme works:**\n\nhttps://medium.com/@tarcisioma/ransomware-encryption-techniques-696531d07bb9\n\n\n**How this ransomware works:**\n\nhttps://0x00sec.org/t/how-ransomware-works-and-gonnacry-linux-ransomware/4594\n\nhttps://medium.com/@tarcisioma/how-ransomware-works-and-gonnacry-linux-ransomware-17f77a549114\n\n\n**Mentions:**\n\nhttps://www.sentinelone.com/blog/sentinelone-detects-prevents-wsl-abuse/\n\nhttps://hackingvision.com/2017/07/18/gonnacry-linux-ransomware/\n\nhttps://www.youtube.com/watch?v=gSfa2L158Uw\n\n-------------\n\n# Disclaimer\n\nThis Ransomware mustn't be used to harm/threat/hurt other person's computer.\n\nIts purpose is only to share knowledge and awareness about Malware/Cryptography/Operating Systems/Programming.\n\nGonnaCry is an academic ransomware made for learning and awareness about security/cryptography.\n\n**Be aware running C/bin/GonnaCry or Python/GonnaCry/main.py Python/GonnaCry/bin/gonnacry in your computer, it may harm.**\n\n-------------\n\n# What's a Ransomware?\n\nA ransomware is a type of malware that prevents legitimate users from accessing\ntheir device or data and asks for a payment in exchange for the stolen functionality.\nThey have been used for mass extortion in various forms, but the\nmost successful one seems to be encrypting ransomware: most of the user data are\nencrypted and the key can be obtained paying the attacker.\nTo be widely successful a ransomware must fulfill three properties:\n\n**Property 1**: The hostile binary code must not contain any secret (e.g. deciphering\nkeys). At least not in an easily retrievable form, indeed white box cryptography\ncan be applied to ransomware.\n\n**Property 2**: Only the author of the attack should be able to decrypt the\ninfected device.\n\n**Property 3**: Decrypting one device can not provide any useful information\nfor other infected devices, in particular the key must not be shared among them.\n\n-------------\n\n# Objectives:\n\n- [x] encrypts all user files with AES-256-CBC.\n- [x] Random AES key and IV for each file.\n- [x] Works even without internet connection.\n- [x] Communication with the server to decrypt Client-private-key.\n- [x] encrypts AES key with client-public-key RSA-2048.\n- [x] encrypts client-private-key with RSA-2048 server-public-key.\n- [x] Changes computer wallpaper -\u003e Gnome, LXDE, KDE, XFCE.\n- [x] Decryptor that communicate to server to send keys.\n- [x] python webserver\n- [x] Daemon\n- [ ] Dropper\n- [x] Kills databases\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftarcisio-marinho%2Fgonnacry","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftarcisio-marinho%2Fgonnacry","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftarcisio-marinho%2Fgonnacry/lists"}