Skip to content

Latest commit

History

64 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Ramonware

AboutFeaturesQuick Start & InformationDownload

About

Top languageRepository sizeCommit activity per yearLicense: MIT LicenseBitcoin BTC

Note

Experimental research. I take no responsibility for damage, loss, or legal trouble that follows from running or sharing this file.

This repo follows GitHub's Acceptable Use Policies, including Active malware or exploits: dual-use security research, harm disclosed here, AES left commented out, SECURITY.md for reports. Not attack infrastructure or a malware CDN.

Hi, I'm a ransomware code in batch my name is Ramon

I built Ramonware as an experiment as a minimum ransomware. You get a disk scan and AES on the matched files. The same .bat then opens a fullscreen HTA lock screen. People copy this file as a template and customize it... Trend Micro published a write-up on one of those forks: https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/trojan.bat.ramonware.thjoebc

Features

  • Lock screen: opens a fullscreen HTA with a WannaCry-style note after the scan.

  • Single file: code/Ramonware.bat holds the scan and the HTML. No extra install.

Quick Start & Information

git clone https://github.com/SegoCode/Ramonware
cd Ramonware/code
Ramonware.bat

The scan starts at %homedrive%\ and walks every folder. Uncommenting the PowerShell AES lines and del encrypts the file and removes the original.

Download

https://raw.githubusercontent.com/SegoCode/Ramonware/refs/heads/master/code/Ramonware.bat


About

AES Ransomware in batch

Resources

Code of conduct

Security policy

Stars

12 stars

Watchers

4 watching

Forks

Used by

Contributors

Languages