Malware sample library.
-
Updated
Nov 21, 2023 - C++
Malware sample library.
A custom version of the previously leaked source code of the Babuk ransomware which will be maintained by me. The purpose of this repo is to create a more easy to understand/maintain version of the original source code
Recover VMware ESXi VMs after Babuk/.babyk ransomware. The encryptor only destroys the first 512 MiB per file, so 99%+ of each VMDK survives as plaintext. Analysis, IOCs, tools, runbook.
Cracked version of Babuk Ransomware Including the missing Locker files. Including source code.
BabyK/Babuk ransomware analysis for VMware ESXi: VMDK encryption behavior, 520 MiB transformed prefix, 32-byte footer, recovery limits, and safe triage.
Babuk Ransomware v1 — Complete Threat Analysis Report | ECDH + ChaCha20 Cryptographic Research | IOCs, MITRE ATT&CK, YARA/Sigma/Snort Detection Rules | Documentation Only — No Source Code
To associate your repository with the babuk topic, visit your repo's landing page and select "manage topics."