Skip to content

Commit faed8a7

Browse files
authored
Update README.md
1 parent 6acba3a commit faed8a7

1 file changed

Lines changed: 2 additions & 3 deletions

File tree

‎README.md‎

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,13 +16,12 @@
1616
[![License: MIT License](https://img.shields.io/badge/license-MIT-blue?style=flat-square)](https://github.com/SegoCode/Ramonware/blob/main/LICENSE)
1717
[![Bitcoin BTC](https://img.shields.io/badge/buy_me_a_coffee-BTC-F7931A?style=flat-square&logo=bitcoin&logoColor=white)](https://github.com/SegoCode/SegoCode/discussions/2)
1818

19+
Hi, I'm a ransomware code in batch my name is Ramon
20+
1921
I built RamonWare as an experiment in minimum ransomware. You get a disk scan and AES on the matched files. The same .bat then opens a fullscreen HTA lock screen. People copy this file as a template and customize it... Trend Micro published a write-up on one of those forks: https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/trojan.bat.ramonware.thjoebc
2022

2123
The logic and the HTML share one .bat, a text payload that YARA and similar rules skip because they target binaries. The PowerShell AES block and the del stay in REM, and the HTA still opens fullscreen with HTML left to edit.
2224

23-
> [!NOTE]
24-
> Experimental research. I take no responsibility for damage, loss, or legal trouble that follows from running or sharing this file.
25-
2625
## Features
2726

2827
- Lock screen: opens a fullscreen HTA with a WannaCry-style note after the scan.

0 commit comments

Comments
 (0)