guys, the robot can type rm -rf /, it’s so over
How it started:
it has to be behavior-based detection. I didn’t want to build a script that was only useful to detect and mitigate the specific ransomware executable I created for this blog. Signature-based detection is only useful for a particular file. The second a single byte changes, the file will have a new hash.
(which is not exactly how AV signatures work but anyways…)
How it’s going:
[…] scans any file in the /home director, for the strings “cryptography”, “cryptodome”, “ransom”, “locked”, “encrypt”.
@sailor_sega_saturn @sinedpick
> For some background on my programming ability, I can read, write, and edit basic scripts in Python, Rust, and Go. I’m far from a seasoned developer.
Wait I think I worked for this guy once