██████╗ █████╗ ███╗ ██╗███████╗ ██████╗ ███╗ ███╗███████╗██╗ ██╗███████╗
██╔══██╗██╔══██╗████╗ ██║██╔════╝██╔═══██╗████╗ ████║██╔════╝╚██╗ ██╔╝██╔════╝
██████╔╝███████║██╔██╗ ██║███████╗██║ ██║██╔████╔██║█████╗ ╚████╔╝ █████╗
██╔══██╗██╔══██║██║╚██╗██║╚════██║██║ ██║██║╚██╔╝██║██╔══╝ ╚██╔╝ ██╔══╝
██║ ██║██║ ██║██║ ╚████║███████║╚██████╔╝██║ ╚═╝ ██║███████╗ ██║ ███████╗
╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═══╝╚══════╝ ╚═════╝ ╚═╝ ╚═╝╚══════╝ ╚═╝ ╚══════╝
by sudo3rs
RansomEye is a specialized monitoring tool designed to track ransomware attacks targeting Indonesia. It leverages the ransomware.live API to identify new victims, send real-time alerts, and generate visual analytics of ransomware trends.
- Real-time Monitoring: Continuously checks for new ransomware victims in Indonesia
- Discord Notifications: Sends instant alerts when new victims are detected
- Visual Analytics: Generates comprehensive visualizations of ransomware trends including:
- Timeline of attacks over time
- Distribution of ransomware groups
- Interactive dashboard for data exploration
- Detailed victim information table
- Persistent Storage: Maintains a history of detected victims to avoid duplicate alerts
- Robust Error Handling: Implements retry mechanisms and comprehensive error handling
- Python 3.7+
- Required Python packages (install via pip):
pip install requests pandas matplotlib seaborn discord-webhook plotly- Clone the repository:
git clone https://github.com/Masriyan/ransomeye.git
cd ransomeye-
Configure your Discord webhook URL:
- Create a webhook in your Discord server
- Replace the
WEBHOOK_URLvariable in the code with your webhook URL
-
Customize the country code if needed (default is "ID" for Indonesia):
- Modify the
COUNTRY_CODEvariable to monitor a different country
- Modify the
Run the monitoring tool:
python ransomeye.pyThe tool will:
- Display the RansomEye banner
- Create an initial set of visualizations
- Begin monitoring for new victims
- Send alerts when new victims are detected
- Update visualizations when changes occur
To stop the tool, press Ctrl+C.
All data is stored in the ransomware_data directory:
victim_history.json: Historical record of detected victimsvisualizations/: Directory containing generated charts and dashboards:indonesia_ransomware_timeline.png: Timeline of attacksindonesia_ransomware_groups.png: Distribution of ransomware groupsindonesia_ransomware_dashboard.html: Interactive dashboardindonesia_ransomware_victims_table.html: Detailed victim table
The default check interval is 1 hour (3600 seconds). To change this:
- Modify the
CHECK_INTERVALvariable (in seconds)
Visualization styles can be customized by modifying the respective visualization functions:
create_time_series_plot(): Timeline chartcreate_group_distribution_plot(): Ransomware group distributioncreate_interactive_dashboard(): Interactive dashboardcreate_victim_table(): Victim information table
RansomEye uses the ransomware.live API v2. The following endpoints are utilized:
/countryvictims/{COUNTRY_CODE}: Retrieves victims by country/groups: Retrieves information about all ransomware groups
Discord alerts include:
- Organization name
- Ransomware group
- Date posted
- Description (if available)
- URL to the ransomware post (if available)
The tool implements:
- Exponential backoff for API request retries
- Comprehensive error logging
- Graceful handling of missing data fields
- Fallback mechanisms for different API response structures
- Created by sudo3rs
- Data provided by ransomware.live
MIT License
This tool is for educational and defensive purposes only. It is intended to help organizations monitor and respond to ransomware threats. Do not use this tool for any illegal or harmful activities.