Skip to content
MasriyanPublic

About

Ransomeye

Resources

Stars

2 stars

Watchers

1 watching

Forks

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

RansomEye

Indonesia Ransomware Monitoring Tool

██████╗  █████╗ ███╗   ██╗███████╗ ██████╗ ███╗   ███╗███████╗██╗   ██╗███████╗
██╔══██╗██╔══██╗████╗  ██║██╔════╝██╔═══██╗████╗ ████║██╔════╝╚██╗ ██╔╝██╔════╝
██████╔╝███████║██╔██╗ ██║███████╗██║   ██║██╔████╔██║█████╗   ╚████╔╝ █████╗  
██╔══██╗██╔══██║██║╚██╗██║╚════██║██║   ██║██║╚██╔╝██║██╔══╝    ╚██╔╝  ██╔══╝  
██║  ██║██║  ██║██║ ╚████║███████║╚██████╔╝██║ ╚═╝ ██║███████╗   ██║   ███████╗
╚═╝  ╚═╝╚═╝  ╚═╝╚═╝  ╚═══╝╚══════╝ ╚═════╝ ╚═╝     ╚═╝╚══════╝   ╚═╝   ╚══════╝
                                                                by sudo3rs

Overview

RansomEye is a specialized monitoring tool designed to track ransomware attacks targeting Indonesia. It leverages the ransomware.live API to identify new victims, send real-time alerts, and generate visual analytics of ransomware trends.

Features

  • Real-time Monitoring: Continuously checks for new ransomware victims in Indonesia
  • Discord Notifications: Sends instant alerts when new victims are detected
  • Visual Analytics: Generates comprehensive visualizations of ransomware trends including:
    • Timeline of attacks over time
    • Distribution of ransomware groups
    • Interactive dashboard for data exploration
    • Detailed victim information table
  • Persistent Storage: Maintains a history of detected victims to avoid duplicate alerts
  • Robust Error Handling: Implements retry mechanisms and comprehensive error handling

Installation

Prerequisites

  • Python 3.7+
  • Required Python packages (install via pip):
pip install requests pandas matplotlib seaborn discord-webhook plotly

Setup

  1. Clone the repository:
git clone https://github.com/Masriyan/ransomeye.git
cd ransomeye
  1. Configure your Discord webhook URL:

    • Create a webhook in your Discord server
    • Replace the WEBHOOK_URL variable in the code with your webhook URL
  2. Customize the country code if needed (default is "ID" for Indonesia):

    • Modify the COUNTRY_CODE variable to monitor a different country

Usage

Run the monitoring tool:

python ransomeye.py

The tool will:

  1. Display the RansomEye banner
  2. Create an initial set of visualizations
  3. Begin monitoring for new victims
  4. Send alerts when new victims are detected
  5. Update visualizations when changes occur

To stop the tool, press Ctrl+C.

Data Storage

All data is stored in the ransomware_data directory:

  • victim_history.json: Historical record of detected victims
  • visualizations/: Directory containing generated charts and dashboards:
    • indonesia_ransomware_timeline.png: Timeline of attacks
    • indonesia_ransomware_groups.png: Distribution of ransomware groups
    • indonesia_ransomware_dashboard.html: Interactive dashboard
    • indonesia_ransomware_victims_table.html: Detailed victim table

Customization

Monitoring Interval

The default check interval is 1 hour (3600 seconds). To change this:

  • Modify the CHECK_INTERVAL variable (in seconds)

Visualization Styles

Visualization styles can be customized by modifying the respective visualization functions:

  • create_time_series_plot(): Timeline chart
  • create_group_distribution_plot(): Ransomware group distribution
  • create_interactive_dashboard(): Interactive dashboard
  • create_victim_table(): Victim information table

API Integration

RansomEye uses the ransomware.live API v2. The following endpoints are utilized:

  • /countryvictims/{COUNTRY_CODE}: Retrieves victims by country
  • /groups: Retrieves information about all ransomware groups

Alert Format

Discord alerts include:

  • Organization name
  • Ransomware group
  • Date posted
  • Description (if available)
  • URL to the ransomware post (if available)

Error Handling

The tool implements:

  • Exponential backoff for API request retries
  • Comprehensive error logging
  • Graceful handling of missing data fields
  • Fallback mechanisms for different API response structures

Credits

License

MIT License

Disclaimer

This tool is for educational and defensive purposes only. It is intended to help organizations monitor and respond to ransomware threats. Do not use this tool for any illegal or harmful activities.

About

Ransomeye

Resources

Stars

2 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages