a1project

Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:55:06

Context

The locker is written in C/C++/ASM. It supports all systems starting from Windows 2003, has a separate binary for ESXi, and uses a unified encrypted file format across all systems. WINDOWS: • Two encryption modes: patch-based and file header. • Extensive configuration settings: from ignoring specific paths/extensions to terminating services/processes, unlocking occupied files, working with network shares, and more. • Arguments available for shutting down Hyper-V virtual machines, deleting backups, network scanning with logged-in user tokens. • Each build includes an obfuscated PowerShell script. • Execution is password-protected. • The locker itself is shellcode for x86/x64; if you have custom execution methods, we can provide the shellcode. ESXI: • Encrypts files in patches, with configurable path exclusions. The default configuration is pre-set to avoid disrupting Windows/ESXi/Linux systems. Our commission is 20% of payouts

Reports & references

  • ransomlook.io — A1Project (report)

External references