Skip to content

Latest commit

 

History

History

trigona

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

Trigona Ransomware Configuration Decryption Tool

Description

This is a Python-based tool to decrypt and parse the Trigona ransomware configuration, which leverages two layers of AES encryption in CBC mode.

Usage

Usage: python3 trigona_config_extractor.py [trigona.exe]

Example Trigona Ransomware Samples

SHA256
8cbe32f31befe7c4169f25614afd1778006e4bda6c6091531bc7b4ff4bf62376
f64211b0a49589bb53523dfb88eb9937ab88c8fcea98e2aabcbee90f1828e94e
11b0e9673bbeb978aa9b95bcad43eb21bbe0bbaaf7e5a0e20d48b93d60204406
eda603f4d469d017917f5d6affeb992fdf3b7971e49868ece8c38fb8e6f8b444
c4529a061f205aaee46c219123d15059d2161df2bd7c7b738dd2a2c1ffd8d3ee
170fa5d29cdb562d41a054abf2a57ca29fc233805b59692a1a57ebf25449be7c
f29b948905449f330d2e5070d767d0dac4837d0b566eee28282dc78749083684
197f4933680a611ad2234a22769bd079885f81956221ec0de172d5a19eab648e
1017fcf607a329bb6ad046181c3656b686906a0767fff2a4a3c6c569c2a70a85
761b78ddab55b4e561607ce5ce9d424a7aec4f1994aad988f0612b096cdd1d6d
097d8edb1762d7d3ded4360a9f5b4673a898937421f36853d2f5cde77e1bac93
4a06231957c53dee1a11ff3eb84caad082f18761aee49e72d79c7f1d32884e34