{"id":17451,"date":"2021-07-16T06:46:51","date_gmt":"2021-07-16T06:46:51","guid":{"rendered":"https:\/\/nsfocusglobal.com\/?p=17451"},"modified":"2026-04-17T18:07:45","modified_gmt":"2026-04-17T18:07:45","slug":"a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1","status":"publish","type":"post","link":"https:\/\/nsfocusglobal.com\/pt-br\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/","title":{"rendered":"A Look into Source Code of Paradise Ransomware, a &#8220;Custom-Built&#8221; Virus &#8211; 1"},"content":{"rendered":"<!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><h2 class=\"wp-block-heading\">Event Overview<\/h2>\n\n\n\n<p>Recently, NSFOCUS CERT, through ongoing monitoring, found that the source code of the Paradise ransomware was leaked. Since data encrypted by Paradise cannot be decrypted now, the source code, if widely spread over the Internet, may cause a lot of trouble.<\/p>\n\n\n\n<p>Paradise had its source code leaked on a Russian hacker forum on the dark web on June 12, becoming the second mainstream ransomware linked with such an event, following Dharma whose source code was disclosed in 2020.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"775\" height=\"620\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/1-1.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17452\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/1-1.jpg 775w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/1-1-300x240.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/1-1-768x614.jpg 768w\" sizes=\"(max-width: 775px) 100vw, 775px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Evolution of Paradise<\/h2>\n\n\n\n<p>First spotted in September 2017, Paradise was distributed via the ransomware-as-a-service (RaaS) model. At first, it was spread through links and attachments in phishing emails, mainly targeting individual end users and small enterprises. Its ransom note was typically as follows:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"516\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/2-1.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17454\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/2-1.jpg 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/2-1-300x151.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/2-1-768x387.jpg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>In October 2019, the new version of Paradise, which used Salsa20 and RSA-1024 to encrypt files with such extensions as .paradise, .2ksys19, .p3rf0rm4, and .FC, was decrypted by Emsisoft, a New Zealand-based security vendor. The company then released a decryption tool, which is available at the following link:<\/p>\n\n\n\n<p><a href=\"https:\/\/www.emsisoft.com\/ransomware-decryption-tools\/download\/paradise\">https:\/\/www.emsisoft.com\/ransomware-decryption-tools\/download\/paradise<\/a><\/p>\n\n\n\n<p>Subsequently, the Paradise operator updated the virus, which, however, was decrypted again by Bitdefender in January 2020. The decryption tool is available at the following link:<\/p>\n\n\n\n<p><a href=\"https:\/\/labs.bitdefender.com\/wp-content\/uploads\/downloads\/paradise-ransomware-decryptor\/\">https:\/\/labs.bitdefender.com\/wp-content\/uploads\/downloads\/paradise-ransomware-decryptor\/<\/a><\/p>\n\n\n\n<p>The ransom note of the new version is as follows:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"588\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/3-1.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17456\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/3-1.jpg 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/3-1-300x172.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/3-1-768x441.jpg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Throughout the year 2020, Paradise became obviously less active. The last time when the sample was spotted was January 2021. Presumably, the project has been given up.<\/p>\n\n\n\n<p>The following figure shows statistics about Paradise submissions on a malware platform.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"353\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/4-1-1024x353.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17458\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/4-1-1024x353.jpg 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/4-1-300x103.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/4-1-768x264.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/4-1.jpg 1156w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Paradise versions in 2017&acirc;&euro;&ldquo;2020:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Paradise: initial version, which could be decrypted because of an encryption vulnerability<\/li><li>Paradise.NET: a secure .net version using RSA to encrypt files<\/li><li>ParadiseB29: a variant used by a &#8220;team&#8221; that encrypts only the end of a file<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Source Code Analysis and Verification<\/h2>\n\n\n\n<p><strong>1. Builder: DP_Builder<\/strong><\/p>\n\n\n\n<p>The code disclosed this time is for the builder of the Paradise ransomware, DP_Builder, which can be used to build a whole package of Paradise, including the main program, decrypter, and a private key generator.<\/p>\n\n\n\n<p>The following figure shows the interface of DP_Builder after being compiled and executed.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"519\" height=\"406\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/5-1.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17460\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/5-1.jpg 519w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/5-1-300x235.jpg 300w\" sizes=\"(max-width: 519px) 100vw, 519px\" \/><\/figure>\n\n\n\n<ol class=\"wp-block-list\"><li>Click <strong>Generate<\/strong> to generate a random RSA encryption vector.<\/li><li>Extension of the encrypted file name (translated from Russian).<\/li><li>Server address of the ransomware, used for information collection.<\/li><li>Admin key, irrelevant to encryption and used for identifying the builder user.<\/li><\/ol>\n\n\n\n<p>Values typed for <strong>Site<\/strong> and <strong>Admin key<\/strong> are saved in <strong>Server.info<\/strong>. When executed again, the builder will read from this file and use these values to automatically populate the fields.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"915\" height=\"208\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/6.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17462\"><\/figure>\n\n\n\n<p>If <strong>Server.info<\/strong> exists, the interface of DP_Builder is as follows:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"807\" height=\"443\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/7.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17464\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/7.jpg 807w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/7-300x165.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/7-768x422.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/7-200x110.jpg 200w\" sizes=\"(max-width: 807px) 100vw, 807px\" \/><\/figure>\n\n\n\n<p>1 and 2 are two email addresses (presumably, one is displayed to victims and the other is for web authentication). 3 is for entry of a contact method for the license and encrypted file extensions.<\/p>\n\n\n\n<p>Clicking <strong>Create build<\/strong>, you have the ransomware compiled and built, including the main program, decrypter, and private key generator.<\/p>\n\n\n\n<p>The code for the main program, decrypter, and private key generator is stored in the resource file of DP_Builder. Each time the package is created, random 1024-bit RSA keys are generated and the private key is built into the ransomware. This promises a certain level of encryption security.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"720\" height=\"119\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/8.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17466\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/8.jpg 720w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/8-300x50.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/8-200x33.jpg 200w\" sizes=\"(max-width: 720px) 100vw, 720px\" \/><\/figure>\n\n\n\n<p>The source code of the three programs previously built can be obtained with the .NET decompilation tool.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"515\" height=\"640\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/9.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17468\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/9.jpg 515w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/9-241x300.jpg 241w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/9-200x249.jpg 200w\" sizes=\"(max-width: 515px) 100vw, 515px\" \/><\/figure>\n\n\n\n<p><strong>2. Encrypter: DP_Main<\/strong><\/p>\n\n\n\n<p>DP_Main.cs is the main program of the ransomware. It provides typical ransomware functions, including encrypting disk files, copying itself to a temporary directory, modifying the registry for automatic running at startup, and deleting volume shadow backups.<\/p>\n\n\n\n<p><strong>2.1 Use of RSA to Encrypt Files<\/strong><\/p>\n\n\n\n<p>DP_Builder hardcodes variables, such as the RSA public key and iv, into the program.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"885\" height=\"267\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/10.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17470\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/10.jpg 885w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/10-300x91.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/10-768x232.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/10-200x60.jpg 200w\" sizes=\"(max-width: 885px) 100vw, 885px\" \/><\/figure>\n\n\n\n<p>The program starts count statistics and attempts to run as admin.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"851\" height=\"252\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/11.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17472\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/11.jpg 851w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/11-300x89.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/11-768x227.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/11-200x59.jpg 200w\" sizes=\"(max-width: 851px) 100vw, 851px\" \/><\/figure>\n\n\n\n<p>The ransomware, when running, checks whether the previously generated key file exists. If yes, it directly encrypts the file.<\/p>\n\n\n\n<p>During the first running, a new RSA key pair is created for encrypting files. The built-in RSA public key is used to encrypt and store the newly generated RSA private key used for file encryption.<\/p>\n\n\n\n<p>The main code is as follows, showing that registry modification and volume shadow backup deletion are conducted only during the first running:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"812\" height=\"394\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/12.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17474\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/12.jpg 812w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/12-300x146.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/12-768x373.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/12-200x97.jpg 200w\" sizes=\"(max-width: 812px) 100vw, 812px\" \/><\/figure>\n\n\n\n<p>The SavePrivateKey function encrypts the private key for encryption. This private key is required for decrypting files. However, it is encrypted with the MasterRSA public key, and the MasterRSA private key is in the hands of attackers. This way, files cannot be decrypted until ransom is paid.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"951\" height=\"316\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/13.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-17476\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/13.jpg 951w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/13-300x100.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/13-768x255.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/13-200x66.jpg 200w\" sizes=\"(max-width: 951px) 100vw, 951px\" \/><\/figure>\n<\/body><\/html>\n","protected":false},"excerpt":{"rendered":"<p>Event Overview Recently, NSFOCUS CERT, through ongoing monitoring, found that the source code of the Paradise ransomware was leaked. Since data encrypted by Paradise cannot be decrypted now, the source code, if widely spread over the Internet, may cause a lot of trouble. Paradise had its source code leaked on a Russian hacker forum on [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":12292,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[3,5],"tags":[578,601,603],"class_list":["post-17451","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-ddos-mitigation","tag-paradise","tag-raas","tag-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>A Look into Source Code of Paradise Ransomware, a &quot;Custom-Built&quot; Virus - 1 - NSFOCUS<\/title>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A Look into Source Code of Paradise Ransomware, a &quot;Custom-Built&quot; Virus - 1 - NSFOCUS\" \/>\n<meta property=\"og:description\" content=\"Event Overview Recently, NSFOCUS CERT, through ongoing monitoring, found that the source code of the Paradise ransomware was leaked. Since data encrypted\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/\" \/>\n<meta property=\"og:site_name\" content=\"NSFOCUS\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-16T06:46:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-17T18:07:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2020\/12\/ransomware.jpg\" \/>\n<meta name=\"author\" content=\"Jie Ji\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"A Look into Source Code of Paradise Ransomware, a &quot;Custom-Built&quot; Virus - 1 - NSFOCUS\" \/>\n<meta name=\"twitter:description\" content=\"Event Overview Recently, NSFOCUS CERT, through ongoing monitoring, found that the source code of the Paradise ransomware was leaked. Since data encrypted\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2020\/12\/ransomware.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jie Ji\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/\"},\"author\":{\"name\":\"Jie Ji\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/person\\\/1077d8fcd7e52c96f17a33b63a0d157b\"},\"headline\":\"A Look into Source Code of Paradise Ransomware, a &#8220;Custom-Built&#8221; Virus &#8211; 1\",\"datePublished\":\"2021-07-16T06:46:51+00:00\",\"dateModified\":\"2026-04-17T18:07:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/\"},\"wordCount\":765,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/ransomware.jpg\",\"keywords\":[\"paradise\",\"RaaS\",\"Ransomware\"],\"articleSection\":[\"Blog\",\"DDoS Mitigation\"],\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/\",\"name\":\"A Look into Source Code of Paradise Ransomware, a \\\"Custom-Built\\\" Virus - 1 - NSFOCUS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/ransomware.jpg\",\"datePublished\":\"2021-07-16T06:46:51+00:00\",\"dateModified\":\"2026-04-17T18:07:45+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/ransomware.jpg\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/ransomware.jpg\",\"width\":562,\"height\":334,\"caption\":\"Ransomware concept with locked padlock and chains.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nsfocusglobal.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A Look into Source Code of Paradise Ransomware, a &#8220;Custom-Built&#8221; Virus &#8211; 1\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#website\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/\",\"name\":\"NSFOCUS\",\"description\":\"Security Made Smart and Simple\",\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\",\"name\":\"NSFOCUS\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"width\":248,\"height\":36,\"caption\":\"NSFOCUS\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/person\\\/1077d8fcd7e52c96f17a33b63a0d157b\",\"name\":\"Jie Ji\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g\",\"caption\":\"Jie Ji\"},\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/author\\\/jji\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A Look into Source Code of Paradise Ransomware, a \"Custom-Built\" Virus - 1 - NSFOCUS","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"pt_BR","og_type":"article","og_title":"A Look into Source Code of Paradise Ransomware, a \"Custom-Built\" Virus - 1 - NSFOCUS","og_description":"Event Overview Recently, NSFOCUS CERT, through ongoing monitoring, found that the source code of the Paradise ransomware was leaked. Since data encrypted","og_url":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/","og_site_name":"NSFOCUS","article_published_time":"2021-07-16T06:46:51+00:00","article_modified_time":"2026-04-17T18:07:45+00:00","og_image":[{"url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2020\/12\/ransomware.jpg","type":"","width":"","height":""}],"author":"Jie Ji","twitter_card":"summary_large_image","twitter_title":"A Look into Source Code of Paradise Ransomware, a \"Custom-Built\" Virus - 1 - NSFOCUS","twitter_description":"Event Overview Recently, NSFOCUS CERT, through ongoing monitoring, found that the source code of the Paradise ransomware was leaked. Since data encrypted","twitter_image":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2020\/12\/ransomware.jpg","twitter_misc":{"Escrito por":"Jie Ji","Est. tempo de leitura":"4 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/#article","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/"},"author":{"name":"Jie Ji","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/person\/1077d8fcd7e52c96f17a33b63a0d157b"},"headline":"A Look into Source Code of Paradise Ransomware, a &#8220;Custom-Built&#8221; Virus &#8211; 1","datePublished":"2021-07-16T06:46:51+00:00","dateModified":"2026-04-17T18:07:45+00:00","mainEntityOfPage":{"@id":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/"},"wordCount":765,"commentCount":0,"publisher":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization"},"image":{"@id":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2020\/12\/ransomware.jpg","keywords":["paradise","RaaS","Ransomware"],"articleSection":["Blog","DDoS Mitigation"],"inLanguage":"pt-BR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/","url":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/","name":"A Look into Source Code of Paradise Ransomware, a \"Custom-Built\" Virus - 1 - NSFOCUS","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/#primaryimage"},"image":{"@id":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2020\/12\/ransomware.jpg","datePublished":"2021-07-16T06:46:51+00:00","dateModified":"2026-04-17T18:07:45+00:00","breadcrumb":{"@id":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/#primaryimage","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2020\/12\/ransomware.jpg","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2020\/12\/ransomware.jpg","width":562,"height":334,"caption":"Ransomware concept with locked padlock and chains."},{"@type":"BreadcrumbList","@id":"https:\/\/nsfocusglobal.com\/a-look-into-source-code-of-paradise-ransomware-a-custom-built-virus-1\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nsfocusglobal.com\/"},{"@type":"ListItem","position":2,"name":"A Look into Source Code of Paradise Ransomware, a &#8220;Custom-Built&#8221; Virus &#8211; 1"}]},{"@type":"WebSite","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#website","url":"https:\/\/nsfocusglobal.com\/pt-br\/","name":"NSFOCUS","description":"Security Made Smart and Simple","publisher":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nsfocusglobal.com\/pt-br\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization","name":"NSFOCUS","url":"https:\/\/nsfocusglobal.com\/pt-br\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/logo\/image\/","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","width":248,"height":36,"caption":"NSFOCUS"},"image":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/person\/1077d8fcd7e52c96f17a33b63a0d157b","name":"Jie Ji","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/secure.gravatar.com\/avatar\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g","caption":"Jie Ji"},"url":"https:\/\/nsfocusglobal.com\/pt-br\/author\/jji\/"}]}},"_links":{"self":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/17451","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/comments?post=17451"}],"version-history":[{"count":0,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/17451\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media\/12292"}],"wp:attachment":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media?parent=17451"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/categories?post=17451"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/tags?post=17451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}