3,697 indexed

SOFTWARESoftware & malware

3,697 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 801–850 of 3,697 · page 17 of 74

IDTitleSummary
DEOSDeosRansomware
DEPRIMONDePriMonDePriMon is a malicious downloader, with several stages and using many non-traditional techniques. To achieve persistence, the malware registers a new local po…
DERIALOCK-RANSOMWAREDeriaLock RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
DEROHEDeroHEransomware
DERUSBIDerusbi
DESKTOPDesktopRansomware
DESKTOPNOWDesktopNowDesktopNow is a free remote access program from NCH Software. After optionally forwarding the proper port number in your router, and signing up for a free acco…
DESOLATEDdesolated
DESOLATORdesolator
DESYNCDesyncThis crypto ransomware encrypts enterprise LAN data with AES (ECB mode), and then requires a ransom in # BTC to return the files.
DETOXCRYPTODetoxCryptoRansomware - Based on Detox: Calipso, We are all Pokemons, Nullbyte
DEVMANdevman
DEVMAN2devman2
DEVOSDevosransomware
DHARMAdharmaDharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware. It operates under a Ransomware-as-a-Service (Ra…
DHARMA-RANSOMWAREDharma RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
DHS2015DHS2015
DIAMONDDiamondRansomware
DIAVOLDiavolA ransomware with potential ties to Wizard Spider.
DIGISOMDigisomRansomware
DIGMINEDigmineDigmine is coded in AutoIt, and sent to would-be victims posing as a video file but is actually an AutoIt executable script. If the user’s Facebook account is …
DILMALOCKERDilmaLockerRansomware
DIMNIEDimnieDimnie, the commonly agreed upon name for the binary dropped by the PowerShell script above, has been around for several years. Palo Alto Networks has observed…
DINOLABDINOLABDINOLAB is a C/C++ builder. It is used to encrypt and decrypt files, obfuscate VBSscripts, and infect files. Availability: Non-public
DIRCRYPTDirCrypt
DIREWOLFdirewolf
DIRTYDECRYPTDirtyDecryptRansomware
DISGUFADisgufa
DISHWASHERDishwasherRansomware
DISKDOCTORDiskDoctornew Scarab Ransomware variant called DiskDoctor that appends the .DiskDoctor extension and drops a ransom note named HOW TO RECOVER ENCRYPTED FILES.TXT
DISPOSSESSORdispossessor
DISTRICTDistrictRansomware
DJANGODjangoransomware
DJVUDjvu
DMA-LOCKER-1-0-2-0-3-0DMA Locker 1.0-2.0-3.0Ransomware
DMA-LOCKER-4-0DMA Locker 4.0Ransomware
DMALOCKERDMALockerRansomware no extension change Encrypted files have prefix: Version 1: ABCXYZ11 - Version 2: !DMALOCK - Version 3: !DMALOCK3.0 - Version 4: !DMALOCK4.0
DMALOCKER-3-0DMALocker 3.0Ransomware
DMALOCKER-IMPOSTERDMALocker ImposterRansomware
DNDNIt’s directed to English speaking users, therefore is able to infect worldwide. Uses the name “Chrome Update” to confuse its victims. Then imitates the chrome…
DNRANSOMWAREDNRansomwareRansomware Code to decrypt: 83KYG9NW-3K39V-2T3HJ-93F3Q-GT
DNSMESSENGERDNSMessengerTalos recently analyzed an interesting malware sample that made use of DNS TXT record queries and responses to create a bidirectional Command and Control (C2) …
DODGERDodgerRansomware
DOGCALLDOGCALLDOGCALL is a backdoor commonly distributed as an encoded binary file downloaded and decrypted by shellcode following the exploitation of weaponized documents. …
DOGECRYPTDogeCryptransomware
DOLPHINTEARDolphinTearRansomware
DOMINODominoRansomware Based on Hidden Tear
DONALD-TRUMPDonald TrumpRansomware
DONALD-TRUMP-2-RANSOMWAREDonald Trump 2 RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
DONATION1Donation1Ransomware
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.