3,719 indexed

SOFTWARESoftware & malware

3,719 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 801–850 of 3,719 · page 17 of 75

IDTitleSummary
DECYOURDATADecYourDataRansomware
DEDCRYPTORDEDCryptorRansomware Based on EDA2
DEEPER-RATDeeper RAT
DEFENDERDefenderRansomware
DEFRAY-GLUSHKOVDefray (Glushkov)Ransomware
DELPHIMORIXDeLpHiMoRix
DELTAdelta
DEMODemoRansomware only encrypts .jpg files
DENDROIDDendroidDendroid is malware that affects Android OS and targets the mobile platform. It was first discovered in early of 2014 by Symantec and appeared in the undergrou…
DENESRATDenesRATDenesRAT is a private Trojan horse of the "Sea Lotus" organization, which can perform corresponding functions according to the instructions issued by the C2 se…
DEOSDeosRansomware
DEPRIMONDePriMonDePriMon is a malicious downloader, with several stages and using many non-traditional techniques. To achieve persistence, the malware registers a new local po…
DERIALOCK-RANSOMWAREDeriaLock RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
DEROHEDeroHEransomware
DERUSBIDerusbi
DESKTOPDesktopRansomware
DESKTOPNOWDesktopNowDesktopNow is a free remote access program from NCH Software. After optionally forwarding the proper port number in your router, and signing up for a free acco…
DESOLATEDdesolated
DESOLATORdesolator
DESYNCDesyncThis crypto ransomware encrypts enterprise LAN data with AES (ECB mode), and then requires a ransom in # BTC to return the files.
DETOXCRYPTODetoxCryptoRansomware - Based on Detox: Calipso, We are all Pokemons, Nullbyte
DEVMANdevman
DEVMAN2devman2
DEVOSDevosransomware
DHARMAdharmaDharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware. It operates under a Ransomware-as-a-Service (Ra…
DHARMA-RANSOMWAREDharma RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
DHS2015DHS2015
DIAMONDDiamondRansomware
DIAVOLDiavolA ransomware with potential ties to Wizard Spider.
DIGISOMDigisomRansomware
DIGMINEDigmineDigmine is coded in AutoIt, and sent to would-be victims posing as a video file but is actually an AutoIt executable script. If the user’s Facebook account is …
DILMALOCKERDilmaLockerRansomware
DIMNIEDimnieDimnie, the commonly agreed upon name for the binary dropped by the PowerShell script above, has been around for several years. Palo Alto Networks has observed…
DINOLABDINOLABDINOLAB is a C/C++ builder. It is used to encrypt and decrypt files, obfuscate VBSscripts, and infect files. Availability: Non-public
DIRCRYPTDirCrypt
DIREWOLFdirewolf
DIRTYDECRYPTDirtyDecryptRansomware
DISGUFADisgufa
DISHWASHERDishwasherRansomware
DISKDOCTORDiskDoctornew Scarab Ransomware variant called DiskDoctor that appends the .DiskDoctor extension and drops a ransom note named HOW TO RECOVER ENCRYPTED FILES.TXT
DISPOSSESSORdispossessor
DISTRICTDistrictRansomware
DJANGODjangoransomware
DJVUDjvu
DMA-LOCKER-1-0-2-0-3-0DMA Locker 1.0-2.0-3.0Ransomware
DMA-LOCKER-4-0DMA Locker 4.0Ransomware
DMALOCKERDMALockerRansomware no extension change Encrypted files have prefix: Version 1: ABCXYZ11 - Version 2: !DMALOCK - Version 3: !DMALOCK3.0 - Version 4: !DMALOCK4.0
DMALOCKER-3-0DMALocker 3.0Ransomware
DMALOCKER-IMPOSTERDMALocker ImposterRansomware
DNDNIt’s directed to English speaking users, therefore is able to infect worldwide. Uses the name “Chrome Update” to confuse its victims. Then imitates the chrome…
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.
Software & malware — full index | SQUR Knowledge Base