3,697 indexed

SOFTWARESoftware & malware

3,697 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 1,151–1,200 of 3,697 · page 24 of 74

IDTitleSummary
GENEVEGeneveransomware
GENOBOTGenobotransomware
GERBER-RANSOMWARE-1-0Gerber Ransomware 1.0
GERBER-RANSOMWARE-3-0Gerber Ransomware 3.0
GERMANWIPERGermanWiperransomware
GETCRYPTGetCryptA new ransomware is in the dark market which encrypts all the files on the device and redirects victims to the RIG exploit kit.
GETMAILGETMAILMembers of this family of malware are utilities designed to extract email messages and attachments from Outlook PST files. One part of this utility set is an e…
GG-RANSOMWAREGG RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
GH0STgh0stRemote Access Trojan
GH0ST-RATGh0st RATGh0st RAT is a Trojan horse for the Windows platform that the operators of GhostNet used to hack into some of the most sensitive computer networks on Earth. It…
GHEGGhegTofsee, also known as Gheg, is another botnet analyzed by CERT Polska. Its main job is to send spam, but it is able to do other tasks as well. It is possible t…
GHOLEGHOLE
GHOSTGhost
GHOSTADMINGhostAdminAccording to MalwareHunterTeam and other researchers that have looked at the malware's source code, GhostAdmin seems to be a reworked version of CrimeScene, an…
GHOSTCRYPTGhostCryptRansomware Based on Hidden Tear
GHOSTENCRYPTORGhosTEncryptorransomware
GHOSTHAMMERGhostHammerransomware
GHOSTMINERGhostMinerGhostMiner is a new cryptocurrency mining malware. By the end of March 2018, a new variant of mining malware was detected targeting MSSQL, phpMyAdmin, and Orac…
GHOTEXGHOTEXPE_GHOTEX.A-O is a portable executable (PE is the standard executable format for 32-bit Windows files) virus. PE viruses infect executable Windows files by inc…
GIBBERISHGibberishransomware
GIBONGibonransomware
GINGERBREADGingerbreadRansomware
GIYOTINGiyotinransomware
GLADIUSGladiusransomware
GLOBALglobalNot a RaaS yet.
GLOBEglobeGlobe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allows operators to configure ransom note te…
GLOBE-V1Globe v1Ransomware
GLOBE2-RANSOMWAREGlobe2 RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
GLOBE3-RANSOMWAREGlobe3 RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
GLOBEIMPOSTERGlobeImposterDuring December 2017, a new variant of the GlobeImposter Ransomware was detected for the first time and reported on malware-traffic-analysis. At first sight th…
GLOOXMAILGLOOXMAILGLOOXMAIL communicates with Google's Jabber/XMPP servers and authenticates with a hard-coded username and password. The malware can accept commands over XMPP …
GLUPTEBAGluptebaA multi-component botnet targeting Windows Computer. Glupteba is known to steal user credentials and cookies, mine cryptocurrencies on infected hosts, deploy a…
GNL-LOCKERGNL LockerRansomware Only encrypts DE or NL country. Variants, from old to latest: Zyklon Locker, WildFire locker, Hades Locker
GOCRYPTOLOCKERGoCryptoLockerransomware
GOD-CRYPT-JOKE-RANSOMWAREGod Crypt Joke RansomwareMalwareHunterTeam found a new ransomware called God Crypt that does not appear to decrypt and appears to be a joke ransomware. Has an unlock code of 29b579fb81…
GODRAGodraransomware
GOG-RANSOMWAREGOG RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
GOGGLESGOGGLESA family of downloader malware, that retrieves an encoded payload from a fixed location, usually in the form of a file with the .jpg extension. Some variants h…
GOGOOGLEGoGoogleransomware
GOHACKGoHackransomware
GOLDDRAGONGOLDDRAGONGOLDDRAGON is a downloader written in C that retrieves a payload from a remote server via HTTP. The downloaded payload is written to disk and executed. GOLDDRA…
GOLDDROPGOLDDROPGOLDDROP is a C/C++ Windows dropper. It decrypts a resource file, saves it to the file system, and injects it into another process. Availability: Non-public
GOLDEN-AXEGolden Axeransomware
GOLDEN-PHOENIXGOlden Phoenix
GOLDENEYE-RANSOMWAREGoldenEye RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
GOLDFINDERGoldFinderTool written in Go, GoldFinder was most likely used as a custom HTTP tracer tool that logs the route or hops that a packet takes to reach a hardcoded C2 server…
GOLDMAXGoldMaxWritten in Go, GoldMax acts as command-and-control backdoor for the actor. It uses several different techniques to obfuscate its actions and evade detection. T…
GOLDSMELTGOLDSMELTGOLDSMELT is a C/C++ utility used to close the rundll32.exe process and delete a file likely used for logs. Availability: Non-public
GOMASOMGomasomRansomware
GOMMEGommeransomware
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.