3,719 indexed

SOFTWARESoftware & malware

3,719 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 2,051–2,100 of 3,719 · page 42 of 75

IDTitleSummary
PHOBOSPhobosPhobos exploits open or poorly secured RDP ports to sneak inside networks and execute a ransomware attack, encrypting files and demanding a ransom be paid in b…
PHOBOSIMPOSTERPhobosImposterransomware
PHONENUMBERPhoneNumberransomware
PHORPIEXPhorpiexProofpoint describes Phorpiex/Trik as a SDBot fork (thus IRC-based) that has been used to distribute GandCrab, Pushdo, Pony, and coinminers. The name Trik is d…
PHPPHPransomware
PICKLESRANSOMWAREPicklesRansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
PICO-RANSOMWAREPICO RansomwareS!Ri found a new Thanatos Ransomware variant called PICO Ransomware. This ransomware will append the .PICO extension to encrypted files and drop a ransom note …
PIRATELOCKpiratelock
PIRATEWAREPiratewareransomware
PIRPIPirpiSymantec has observed Buckeye activity dating back to 2009, involving attacks on various organizations in several regions. Buckeye used a remote access Trojan …
PIRRITPirritPirrit is a potentially unwanted application (PUA) for Windows and MacOS devices. It displays additional pop-ups and advertisements when the device is used. Pi…
PITOUPitouPitou is a trojan for Windows devices. Its functions are to steal passwords and collect various pieces of information about the mobile phone, such as its locat…
PIZHONPizhonransomware
PIZZACRYPTSPizzaCryptsRansomware
PLPLransomware
PLAINTEEPLAINTEEThis sample is configured with three exported functions: Add, Sub, DllEntryPoint. The DLL expects the export named ‘Add’ to be used when initially loaded. When…
PLANETARYPlanetaryFirst discovered by malware security analyst, Lawrence Abrams, PLANETARY is an updated variant of another high-risk ransomware called HC7.
PLASMA-RATPlasma RATPlasma RAT’s stub is fairly advanced, having many robust features. Some of the features include botkilling, Cryptocurrencies Mining (CPU and GPU), persistence,…
PLAYplayInitially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. It…
PLAY-RANSOMWAREPLAY RansomwareRansomware
PLAYBOYplayboy
PLEADPLEADPLEAD has two kinds – RAT (Remote Access Tool) and downloader. The RAT operates based on commands that are provided from C&C servers. On the other hand, PLEAD …
PLEAD-DOWNLOADERPLEAD DownloaderPLEAD is referred to both as a name of malware including TSCookie and its attack campaign. PLEAD has two kinds – RAT (Remote Access Tool) and downloader. The R…
PLEASEREAD-RANSOMWAREPleaseRead RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
PLEXORPlexor
PLUGXPlugXPLUGX is a remote access tool (RAT) used in targeted attacks aimed toward government-related institutions and key industries. It was utilized the same way as P…
PNG-DROPPERPNG DropperThe PNG_dropper family primarily uses a modified version of the publicly available tool JPEGView.exe (version 1.0.32.1 – both x86 and x64 bit versions). Carbo…
POCKET-RATPocket RAT
POISON-IVYPoison IvyPoison Ivy is a RAT which was freely available and first released in 2005.
POISONFANGPoisonFangransomware
POISONIVYPoisonIvyPoison Ivy is a RAT which was freely available and first released in 2005.
POJIEPojieransomware
POKEMONGOPokemonGORansomware Based on Hidden Tear
POLSKI-RANSOMWAREPolski RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
POLYGLOTPolyglotRansomware Immitates CTB-Locker
POLYVICEpolyvice
PONTOEBPontoebThe bot gathers information from the infected system through WMI queries (SerialNumber, SystemDrive, operating system, processor architecture), which it then s…
PONYFINALPonyFinalransomware
POOLEZOORPooleZoorransomware
POORAIMPOORAIMPOORAIM malware is designed with basic backdoor functionality and leverages AOL Instant Messenger for command and control communications. POORAIM includes the …
POPCORN-TIME-RANSOMWAREPopCorn Time RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
POPCORNTIMEPopCornTimeransomware
PORNBLACKMAILERPornBlackmailerA new infection is being distributed by porn sites that tries to blackmail a victim into paying a ransom by stating they will tell law enforcement that the vic…
POTATO-RANSOMWAREPotato RansomwareWants a ransom to get the victim’s files back . Originated in English. Spread worldwide.
POVISOMWAREPovisomwareransomware
POWERGHOSTPowerGhostPowerGhost is capable of stealthily establishing itself in a system and spreading across large corporate networks infecting both workstations and servers. This…
POWERHENTAIPowerHentairansomware
POWERLOCKYPowerLockyransomware
POWERRATPowerRAT
POWERRATANKBAPowerRatankbaPowerRatankba is used for the same purpose as Ratankba: as a first stage reconnaissance tool and for the deployment of further stage implants on targets that a…
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.