3,719 indexed

SOFTWARESoftware & malware

3,719 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 3,151–3,200 of 3,719 · page 64 of 75

IDTitleSummary
SKYFILESkyFile
SKYIPOTSkyipot
SKYNAME-RANSOMWARESkyName RansomwareIt’s directed to Czechoslovakianspeaking users. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: mu…
SKYSTARSSkyStarsransomware
SLAMslam
SLANKCRYPTORSlankCryptorransomware
SLEMPOSlempoAndroid-based malware
SLENFBOTSlenfbotSlenfbot was first discovered in 2007 and, since then, numerous variants have followed; each with slightly different characteristics and new additions to the w…
SLIMCURLSLIMCURLSLIMCURL is a C/C++ downloader. It contains the next stage as a Base64 encoded Google Drive link. The next stage is downloaded using cURL. Availability: Non-pu…
SLIMHEM-RANSOMWARESlimhem RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is NOT spread using email spam, fake updates, attachments and so on. It sim…
SLIVERSLIVERSliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. Slive…
SLOWDRIFTSLOWDRIFTSLOWDRIFT is a launcher that communicates via cloud based infrastructure. It sends system information to the attacker command and control and then downloads an…
SLUB-BACKDOORSLUB BackdoorThe SLUB backdoor is a custom one written in the C++ programming language, statically linking curl library to perform multiple HTTP requests. Other statically-…
SLUGslug
SMALL-NETSmall-NetRAT
SMALLNETsmallnetRemote Access Trojan
SMASHSmash!Ransomware
SMAUGSmaugransomware
SMBTOUCHSMBTOUCHcheck if the target is vulnerable to samba exploits like ETERNALSYNERGY, ETERNALBLUE, ETERNALROMANCE
SMOKE-LOADERSmoke LoaderThis small application is used to download other malware. What makes the bot interesting are various tricks that it uses for deception and self protection.
SMRSS32Smrss32Ransomware
SNAKE-EKANSSnake-Ekansransomware
SNAKE-RANSOMWARESnake RansomwareSnake ransomware first attracted the attention of malware analysts in January 2020 when they observed the crypto-malware family targeting entire corporate netw…
SNAKELOCKERSnakeLockerransomware
SNATCHSnatchransomware
SNIFULASnifula
SNOOPYSnoopySnoopy is a Remote Administration Tool. Software for controlling user computer remotely from other computer on local network or Internet.
SNOWDOORSnowdoorBackdoor.Snowdoor is a Backdoor Trojan Horse that allows unauthorized access to an infected computer. It creates an open C drive share with its default setting…
SNOWPICNICSnowPicnicransomware
SNOWYAMBERSNOWYAMBERA tool first used in October 2022, abusing the Notion service to communicate and download further malicious files. Two versions of this tool have been observed…
SNSLOCKERSNSLockerRansomware Based on EDA2
SNUGRIDESNUGRIDESNUGRIDE is a backdoor that communicates with its C2 server through HTTP requests. Messages are encrypted using AES with a static key. The malware’s capabiliti…
SOCKET23Socket23SOCKET23 was launched from his web site and immedi- ately infected major French corporations between August and October 1998. The virus (distributing the Troja…
SOCKETPLAYERSocketPlayerThe RAT is written in .NET, it uses socket.io for communication. Currently there are two variants of the malware, the 1st variant is a typical downloader where…
SODAMASTERSodaMasterThis is a RAT that is usually loaded with one or more shellcode and/or reflective DLL injection techniques. The RAT uses RC4 or a hardcoded RSA key for traffic…
SODINOKIBISodinokibiAttackers are actively exploiting a recently disclosed vulnerability in Oracle WebLogic to install a new variant of ransomware called "Sodinokibi." Sodinokibi …
SOFUCKEDSoFuckedransomware
SOLEENYAsoleenya
SOLIDBITSolidbitRansomware, written in .NET.
SOLIDERSoliderransomware
SOLOSOLOransomware
SOLVESolveransomware
SOMIK1Somik1ransomware
SORASoraBig changes on the IoT malware scene. Security researchers have spotted a version of the Mirai IoT malware that can run on a vast range of architectures, and e…
SOREBRECTSOREBRECTFileless, Code-injecting Ransomware
SORRY-HTSorry HTransomware
SOUNDWAVESOUNDWAVESOUNDWAVE is a windows based audio capturing utility. Via command line it accepts the -l switch (for listen probably), captures microphone input for 100 minute…
SOURFACESOURFACEdownloader - Older version of CORESHELL
SPACE-BEARSspace bears
SPAMTHRUSpamthruSpam Thru represented an expontential jump in the level of sophistication and complexity of these botnets, harnessing a 70,000 strong peer to peer botnet seede…
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.
Software & malware — full index | SQUR Knowledge Base