Ngày
|
Tên ransomware +
VirusTotal
|
Ghi chú
|
30/12/2018
|
FilesLocker
v2 ransomware (Christmas)
|
#Note: 解密我的文件.txt
#DECRYPT MY FILES.txt #Update 31/12/2018: Có thể giải mã
|
Globe
ransomware
|
#Extension: .globe #Email: [email protected]
|
|
Paradise (VACv2 code) ransomware
|
#Extension: ._%ID%_{[email protected]}.CORP
|
29/12/2018
|
Project57
ransomware
|
#Extension: .костя баранин #Note: DECRYPT.HTML
|
26/12/2018
|
Bizer
CrySiS ransomware
|
#Dharma ransomware #Extension: .bizer #Email:
[email protected]
|
25/12/2018
|
MindSystem
ransomware
|
#MindSystemNotRansomWare
|
24/12/2018
|
Lockify
ransomware
|
#KGDecrypt Ransomware #.NET ransomware #Extension:
.tunca
|
23/12/2018
|
VACv2
Paradise ransomware
|
#Extension: .VACv2 #Note: $%%! NOTE ABOUT FILES
-=!-.html
|
20/12/2018
|
demo
ransomware
|
#from "Cisco Cyber Range Security Team"
|
Cypher
ransomware
|
#Extension: .cypher # Email contact:
[email protected] &
[email protected]
|
19/12/2018
|
Grafimatriux
ransomware
|
#Extension: .Защищено
|
Ransomwared
ransomware
|
#Extension: .ransomwared #Email:
[email protected]
|
|
Ransom102
ransomware
|
|
18/12/2018
|
GandCrab
v5.1.6 ransomware
|
|
GandCrab
v5.1.5 ransomware
|
|
GandCrab
v5.1.4 ransomware
|
|
GandCrab
v5.1.0 ransomware
|
#Extension: .ducueyuav
|
GandCrab
v5.1. ransomware
|
#Extension: .jsajpse
|
GandCrab
v5.0.9 ransomware
|
|
GandCrab
v5.0.8 ransomware
|
|
|
GandCrab
v5.0.7 ransomware
|
|
17/12/2018
|
PewDiePie
ransomware
|
#ShellLocker.
|
16/12/2018
|
Jemd
Ransomware
|
#Ransom note: Recovery.txt #Email contact:
[email protected]
|
15/12/2018
|
Scarab-Enter
ransomware
|
#Ransom note: HELP HELP HELP.TXT
|
|
Cyron
Screenlocker
|
#Email: [email protected]
|
13/12/2018
|
Black
Worm Ransomware
|
#Extension: .bworm
|
11/12/2018
|
Forma
ransomware
|
#Extension: .locked #Ransom note:
ODSZYFRFUJ_PLIKI_TERAZ.txt #Email: [email protected]
|
10/12/2018
|
Crypto034
Scarab ransomware
|
#Extension: .crypted034 #Ransom note: HOW TO
RECOVER ENCRYPTED FILES.TXT #Email address: [email protected], [email protected],
[email protected]
|
Thomas
ransomware
|
#French
|
09/12/2018
|
Gerber
ransomware 5.0
|
#Extension: .gerber5 #Ransom note: GRBR Decryptor
|
08/12/2018
|
Cryptre
ransomware
|
|
07/12/2018
|
Gerber
ransomware 3.0
|
#Extension: .FJ7QvaR9VUmi #Ransom note: GRBR Decryptor 3.0
|
Gerber
ransomware 2.0
|
|
Gerber
Ransomware 1.0
|
#Extension: .*.XY6LR
|
|
Outsider
ransomware
|
#Extension: .protected
|
|
Mega
Cryptorr ransomware
|
#Extension: .bip #Note: Information.html
|
06/12/2018
|
Dablio
ransomware
|
#HolyCrypt ransomware
|
05/12/2018
|
Eq
ransomware
|
#Extension: .fuck #GlobeImposter
|
ZeroLocker
ransomware
|
#Extension: .encrypt
|
04/12/2018
|
Israbye
ransomware
|
#Extension: .israbye #Hidden tear
|
03/12/2018
|
GandCrab
v5.0.9 ransomware
|
|
01/12/2018
|
cmdRansomware
|
#Extension: .ransomware #Note: cmdRansomware.txt
|
CashCat
ransomware
|
|
FilesLocker ransomware
|
|
|
Rape
ransomware
|
#Hidden tear
|
30/11/2018
|
Facebook
HT ransomware
|
#Extension: .Facebook #Hidden tear
|
|
StupidJapan
Ransomware
|
|
29/11/2018
|
KUAJW
Raransomware
|
#Extension: .KUAJW
|
GandCrab
V5.0.4 Ransomware
|
#Extension: .poqtqmjvc #Note: POQTQMJVC-DERCYPT.txt
|
|
Bip
GusCrypter ransomware
|
#Extension: .bip #Note: [email protected]
|
|
War Dharma ransomware
|
#Extension: .[[email protected]].war
|
28/11/2018
|
Lightning Everbe 2.0 ransomware
|
#Extension: .[<email>].lightning
|
26/11/2018
|
Lolita
Scarab ransomware
|
#Extension: .lolita #email : [email protected]
|
FilesLocker ransomware v2.0
|
#Extension: .[[email protected]] . #Update 31/12/2018: Có
thể giải mã
|
23/11/2018
|
DeLpHiMoRix!
Red Ransom
|
#Extension: .demonslay335_you_cannot_decrypt_me!
& .malwarehunterteam
|
22/11/2018
|
DeLpHiMoRix!
Ransom
|
.DeLpHiMoRiX!@@@@_@@_@_2018_@@@_@_@_@@@
|
21/11/2018
|
Aurora
ransomware
|
#Zorro Ransomware #Extension: .aurora #Notes:
!-GET_MY_FILES-!.txt
#RECOVERY-PC#.txt, @[email protected] #Email:
[email protected], [email protected] #Update 26/12/2018: Có thể giải mã
|
DeLpHiMoRix!
Ransom
|
#Extension: .DeLpHiMoRix!
|
|
Puma
Stop ransomware
|
#Extension: .Puma #Note: !readme.txt. #Update 30/11/2018: Có
thể giải mã.
|
20/11/2018
|
IEncrypt
ransomware
|
#Extension: .kraussmfz
|
|
GarrantyDecrypt
ransomware
|
#Extension: .decryptgarranty #Note:
#RECOVERY_FILES#.txt
|
17/11/2018
|
EnyBeny
Horsuke ransomware
|
#Extension: .Horsuke #Email: [email protected] &
[email protected]
|
15/11/2018
|
Bear
Dharma ransomware
|
#CrySiS ransomware #Email: [email protected] # Extension: .Bear
|
14/11/2018
|
Sieren
ransomeware
|
|
12/11/2018
|
C3YPT3OR
ransomware
|
|
11/11/2018
|
GrujaRSorium
ransomware
|
#Extension: .GrujaRS
|
Argus
ransomware v1.0
|
#Extension: .Argus #Email: [email protected] &
[email protected]
|
10/11/2018
|
PyCL
ransomware
|
#Extension: .impect #Email: [email protected]
|
|
NoBad Matrix ransomware
|
#Note:#NOBAD_README#.rtf
|
09/11/2018
|
AUDIT
Dharma Ransomware
|
#CrySiS ransomware #Extension: .AUDIT
|
cccmn
Dharma Ransomware
|
#CrySiS ransomware #Extension: .cccmn #Email: [email protected] &
[email protected]
|
|
PPTX
GlobeImposter 2.0 ransomware
|
#Extension .PPTX
|
08/11/2018
|
DispKill
ransomware
|
|
07/11/2018
|
Crypted034
Scarab ransomware
|
#Extension .crypted034
|
|
SaveFiles
ransomware
|
#Note: !readme.txt #Extension: .DATAWAIT
|
06/11/2018
|
CuteRansom
|
#Extension: .6db8
|
Titan
Cryptor ransomware
|
|
Tron
ransomware
|
#Dharma/CrySis ransomware #Extension: .[[email protected]].tron
|
|
Delphi
ransomware
|
#Ghi đè MBR
|
05/11/2018
|
Kraken
Cryptor 2.2 ransomware
|
|
03/11/2018
|
InducVirus
ransomware
|
#DelphiRansomware #Extension: .FilGZmsp #Email:
[email protected]
|
02/11/2018
|
FileFuck
ransom
|
|
XUY
ransomware
|
#Based on Thron ransomware #Extension: .xuy
|
SimmyWare
Ransomware
|
|
01/11/2018
|
Kraken
Cryptor 2.1 ransomware
|
|
31/10/2018
|
NoBab
Matrix ransomware
|
#Email:[email protected];
[email protected] #Note: #NOBAD_README#.rtf
|
|
Vapor
ransomware v1
|
#Extension: .Vapor #Xóa toàn bộ file bị giải mã
khi hết hạn thời gian
|
30/10/2018
|
xxxxx
CrySiS ransomware
|
#Dharma ransomware #Extension: .xxxxx #Email: [email protected]
|
29/10/2018
|
Trojan
Screenlock
|
|
docx
GlobeImposter 2.0 ransomware
|
#Extension: .docx
|
28/10/2018
|
El
Ransomware
|
#extension: .WAND
|
EnybenyCrypt ransomware
|
#Hidden tear #Extension: .crypt888
|
|
M@r1a
ransomware
|
#BlackHeart ransomware #Extension: .mariacbc
|
27/10/2018
|
PikoCrypt
ransomware
|
#CryptoJoker ransomware #Extension: .Piko
|
26/10/2018
|
Troldesh/Shade
ransomware
|
#extension .crypted000007
|
French
ransomware
|
#Extension: .encrypt #In-dev/test ransomware
|
Vendetta
ransomware
|
#Sử dụng mã hóa RSA-5008 #Extensions: .vendetta & .vendetta2 #Note:
How to decrypt files.html
|
GandCrab
V5.0.5 Ransomware
|
|
|
Ghost
ransomware
|
#Extension: .Ghost #Email: [email protected]
|
|
010001
ransomware
|
#Extension: .010001 #note: tmpsfn_as.txt
|
25/10/2018
|
Blackout
ransomware
|
|
24/10/2018
|
Vanss
ransomware
|
#CrySiS/Dharma ransomware #Extension: .vanss #Email: [email protected]
#Notes: Info.hta & FILES ENCRYPTED.txt
|
GusCrypter
ransomware
|
|
|
DiskCryptor
Ransom
|
#MCrypt2018 Ransomware #Email: [email protected]
|
23/10/2018
|
Desktop
ransomware
|
|
21/10/2018
|
Kraken
Cryptor 2.0.7.1 beta ransomware
|
|
Kraken
Cryptor 2.0.7 ransomware
|
#Extension: .W0YR8!
|
Kraken
Cryptor 2.0.6 beta ransomware
|
|
HiddenBeer
ransomware
|
#Hidden Tear
|
20/10/2018
|
Kraken
Cryptor 2.0.6 ransomware
|
|
19/10/2018
|
Betta
ransomware
|
#CrySiS/Dharma ransomware (from Avast) #Extensions
.betta #Email: [email protected]
|
18/10/2018
|
Kraken
Cryptor 2.0.5 ransomware
|
#Researchers Editon: Zero Resistance #[email protected]
#[email protected]
|
17/10/2018
|
Birbware
ransomware
|
#Extension: .birbware
|
District
ransomware
|
#CtrlAlt ransomware #Extension:
[email protected] #Ransom Note: READ_IT.district
|
|
Ransom
HiddenTear
|
|
16/10/2018
|
Katyusha
Ransomware
|
#Extension: .katyusha #Email:
[email protected]
#BTC: 3ALmvAWLEothnMF5BjckAFaKB5S6zan9PK
|
13/10/2018
|
EbolaRnsmwr
ransomware
|
#Extension: .101 #Hidden Tear
|
12/10/2018
|
Minotaur
ransomware
|
|
Shade
ransomware
|
#Troldesh ransomware #Extension: .crypted 000007
|
12/10/2018
|
Kraken
Cryptor 2.0.4 ransomware
|
#kraken656kn6wyyx[.]onion
|
|
NanoCore
1.2.2.0 ransomware
|
|
|
GandCrab
V5.0.4 Ransomware
|
#Extension .LGAWPULM!
|
11/10/2018
|
Kraken
Cryptor 2.0 ransomware
|
|
RotorCrypt
Ransomware
|
#extension: !@#$%^&-()_+.1C #note: INFO.txt
#Email: [email protected]
|
10/10/2018
|
Junked
Scrabber ransomware
|
#Ext: .junked #Hidden Tear
|
GandCrab
V5.0.3 Ransomware
|
|
08/10/2018
|
Ransom
FileCoder
|
|
07/10/2018
|
A
Ranion 1.9 ransomware
|
|
05/10/2018
|
Ransomware
God Crypt
|
#Godsomware v1.0 #Unlock code:
29b579fb811f05c3c334a2bd2646a27a
|
Kraken
Cryptor 1.53
|
|
04/10/2018
|
Kraken
Cryptor 1.6 ransomware (2)
|
|
01/10/2018
|
GandCrab
V5.0.2 Ransomware
|
|
29/09/2018
|
GandCrab
V5.0.1 Ransomware
|
|
28/09/2018
|
FilesL0cker
RAN$OMWARE
|
#Chinese/English FilesLocker ransomware
#Extension: .locked #Notes: #DECRYPT MY FILES#.txt / #解密我的文件#.txt
|
27/09/2018
|
MBRLocker
ransomware
|
|
24/09/2018
|
Moware
ransomware
|
|
23/09/2018
|
GandCrab
V5.0 Ransomware
|
|
Kraken
Cryptor 1.52 ransomware
|
|
XD
ransomware
|
#Extension .xd
|
New
LockCrypt 2.0 Ransomware
|
#Extension .BDKR #Email contact:
[email protected]
|
22/09/2018
|
Qinynore
ransomware
|
#HiddenTear #Extension: .anonymous
|
Bytar
Ransomware
|
#In-dev ransomware
|
17/09/2018
|
Rektware
ransomware
|
#Extension: .CQScSFy
|
|
Why
Stop ransomware
|
#Extension:
.WHY #Ransom Note: !!!WHY__MY__FILES__NOT__OPEN!!!.txt #Email:
[email protected]
|
14/09/2018
|
Nog4yH4n
Project ransomware
|
#Extension:
.locked #Hidden Tear
|
11/09/2018
|
Mammon
Scarab ransomware
|
#Extension: .mammon #Scarab DiskDoctor
|
MPV
ransomware
|
#Extension: .mpv #Scarab
|
Kraken
Cryptor 1.5 ransomware
|
#Hacker đã tấn công vào website của SuperAntiSpyware
(https://www.SUPERAntiSpyware.com/downloads/superantispywares.exe) và tiêm
ransomware vào trình cài đặt.
|
09/09/2018
|
CrySiS/Dharma
ransomware
|
#Extension: [[email protected]].brrr #FILES ENCRYPTED.txt #Info.hta
|
CrySiS/Dharma
ransomware
|
#extension: .gamma (.id-%ID%.[[email protected]].gamma) #ransom notes:
FILES ENCRYPTED.txt
|
IT.Books
ransomware
|
#Hidden Tear #Extension: .fucked #Giao diện như
Jigsaw ransomware #Dropped note: READ__IT.txt
|
08/09/2018
|
Ransomware
5H311 1NJ3C706
|
#ScreenLocker #Unlock Code: 666HackerThn
|
|
Viro
Botnet ransomware
|
#Hidden Tear #Virobot
ransomware
|
07/09/2018
|
Wannabe
ransomware
|
|
Bandarchor
ransomware
|
#Extension: .id-%ID%-[[email protected]].pip
|
|
CryptoJoker
ransomware
|
#Extension: .cryptoloker
|
05/09/2018
|
Thanatos
ransomware
|
|
PICO
ransomware
|
|
02/09/2018
|
Locdoor
ransomware
|
#DryCry ransomware
|
01/09/2018
|
EOEO
ransomware
|
#Extension: .eoeo
|
Shiva
ransomware
|
#Extension: .good
|
30/08/2018
|
Combo
Crysis ransomware
|
#Extension: .COMBO
|
29/08/2018
|
ScreenLocker
|
#yêu cầu mở khóa 20$ khi email cho và làm theo
hướng dẫn email: [email protected]
|
LIGMA
ransomware
|
|
Opdailyallowance
ransomware
|
#Extension: .CRYPTR #HiddenTear
|
|
Ryuk
ransomware
|
|
28/08/2018
|
Termite
ransomware
|
|
Acroware
Cryptolocker ransomware
|
#ScreenLocker
|
KCTF
Locker ransomware
|
|
|
Acroware
Cryptolocker ransomware
|
#ScreenLocker #Không mã hóa dữ liệu
|
26/08/2018
|
CreamPie
ransomware
|
#Extension: [[email protected]].CreamPie
|
JeFf
thE rAnSOomwArE v1.0
|
#in-dev ransomware
|
25/08/2018
|
SaherBlueEagle
ransomware
|
|
HydraCrypt
ransomware
|
|
PyLocky
ransomware
|
|
Suri
ransomware
|
# Extension: .SLAV #Stupid ransomware #From Italy
|
24/08/2018
|
LockBox
Ransomware
|
#Polish Jigsaw Ransomware #Extension:
.#__EnCrYpTED_BY_dzikusssT3AM_ransomware!__#
|
|
EDA2
ransomware
|
#Extension: .hao17
|
23/08/2018
|
TotalWipeOut
ransomware
|
|
BadNews
LockCrypt ransomware
|
#Extension: .BadNews #Note: How To Decode
Files.hta
|
22/08/2018
|
KrakenCryptor
ransomware 1 2 3
|
Avast phát hiện nhiều biến thể của Kraken
ransomware mã hoá và đổi tên file
00000000-Lock.onion; 00000001-Lock.onion, 00000002-Lock.onion...
|
Obamaware
ransomware
|
|
|
CryptoNar
ransomware
|
#Có thể giải mã #Extensions: .fully.cryptoNar
/ .partially.cryptoNar #Note: CRYPTONAR RECOVERY INFORMATION.txt
|
20/08/2018
|
ONI
ransomware
|
#Extension: .ONI #Note: RESTORE_ONI_FILES.txt #Update 26/12/2018: Có
thể giải mã
|
17/08/2018
|
Divine
Everbe 2.0 ransomware
|
#Extension: .[<email>].divine #note:
!=How_to_decrypt_files=!.txt
|
16/08/2018
|
ShutUpAndDance
ransomware
|
#Hidden Tear #Extension: .ShutUpAndDance
|
Lime
ransomware
|
#Extension: .Lime
|
Crypt12
ransomware
|
#Extension: =<id>=<email>.crypt12
#Email: [email protected]
|
|
Kraken
Cryptor 1.2 ransomware
|
|
15/08/2018
|
SARansom
ransomware
|
|
Rapid
v1 ransomware
|
#Extension: no_more_ransom
|
14/08/2018
|
Wise
ransomware
|
#ransomware không mã hoá file nhưng xoá file.
|
Princess
Evolution ransomware
|
#Random extension: .K8VfiZ #Tor:
royal666k6zyxnai[.]onion #Note: (_H0W_TO_REC0VER_<added extension>.html
|
13/08/2018
|
Keypass
ransomware
|
#Extension: .KEYPASS
|
12/08/2018
|
MAFIA
ransomware
|
#Extension: .mafia #Update 19/08/2018: Có tool giải mã
|
11/08/2018
|
Golden
ransomware
|
|
10/08/2018
|
Blackout
ransomware
|
|
09/08/2018
|
Cryakl
v1.5.1 ransomware
|
#Extension: ".doubleoffset" #Email: [email protected]
|
08/08/2018
|
PTP
Ransomware
|
#HiddenTear #Extension: .PTPRansomware #From South
Korea
|
Retwyware ransomware
|
#Extension: .killrabbit
|
ZOLDON
Crypter V3.0 ransomware
|
|
07/08/2018
|
Putin
Lockware
|
#ScreenLocker #Unlock Code: Trong link
|
06/08/2018
|
AutoWannaCryV2
ransomware
|
|
Gandcrab
v4.4 ransomware
|
|
04/08/2018
|
Ranion
1.09 ransomware
|
|
|
PooleZoor
ransomware
|
#Extension: .poolezoor #Hidden Tear
|
03/08/2018
|
AutoIt
ransomware
|
#wannacryV2 #Extension: .wannacryv2 #Key for
decrypt: 123qwe
|
02/08/2018
|
GandCrab
V4.3 ransomware
|
|
GandCrab
V4.2.1 ransomware
|
|
01/08/2018
|
Invaded
Jigsaw ransomware
|
#Extension: .invaded
|
JobCrypter
Ransomware
|
#Extension: .css #Email: [email protected]
|
31/07/2018
|
Ann
Matrix ransomware
|
#Extension: .ANN #Email:[email protected]
#Giao diện tiền chuộc tiếng Pháp.
|
30/07/2018
|
Aurora
ransomware
|
#Animus ransomware #Extension: .desu ;#Email: [email protected] #Update
26/12/2018: Có thể giải mã
|
Aurora
ransomware
|
#Animus ransomware #Extension: .desu #Email:
[email protected] #Update 26/12/2018: Có thể
giải mã
|
PyLocky
ransomware
|
#Extension: .lockedfile #LOCKY-README.txt #Tor:
http://4wcgqlckaazugwzm.onion/index.php
|
29/07/2018
|
FoxRansom
|
#HiddenTear #extension: .fox #From Hungary
|
28/07/2018
|
Xlockr
ransomware
|
|
27/07/2018
|
Dcrt
Ransomware
|
#extension: .cryptes #Note: HOW TO DECRYPT ALL MY
FILES.txt
|
Paradise
Ransomware
|
#Extension: [id-<id>].[[email protected]].b29
|
26/07/2018
|
XiaoBa
2.0 ransomware
|
#note:HELP_SOS.hta #Extension:
.[[email protected]]Encrypted_(random id).XIAOBA #GlobeImposter 2.0
|
WannCrypt
V6 ransomware
|
#Không mã hoá file, Alt+F4 để đóng.
|
RackCrypt
Ransomware
|
#Email: [email protected] #BTC:
17Avc5GfDEzMeos71G2ftfpvfnvjkL2oo7
|
DDE
ransomware
|
#in-dev ransomware #extension .encrypted #Chỉ mã
hoá thư mục chứa file thực thi (tải xuống)
|
25/07/2018
|
SamSam
ransomware
|
#Extension: .weapologize
|
Liviu Dragnea
ransomware
|
#From Romania's ransomware #extension: .dragnea
#Phân tích mã có giao diện kiểu Jigsaw, nhưng thực ra đây là Stupid
ransomware.
|
Thunder
Everbe 2.0 ransomware
|
#Extension: .[[email protected]].thunder
|
RansomWarrior 1.0 ransomware
|
Update
31/08/2018 : Phát hành tool giải mã.
|
24/07/2018
|
Zip
Unlock92 ransomware
|
#Unlock92 Zipper #Extension:
<foldername>-<random>.zip
|
23/07/2018
|
Armage
ransomware
|
#Extension: .
armage
|
21/07/2018
|
Animus ransomware
|
#Extension: .desu #Email:
[email protected]
|
|
Accdfisa
ransomware
|
|
20/07/2018
|
Gandcrab
4.2 ransomware
|
|
Beep
Jigsaw ransomware
|
#Extension: .beep lol #Unlock Code:
QQlziAbDzrrWPjksTYoxYq
|
NSB
ransomware
|
#National Security Bureau Ransomware #VirLock
ransomware
|
19/07/2018
|
Proticc
Ransomware
|
#Extension: .lol
#Unlock Code:
Hyd12UGhhzZmvF7
|
LanRan
2 Ransomware
|
#extension .LanRan2.0.5
|
18/07/2018
|
TQV
ransomware
|
#in-dev ransomware #Vietnamese ransomware
#Extension: .TQV #
|
ransomware
|
|
yami
ransomware cat
|
|
16/07/2018
|
Yyto
ransomware
|
#Extension: [email protected]
|
13/07/2018
|
FireEye
ransomware
|
#BlackRansomwareFireeye #Extension: .jes
|
AndreaGalli
In-Dev ransomware
|
#Extension: .locked
|
Shrug2
ransomware
|
# Extension:
.SHRUG2
|
12/07/2018
|
XeroWare
ransomware
|
#XeroWare Ransom 1.2 #HiddenTear #Extension: .XERO
|
FBI
Locker
|
#Unlock Code: 290274887
|
11/07/2018
|
LockBitpaymer
ransomware
|
#Extension: .LOCK #Email:
[email protected]
|
FLKR
ransomware
|
#Extension: [email protected]
|
10/07/2018
|
Everbe
2.0 ransomware
|
#Extension: .[[email protected]].eV3rbe
|
Jewsomware
ransomware
|
#Extension: .jewsomware
|
FBI
Locker
|
#Unlock Code: 94238075
|
09/07/2018
|
Evil
Locker ransomware
|
#extension: .[[email protected]].EVIL
|
PoisonFang
ransomware
|
|
08/07/2018
|
CryptoLite
ransomware
|
#Extension: .encrypted #Decryption key: GuBlZEpxPFqDAtjNh7c6mKs4Iy9Mrfw2UYvn3ei5HTgaO1dCbz8QXLJk0RVoW
|
07/07/2018
|
Shrug
ransomware
|
|
ScreenLocker
|
#nRansom
#Email: [email protected] #Unlock Code: 1a2b3c
|
06/07/2018
|
Winlock
|
#Screenlocker
|
05/07/2018
|
Gandcrab
V4.1 ransomware
|
|
04/07/2018
|
NotAHero
ransomware
|
# KyMERA
#Extension: locked.zip #Email: [email protected]
|
03/07/2018
|
Choda
Jigsaw ransomware
|
#Extension: .choda
#Korea
|
OSX.Dummy
|
# Mac malware
|
02/07/2018
|
Gandcrab
V4 ransomware
|
Note: KRAB-DECRYPT.txt ; Extension: .KRAB
|
Rapid
v1 ransomware
|
#Extension: .RPD
|
Gollum
ransomware
|
|
RaRansomware
|
|
Winlock
|
|
01/07/2018
|
LanRan-2
ransomware
|
|
30/06/2018
|
BloodJaws
ransomware
|
|
Animus
ransomware
|
#Animus locker
|
CryptoGod
ransomware
|
#HiddenTear
|
29/06/2018
|
StalinLocker
|
#StalinkScreamer
|
28/06/2018
|
The
Brotherhood ransomware
|
# Extension: .ransomcrypt
#HiddenTear
|
27/06/2018
|
Whoopsie
ransomware
|
|
24/06/2018
|
ScreenLocker
|
# Mở
khoá: Z234-0113-522T-3UIOP
|
22/06/2018
|
KingOuroboros
ransomware
KingOuroboros
ransomware (unpack)
|
# filename<.king_ouroboros.>extension
#Email: [email protected]
|
21/06/2018
|
CryptConsole 3 ransomware
|
|
20/06/2018
|
HiddenTear
ransomware
|
#ScreenLocker #Gamelorf hacking tool
|
19/06/2018
|
CyberSPCP Dumb
ransomware
CyberSPCP Dumb
ransomware
|
|
18/06/2018
|
Boris
ransomware
Boris
ransomware
|
#
Extension: .boris #HiddenTear
#
Extension: [[email protected]].boris
|
17/06/2018
|
MBRDiskLocker
|
#Abantes trojan #HiddenTear
|
16/06/2018
|
FileIce
ransomware
|
#GoldFork ransomware # SreenLocker #In-dev ransomware -Có thể mở khoá
|
15/06/2018
|
RotoCrypt2
ransomware
|
#
Extension: !@#[email protected]_____$#@!.RAR
|
14/06/2018
|
DBGer
ransomware
|
#
image.png -- > [[email protected]]image.png.dbger
# Tác giả
của Satan ransomware đã đổi tên "sản phẩm" của họ thành DBGer
Ransomware sử dụng EternalBlue và
Mimikats để lan truyền qua mạng.
|
DiskDoctor
ransomware
|
#
Email: [email protected] #Scarab ransomware
|
|
Xorist-Frozen
ransomware
|
#
Extension: (xem trong link virustotal)
|
11/06/2018
|
RotoCrypt
ransomware
|
#Extension:
!@#$%[email protected]_____%$#@.mail
|
10/06/2018
|
Donut
ransomware
|
#Extension:
.donut; Email: [email protected]
|
Rsod
ransomware
|
#ScreenLocker
|
09/06/2018
|
Sunlocker ransomware
|
#
Extension: [email protected]; [email protected];
[email protected]
|
BabMonkey
ransomware
|
|
06/06/2018
|
RedEye
ransomware
|
#Extension:
.redeye. RedEye ransomware là một biến thể mới hoặc biến thể của cùng một tác
giả của Annabelle ransomware
|
|
Xiaoba
ransomware
|
#Beethoven
theme
|
05/06/2018
|
Pedcont
ransomware
|
|
XiaoBa
ransomware
|
#Extension:
.AdolfHitler; Note: # # DECRYPT MY FILE # #.bmp
|
04/06/2018
|
Encrypt
ransomware
|
#In-dev
ransomware
|
03/06/2018
|
CryBrazil
ransomware
|
#Extension:
.crybrazil; Note: SUA_CHAVE.html
|
|
Paradise
ransomware
|
# Extension: _V.0.0.0.1{[email protected]}.prt
Note:
[email protected]
|
01/06/2018
|
Cryptgh0st
Ransomware
|
|
31/05/2018
|
BitPaymer
ransomware
|
|
LockCrypt
2.0 ransomware
|
# Extension:<code> id-<ID>.BI_D</code> Email: [email protected]
|
Altracaz
ransomware
|
#Extension:
.Alcatraz ; BTC: 1CNpMj7DTH3gbJAPrQT2FZ4whqpYQvFrY8
|
MrDec
ransomware
|
# Extension:
[ID]<id>[ID]; Email: [email protected]; Email:
[email protected]
|
30/05/2018
|
Aurora
ransomware
|
#OneKeyLocker
|
Everbe
ransomware
|
#.[[email protected]].embrace
|
29/05/2018
|
PaintLocker
ransomware
|
# Biến thể
của Everbe ransomware
|
27/05/2018
|
OpsVenezuela ransomware
|
#HiddenTear
|
26/05/2018
|
LittleFinger
ransomware
|
#HiddenTear
#[email protected]
|
Jigsaw
ransomware
|
#Tusrkish
#.fun
|
CryptoMix
ransomware
|
#.BACKUP/Note:
_HELP_INSTRUCTION.TXT/ Contact emails: [email protected];
[email protected]; [email protected]; [email protected];
[email protected]; [email protected]
|
24/05/2018
|
Embrace
ransomware
|
|
Magician
ransomware
|
#Magician
RSWware
|
23/05/2018
|
Dont_Worry
ransomware
|
|
21/05/2018
|
Sigrun
1.0 ransomware
|
|
Anonymous
ransomware
|
#HiddenTear
#MrKarabs
|
Fox
ransomware
|
#In-dev
HiddenTear ransomware
|
20/05/2018
|
CryptConsole-2018
|
#Crypt
Console-Sequre
|
JosepCrypt
ransomware
|
|
|
Vietnamese
ransomware
|
#Phiên
bản mới, kết nối C&C server và xây dựng bảng điều khiển.
|
19/05/2018
|
Rapid
3.0 ransomware
|
|
17/05/2018
|
Everbe
ransomware
|
|
16/05/2018
|
Bip
Dharma ransomware
|
|
Horsuke
ransomware
|
|
15/05/2018
|
PGPSnippet
ransomware
|
|
14/05/2018
|
Sepsis
ransomware
|
|
StalinLocker
|
#StalinScreamer
|
13/05/2018
|
FBLocker
|
#Facebook
ransomware
|
12/05/2018
|
CryptON
ransomware
|
|
11/05/2018
|
GandCrab
V3.0.1 ransomware
|
|
10/05/2018
|
Matrix
MTXLOCK ransomware
|
|
07/05/2018
|
RansomAES
ransomware
|
#Korean
ransomware
|
06/05/2018
|
German
Stupid ransomware
|
#Screenlocker
- Có thể mở khoá
|
05/05/2018
|
ExoCrypt
XTC v2.0 ransomware
|
|
BKRansomware
|
#DataKeeper
ransomware #Vietnamese ransomware
Mã
hóa bằng ROT32, yêu cầu trả tiền chuộc bằng thẻ cào điện thoại
|
01/05/2018
|
GandCrab
V3 ransomware
|
|
UselessFiles
ransomware
|
|
30/04/2018
|
TSS
Screenlocker
|
#Tech
Support Scam
|
Kraken
2.0 ransomware
|
Có thể mở khoá
|
29/04/2018
|
Rar
ransomware
|
#Screenlocker
|
28/04/2018
|
Blackout
ransomware
|
|
27/04/2018
|
RandomLocker
ransomware
|
|
MauriGo
ransomware
|
#CryptGO
#Mauri870
|
26/04/2018
|
German
Stupid ransomware
|
#Screenlocker
- Có thể mở khoá
|
CryptConsole
ransomware
|
|
25/04/2018
|
HiddenTear(1)
ransomware
|
#Itad
Screenlocker - Có thể mở khoá
|
NRansome
Reborn ransomware
|
|
24/04/2018
|
Vietnamese
ransomware
|
#WannaCrypt
|
|
ANDRZEJ
DUPA ransomware
|
#HiddenTear
|
23/04/2018
|
GandCrab v2.1
ransomware
|
|
22/04/2018
|
DotZeroCMD
ransomware
|
#RansomDotZeroCMD
#Scareware
|
AutoN
ransomware
|
|
Krakatowis
ransomware
|
#Screenlocker
- Có thể mở khoá
|
21/04/2018
|
BlackHeart
ransomware
|
#BlackRouter
ransomware
|
|
Exocrypt
ransomware
|
#XTC
ransomware
|
|
GandCrab v2.2r
ransomware
|
|
20/04/2018
|
RansSIRIA
ransomware
|
#WannaPeace
ransomware
Ransomware
lợi dụng cuộc khủng hoảng người tị nạn Syria tuyên bố rằng nó sẽ quyên góp
tiền chuộc cho những người tị nạn Syria và nhắm mục tiêu các nạn nhân Brazil.
|
|
HiddenTear
Test2 ransomware
|
#In-dev
HiddenTear ransomware
|
19/04/2018
|
Satyr
ransomware
|
|
18/04/2018
|
Python
ransomware
|
#Meine
ransomware #PGP_DANGEROUS ransomware
|
MC
ransomware
|
|
CSGO
ransomware
|
|
17/04/2018
|
Apophis
ransomware
|
#Jigsaw
ransomware
|
16/04/2018
|
NMCRYPT
ransomware
|
#NM4
ransomware
|
15/04/2018
|
Spartacus
ransomware
|
|
Tron
ransomware
|
|
|
LMAOxUS
ransomware
|
#Extension:
.lmao; RansomNote: LMAO_READ_ME.txt; Email: [email protected]
|
13/04/2018
|
Cryptowire
ransomware
|
Có thể mở khoá
|
11/04/2018
|
Iron
ransomware
|
#Makatub ransomware
|
|
WhiteRose
ransomware
|
|
10/04/2018
|
PUBG
ransomware
|
|
RSA2048Pro
ransomware
|
|
|
Ransomware
demo
|
|
09/04/2018
|
FakeLocker
ransomware
|
#Screen Locker
|
|
DCRTR
ransomware
|
#in-dev ransomware
|
08/04/2018
|
Horros
ransomware
|
|
06/04/2018
|
LolSec
ransomware
|
#Jigaw ransomware - Có thể mở khoá
|
HiddenTear
Cyberresearcher ransomware
|
|
04/04/2018
|
Dont_Worry
ransomware
|
|
OXAR
ransomware
|
#HiddenTear
|
Satan
v2.1 ransomware
|
#SatanCryptor V2.1
|
HDDCryptor
ransomware
|
|
|
AutismLocker
ransomware
|
|
03/04/2018
|
ScorpionLocker
ransomware
|
#HiddenTear #H34rtBl33b
#HeartBleed
|
BlackRuby
Light ransomware
|
#BlackRuby
|
|
Crypren
ransomware
|
|
|
Vurten
ransomware
|
|
02/04/2018
|
WhiteRose
ransomware
|
|
TurkHackTeam
ransomware
|
|
01/04/2018
|
Matrix
ransomware
|
|
31/03/2018
|
Satan
ransomware
|
|
30/03/2018
|
RansomwareTest
ransomware
|
|
29/03/2018
|
Aira
ransomware
|
|
Cryakl
CL 1.5.1.0 ransomware
|
|
|
Sorry
ransomware
|
#HiddenTear
|
28/03/2018
|
Bansomqare
Wanna ransomware
|
Ransomware mới với Whatsapp
icon, nhưng giao diện giống Wannacry
|
GandCrab
1.2.5 ransomware
|
|
Mole66
ransomware
|
#CryptoMix
|
|
EggLocker
ransomware
|
|
26/03/2017
|
Haxerboi
ransomware
|
Mới: Malware kết hợp với
ransomware
|
MBR
bootlocker
|
#DiskWriter #UselessDisk
BootLocker
|
25/03/2018
|
AVCrypt
ransomware
|
AVCrypt ransomware cố gắng gỡ bỏ
cài đặt phần mềm bảo mật hiện có trên máy tính trước khi nó mã hóa máy tính.
|
JF
ransomware
|
#ScreenLocker - Có thể mở khoá
|
24/03/2018
|
Rapid
2.0 ransomware
|
|
23/03/2018
|
l0cked
ransomware
|
|
20/03/2018
|
Unlock92
ransomware
|
|
Ladon
ransomware
|
|
19/03/2018
|
Xorist-XWZ
Ransomware
|
|
Mrkv
ransomware
|
#HiddenTear
|
18/03/2018
|
Matrix
ransomware
|
|
17/03/2018
|
GandCrab
v2.0 ransomware
|
|
16/03/2018
|
Stinger
ransomware
|
|
15/03/2018
|
Zenis ransomware
|
Zenis ransomware không những mã
hóa dữ liệu mà còn tìm kiếm, ghi đè và xóa dữ liệu backup khiến cho việc phục
hồi trở nên khó khăn. Zenis ransomware
là biến thể của BlackRuby ransomware.
|
VBRansom
Ransomware
|
|
12/03/2018
|
PrincessLocker ransomware
|
|
RestoLocker ransomware
|
#HiddenTear
|
10/03/2018
|
GandCrab
v2.1r ransomware
|
|
09/03/2018
|
Ultimo ransomware
|
#HiddenTear
|
08/03/2018
|
FileIce ransomware
|
#SurveyLocker #Screenlocker
|
FRS ransomware
|
|
07/03/2018
|
PPGQwerty ransomware
|
|
Cryakl v1.5.1.0 ransomware
|
|
BlackRuby2 ransomware
|
|
|
GandCrab
v2.3r ransomware
|
|
06/03/2018
|
SilentSpring ransomware
|
|
GandCrab 2 v1.0.0r ransomware
|
Tác giả của GandCrab 2 đã xây
dựng cổng Raas với bảng điều khiển quản trị với các đối tác liên kết và sử
dụng ví thanh toán DASH.
|
04/03/2018
|
Jigsaw Bitconnect ransomware
|
# Jigsaw
|
02/03/2018
|
Data
Keeper ransomware
|
|
01/03/2018
|
Qwerty ransomware
|
|
28/02/2018
|
Kwaak ransomware
|
#HiddenTear
|
ScammerLocker ransomware
|
#HiddenTear
|
26/02/2018
|
CryptoBit ransomware
|
#Malasypt #Mobef #Salam
|
24/02/2018
|
XiaoBa ransomware
|
|
GandCrab v2.3.1r ransomware
|
|
23/02/2018
|
Ransomware sample
|
#HiddenTear
|
Baliluware ransomware
|
#HiddenTear
|
22/02/2018
|
WininiCrypt ransomware
|
|
21/02/2018
|
ByteLocker
|
|
DeadRansomware
|
#HiddenTear
|
Relec ransomware
|
Lây nhiễm nhưng không mã hóa.
|
20/02/2018
|
Annabella ransomware
|
Annabelle Ransomware với khả
năng vô hiệu hóa/qua mặt các chương trình bảo mật và mã hóa dữ liệu người
dùng.
Có thể mở khoá
|
19/02/2018
|
Russenger ransomware
|
|
18/02/2018
|
BananaCrypt ransomware
|
|
17/02/2018
|
In-dev ransomware
|
.ransomwared
|
Thanatos ransomware
|
|
FolderLocker
|
#WannaCrypt v22.01 - Có thể mở khoá
|
16/02/2018
|
Saturn ransomware
|
. Khi Saturn Ransomware được cài
đặt, nó sẽ kiểm tra nếu nó phát hiện rằng nó đang chạy dưới một máy ảo, nó sẽ
hủy toàn bộ quá trình lây nhiễm và tự hủy.
. Tác giả của Saturn Ransomware
cho phép bất cứ ai cũng có thể phân phối ransomware miễn phí thông qua chương
trình liên kết Ransomware-as-a-Service (RaaS) trên các trang Web đen.
|
Umaru ransomware
|
#Japanese ransomware (.干物妹!)
#DriedSister ransomware
|
15/02/2018
|
GlobeImposter ransomware
|
.suddentax
|
14/02/2018
|
Korean Jigsaw ransomware
|
Có thể mở khoá
|
13/02/2018
|
desuCrypt ransomware
|
#InsaneCrypt ransomware
|
12/02/2018
|
Defender ransomware
|
|
11/02/2018
|
TBLocker ransomware
|
|
10/02/2018
|
Blank ransomware
|
|
09/02/2018
|
ransomware
|
|
08/02/2018
|
Honor ransomware
|
|
Atom ransomware
|
|
DexCrypt MBRLocker ransomware
|
#DexLocker # China MBRLocker
|
07/02/2018
|
AdamLocker ransomware
|
|
BlackRuby ransomware
|
BlackRuby ransomware có thể được
cài đặt thông qua Remote Desktop Services, và truy vấn vào http://freegeoip.net/json/
và kiểm tra xem phản hồi chứa "country_code". Nếu trang web này chỉ
ra rằng người dùng đến từ Iran ( "country_code": "IR"),
quá trình sẽ chấm dứt và sẽ không thực hiện bất kỳ hoạt động độc hại nào trên
máy tính.
BlackRuby ransomware cũng sẽ cài
đặt một trình đào tiền ảo Monero (Monero miner) lên máy tính bị lấy nhiễm -
Monero miner chứa thuật toán sử dụng tài nguyên CPU càng nhiều càng tốt.
Có thể nói BlackRuby là biến thể
mới của WannaCry, tấn công vào máy tính
của người dùng, cài đặt phần mềm độc hại, mã hóa thiết bị và đào tiền ảo.
|
06/02/2018
|
RaRuCrypt ransomware
|
|
CryptoClone ransomware
|
#WannaCry V35
với hình nền WannaCry 2.0
|
05/02/2018
|
The_Last ransomware
|
#InfiniteTear ransomware V3
|
Hermes 2.1 ransomware
|
|
03/02/2018
|
Phobos
ransomware
|
|
02/02/2018
|
Tear Dr0p v1
|
#Hidden Tear #Cry more
|
30/01/2018
|
MindLost ransomware
|
|
Ranion 1.08 ransomware
|
#Hidden Tear #Trojan
|
26/01/2018
|
GandCrab ransomware
|
#ButtCrab ransomware
|
23/01/2018
|
DeusCrypt ransomware
|
Có thể mở khoá
|
InsaneCrypt ransomware
|
Có thể mở khoá
|
22/01/2018
|
RansomUserLocker ransomware
|
#Korean Talk 2016 ransomware
#Hidden Tear
|
Talk ransomware
|
#Korean Hidden Tear
|
Ghack ransomware
|
#in-dev ransomware
|
21/01/2018
|
KillBot Virus
|
#ScreenLocker
|
20/01/2017
|
Instalador ransomware
|
#in-dev ransomware
|
19/01/2018
|
Velso ransomware
|
|
Mada ransomware
|
#Jigsaw
|
17/01/2018
|
R3vo ransomware
|
#BigEyes
|
LitmeDecryptor ransomware
|
|
SuseRansom ransomware
|
#in-dev ransomware (Does not
encrypt)
|
Rancidware Screen Locker
|
#in-dev ransomware
|
16/01/2018
|
MoneroPay ransomware
|
#SpriteCoin ransomware
|
15/01/2016
|
KillDisk ransomware
|
#Dimens
|
11/01/2018
|
#Stealer ransomware
|
Ransomware mới mã hóa và đánh
cắp dữ liệu
|
D4CK3R ransomware
|
|
Death Note ransomware
|
|
Frog ransomware
|
|
LongTermMemoryLoss Ransomware
|
#LTML
|
CrypterWalker Dumb ransomware # Jigsaw
|
Có thể mở khoá
|
10/01/2018
|
LazagneCrypt ransomware
|
#BRC
|
CryptXXX ransomware
|
|
09/01/2018
|
NSFW ransomware
|
#Jigsaw
|
Tk ransomware
|
|
08/01/2018
|
KoreanLocker ransomware
|
#HiddenTear
|
|
Krypton ransomware
|
|
05/01/2018
|
Rapid ransomware
|
|
04/01/2018
|
Server Cryptomix ransomware
|
.
|
Turkish Globe ransomware
|
#Globe2
|
02/01/2018
|
Heropoint ransomware
|
#in-dev ransomware
|
MicroSoft ransomware
|
#MS ransomware
|
Unlckr ransomware
|
|
01/01/2018
|
Google Crypt ransomware
|
#in-dev ransomware
|
MINER.exe (Miner as Rootkit)
|
|
Syndown ransomware
|
|