|
|
|
|
RANSOMWARE |
EXTENSIÓN DE LOS ARCHIVOS ENCRIPTADOS |
|
.CryptoHasYou. |
.enc |
|
777
Sevleg |
.777 |
|
7ev3n
7ev3n-HONE$T |
.R4A
.R5A |
|
7h9r |
.7h9r |
|
8lock8
(basado en el
ransomware
HiddenTear) |
.8lock8 |
|
AiraCrop
(relacionado com TeamXRat) |
._AiraCropEncrypted |
|
Al-Namrood |
.unavailable
.disappeared |
|
Alcatraz Locker |
.Alcatraz |
|
ALFA Ransomware
(de los mismos creadores que
el ransomware
Cerber) |
.bin |
|
Alma Ransomware |
(aleatorio) |
|
Alpha Ransomware
AlphaLocker |
.encrypt |
|
Alphabet |
|
|
AMBA |
.amba |
|
Angela Merkel |
.angelamerkel |
|
AngleWare |
.AngleWare |
|
Angry Duck |
.adk |
|
Anony
(Basado en el
ransomware
HiddenTear
ngocanh) |
|
|
Anubis
(variante de EDA2) |
.coded |
|
Apocalypse
Fabiansomeware |
.encrypted
.SecureCrypted
.F_ _kYourData
.unavailable
.bleepYourFiles
.Where_my_files.txt |
|
ApocalypseVM |
.encrypted
.locked |
|
ASN1 |
|
|
AutoLocky |
.locky |
|
Aw3s0m3Sc0t7 |
.enc |
|
BadBlock |
|
|
BadEncript |
.bript |
|
BaksoCrypt
(basado en el ransomware my-Little-Ransomware) |
.adr |
|
Bandarchor
Rakhni |
.id-1235240425_help@ |
|
BarRax
(basado en el
ransomware
HiddenTear) |
.BarRax |
|
Bart
BaCrypt
(posible relación con RockLoader,
Locky y Dridex) |
.bart.zip
.bart
.perl |
|
BitCryptor
De la familia CryptoGraphic Locker Nueva variante del
ransomware CoinVault |
.clf |
|
BitPaymer (iEncrypt) |
.lock |
|
BitStak |
.bitstak |
|
BlackShades Crypter
SilentShade |
.Silent |
|
Blocatto
(basado en el ransomware
HiddenTear) |
.blocatto |
|
Booyah
Salam! |
|
|
Brazilian
(basado en EDA2) |
.lock |
|
Brazilian Globe |
|
|
BrLock |
|
|
Browlock |
|
|
BTCWare
(versión del ransomware
CryptXXX) |
.btcware |
|
Bucbi |
|
|
BuyUnlockCode |
|
|
Central Security Treatment Organization |
.cry |
|
|
Cerber |
.cerber
.cerber2
.cerber3 |
|
CerberTear |
|
|
Chimera |
.crypt
4 caracteres aleatorios, ej.: .PzZs, .MKJL |
|
CHIP |
.CHIP
.DALE |
|
Click Me Game |
|
|
Clock |
|
|
CloudSword |
|
|
Cockblocker |
.hannah |
|
CoinVault
(de la familia del ransomware CryptoGraphic Locker)
No confundir con CrypVault! |
.clf |
|
Coverton |
.coverton
.enigma
.czvxce |
|
Crptxxx |
.crptxxx |
|
Cryaki |
.{CRYPTENDBLACKDC} |
|
Crybola |
|
|
CryFile |
.criptiko
.criptoko
.criptokod
.cripttt
.aga |
|
CryLocker
Cry
CSTO
Central Security Treatment Organization
(identifica la localización de las víctimas con Google Maps) |
.cry |
|
CrypMIC
(clon del ransomware
CryptXXX) |
|
|
Crypren |
.ENCRYPTED |
|
Crypt38 |
.crypt38 |
|
CryptConsole |
(aleatorio) |
|
Cryptear
(Basado en
el ransomware Hidden Tear) |
|
|
Crypter |
|
|
CryptFIle2 |
.scl |
|
CryptInfinite |
.crinf |
|
CryptoBit
(no confundir con CryptorBit ) |
|
|
CryptoBlock |
|
|
CryptoDefense |
|
|
CryptoDevil |
.devil |
|
CryptoFinancial
Ranscam |
|
|
CryptoFortress
(imita al ransomware Torrentlocker) |
.frtrss |
|
CryptoGraphic Locker
Subvariantes: CoinVault
BitCryptor |
.clf |
|
CryptoHost
Manamecrypt
Telograph
ROI Locker |
|
|
CryptoJacky |
|
|
CryptoJoker |
.crjoker |
|
CryptoLocker |
.encrypted
.ENC |
|
CryptoLocker 1.0.0 |
|
|
CryptoLocker 5.1 |
|
|
CryptoLuck / YafunnLocker |
.[id_víctima]_luck |
|
CryptoMix
Zeta |
.code
.scl
.rmd
.lesli
.rdmk
.CRYPTOSHIELD
.CRYPTOSHIEL |
|
CryptON
Nemesis
X3M |
_crypt
.id-_locked
.id-_locked_by_krec
.id-_locked_by_perfect
.id-_x3m
.id-_r9oj
[email protected]
[email protected]_
[email protected]_
[email protected]_
[email protected]_
.id-_maria.lopez1@indi |
|
CryptoRansomeware |
|
|
Cryptorium |
.ENC |
|
CryptoRoger |
.crptrgr |
|
CryptoShadow |
.doomed |
|
CryptoShield
(variante del ransomware CryptoMix) |
.CRYPTOSHIELD |
|
CryptoShocker |
.locked |
|
CryptoTorLocker2015 |
.CryptoTorLocker2015! |
|
CryptoTrooper |
|
|
CryptoWall 1, 2, 3 y 4 |
.aaa
.locked |
|
|
|
|
CryptoWire |
|
|
CryptXXX
CryptProjectXXX |
.crypt |
|
CryptXXX 2.0
CryptProjectXXX |
.crypt |
|
CryptXXX 3.0
UltraDeCrypter
UltraCrypter |
.crypt
.cryp1
.crypz
.cryptz
random |
|
CryptXXX 3.1 |
.cryp1 |
|
CryPy |
.cry |
|
CTB-Faker |
|
|
CTB-Locker
Citroni |
.ctbl |
|
CTB-Locker WEB |
|
|
CuteRansomware
my-Little-Ransomware |
.已加密
.encrypted |
|
Cyber SpLiTTer Vbs
CyberSplitter
(basado en el
ransomware HiddenTear) |
|
|
Damage |
.damage |
|
Dharma
(variante del ransomware CrySiS) |
.dharma
.wallet
.zzzzz
.cezar
.adobe |
|
Deadly for a Good Purpose |
|
|
Death Bitches |
.locked |
|
DeCrypt Protect |
.html |
|
DEDCryptor
(basado on EDA2) |
.ded |
|
Demo
(solo encripta archivos .jpg) |
.encrypted |
|
Depsex
MafiaWare
(basado en el
ransomware HiddenTear) |
.Locked-by-Mafia |
|
DeriaLock |
.deria |
|
DetoxCrypto
Calipso
We are all Pokemons
Nullbyte |
|
|
Digisom |
|
|
DirtyDecrypt |
|
|
DMALocker |
|
|
DMALocker 3.0 |
|
|
DNRansomware |
.f_ _ked |
|
Domino
(basado en el ransomware
Hidden Tear) |
.domino |
|
Donald Trump |
.ENCRYPTED |
|
DoNotChange |
.id-7ES642406.cry
.Do_not_change_the_filename |
|
DummyLocker |
.dCrypt |
|
DXXD |
.dxxd |
|
DynA-Crypt |
.crypt |
|
EDA2 / HiddenTear
Cryptear |
.locked |
|
EdgeLocker |
.edgel |
|
EduCrypt
EduCrypter
(basado en el ransomware
Hidden Tear) |
.isis
.locked |
|
EiTest |
.crypted |
|
El-Polocker
Los Pollos Hermanos |
.ha3 |
|
Encoder.xxxx |
|
|
encryptoJJS |
.enc |
|
Enigma |
.enigma
.1txt |
|
Enjey |
|
|
EnkripsiPC
IDRANSOMv3
Manifestus |
.f_ _ked |
|
Erebus |
|
|
Evil |
.file0locked
.evillock |
|
Exotic |
.exotic |
|
FabSysCrypto
(basado en el ransomware
HiddenTear) |
|
|
Fadesoft |
|
|
Fairware |
|
|
Fakben
(basado en el
ransomware
HiddenTear) |
.locked |
|
FakeGlobe aka
GlobeImposter |
.crypt |
|
FakeCryptoLocker |
.cryptolocker |
|
Fantom
(basado en EDA2)
Variantes:
Comrade, Circle |
.fantom
.comrade |
|
FenixLocker |
.FenixIloveyou!! |
|
FILE FROZR |
|
|
FileLocker |
.ENCR |
|
FireCrypt |
.firecrypt |
|
Flyper
(basado en EDA2 / HiddenTear) |
.locked |
|
Fonco |
|
|
FortuneCookie |
|
|
Free-Freedom
Roga |
.madebyadam |
|
FSociety
(basado en EDA2 y el ransomware
RemindMe) |
.fs0ciety
.dll |
|
Fury |
|
|
GandCrab |
[extensiones aleatorias] |
|
GhostCrypt
(basado en el ransomware
Hidden Tear) |
.Z81928819 |
|
Gingerbread |
|
|
Globe v1
Purge |
.purge |
|
Globe v2
Purge |
.lovewindows
[email protected] |
|
Globe v3
Purge |
.[aleatorio].blt
.[aleatorio].encrypted
.[aleatorio].raid10
.[[email protected]]
.[aleatorio].globe
[email protected]
[email protected]
.locked
.decrypt2017
.hnumkhotep |
|
GNL Locker
Variantes:
Zyklon Locker
WildFire locker
Hades Locker |
.locked |
|
GOG |
.L0CKED |
|
Gomasom |
.crypt |
|
Goopic |
|
|
Gopher |
|
|
Gremit |
.rnsmwr |
|
Guster |
.locked |
|
Hacked
(variante del ransomware
Jigsaw) |
.versiegelt
.encrypted
.payrmts
.locked
.Locked |
|
HappyDayzz |
|
|
Harasom |
.html |
|
HDDCryptor
Mamba |
|
|
Heimdall |
|
|
Help_dcfile |
.XXX |
|
Herbst |
.herbst |
|
Hermes |
|
|
Hi Buddy!
(basado en el
ransomware
HiddenTear) |
.cry |
|
Hitler
(borra los archivos) |
|
|
HolyCrypt |
(encrypted) |
|
HTCryptor
(incluye una función para desactivar el cortafuegos de Windows
de la víctima.
Variante de HiddenTear) |
|
|
Hucky
(basado en el
ransomware
Locky) |
.locky |
|
HydraCrypt
(de la familia del
ransomware CrypBoss) |
|
|
IFN643 |
|
|
iLock |
.crime |
|
iLockLight |
.crime |
|
International Police Association
(variante del ransomware CryptoTorLocker2015) |
|
|
iRansom |
.Locked |
|
Jack.Pot |
|
|
JagerDecryptor |
!ENC |
|
JapanLocker
shc Ransomware
SyNcryption |
|
|
Jeiphoos
Encryptor RaaS
Sarento |
|
|
Jhon Woddy |
.killedXXX |
|
Jigsaw
CryptoHitMan (subvariante) |
.btc
.kkk
.fun
.gws
.porno
.payransom
.payms
.paymst
.AFD
.paybtcs
.epic
.xyz
.encrypted
.hush
.paytounlock
[email protected]
.gefickt
.nemo-hacks.at.sigaint.org |
|
Job Crypter
(basado en el
ransomware
HiddenTear, pero utiliza triple cifrado) |
.locked
.css |
|
JohnyCryptor |
|
|
Kaandsona
Käändsõna
RansomTroll |
.kencf |
|
Kangaroo
(del mismo desarrollador tras los ransomwares Apocalypse,
Fabiansomware y Esmeralda) |
.crypted_file |
|
Karma
(simula ser un programa de optimización de Windows llamado
Windows-TuneUp) |
.karma |
|
Karmen
(basado en el
ransomware
HiddenTear) |
.grt |
|
Kasiski |
[KASISKI] |
|
KawaiiLocker |
|
|
KeRanger |
.encrypted |
|
KeyBTC |
keybtc@inbox_com |
|
KEYHolder
(a través de un atacante remoto) |
|
|
KillDisk |
|
|
KillerLocker
(posible desarrollador portugués) |
.rip |
|
KimcilWare
(solo ataca a páginas web) |
.kimcilware
.locked |
|
Kirk |
.Kirked |
|
Koolova
(con texto en italiano) |
|
|
Korean
(basado en el
ransomware
HiddenTear) |
.암호화됨 |
|
Kostya |
.kostya |
|
Kozy.Jozy
QC |
.31392E30362E323031 |
|
Kraken |
.kraken |
|
KratosCrypt |
.kratos |
|
KRider |
.kr3 |
|
KryptoLocker
(basado en el
ransomware
HiddenTear) |
|
|
LambdaLocker
(ransowmare en Python) |
.lambda_l0cked |
|
LanRan
(variante del ransomware MyLittleRansomware) |
|
|
LeChiffre
(a través de un atacante remoto) |
.LeChiffre |
|
Lick
(variante de Kirk) |
.Licked |
|
Linux.Encoder
Linux.Encoder.{0,3}
(ransomware para Linux) |
|
|
LK Encryption
(basado en el
ransomware
HiddenTear) |
|
|
LLTP Locker
(dirigido a víctimas de habla hispana) |
.ENCRYPTED_BY_LLTP
.ENCRYPTED_BY_LLTPp |
|
LockBox |
@keemail.me.sg1e |
|
LockCrypt |
.lock |
|
Locked-In
(basado en el
ransomware
RemindMe) |
|
|
Locker
(no cambia las extensiones) |
|
|
LockLock |
.locklock |
|
Locky
(variantes Diablo6 y Lukitus )
(relacionado con las botnets Dridex y Necurs) |
.locky
.zepto
.odin
.shit
.thor
.aesir
.zzzzz
.osiris
.DIABLO6
.lukitus |
|
Lock93 |
.lock93 |
|
Lomix
(basado en el
ransomware
CryptoWire) |
|
|
Lortok |
.crime |
|
LowLevel04 |
oor. |
|
M4N1F3STO
(no encripta archivos, solo bloquea el ordenador) |
|
|
Mabouia |
|
|
MacAndChess
(basado en el ransomware
HiddenTear) |
|
|
Magic
(basado en EDA2) |
.magic |
|
MaktubLocker |
|
|
Marlboro |
.oops |
|
MarsJoke |
.a19
.ap19 |
|
MasterBuster |
|
|
Matrix
(utiliza GnuPG) |
|
|
Meister
(se dirige a víctimas francesas) |
|
|
Merry X-Mas!
MRCR
(escrito en Delphi) |
.PEGS1
.MRCR1
.RARE1
.MERRY
.RMCM1 |
|
Meteoritan |
|
|
MIRCOP
Crypt888 |
Lock. |
|
MireWare
(basado en el
ransomware
HiddenTear) |
.fu_ _ed
.f_ _k |
|
Mischa
("hermano pequeño" del
ransomware
Petya) |
|
|
MM Locker
Booyah
(basado en EDA2) |
.locked |
|
Mobef
Yakes
CryptoBit |
.KEYZ
.KEYH0LES |
|
Mole
CryptoMix |
.mole
.mole02 |
|
Monument
(variante del
ransomware
Jigsaw) |
|
|
MOTD |
.enc |
|
MSN CryptoLocker |
|
|
n1n1n1 |
|
|
N-Splitter
(variante ruso del
ransomware Koolova) |
.кибер разветвитель |
|
Nagini |
|
|
NanoLocker
(no cambia las extensiones)
(tiene interfaz gráfica de usuario) |
|
|
Nasoh (de la familia Djvu) |
.nasoh |
|
Nemucod
(variante del
ransomware 7zip (a0.exe)) |
.crypted |
|
Netix
RANSOM_NETIX.A |
|
|
Nhtnwcuf
(no encripta los archivos, sino que los destruye) |
|
|
NMoreira
XRatTeam
XPan
AiraCrop |
.maktub
.__AiraCropEncrypted!
.aac |
|
NoobCrypt |
|
|
Nuke |
.nuclear55 |
|
Nullbyte |
_nullbyte |
|
Ocelot |
|
|
ODCODC |
.odcodc |
|
Offline ransomware
Vipasana
Cryakl |
.cbf |
|
OMG! Ransomware
GPCode |
.LOL!
.OMG! |
|
Onyx
(ransomware georgiano) |
|
|
Operation Global III |
.EXE |
|
Owl
CryptoWire |
dummy_file.encrypted |
|
OzozaLocker |
.Locked |
|
PadCrypt
(tiene un chat de soporte) |
.padcrypt |
|
Padlock Screenlocker |
|
|
Patcher
(se dirige a usuarios de macOS) |
.crypt |
|
PayDay
(basado en el
ransomware
Hidden-Tear) |
.sexy |
|
PayDOS
Serpent |
|
|
Paysafecard Generator 2016 |
.cry_ |
|
PClock
WinPlock
(clon del ransomware
CryptoLocker) |
|
|
PetrWrap |
|
|
Petya
Goldeneye
(sobrescribe el Registro de Arranque;
encripta la Tabla Maestra de Archivos) |
|
|
Philadelphia |
.locked |
|
Phoenix
(basado en el
ransomware
HiddenTear) |
.R.i.P |
|
Pickles
(ransomware en
Python ) |
.EnCrYpTeD |
|
PizzaCrypts |
.id-[id_víctima][email protected] |
|
PokemonGO
(basado en el ransomware HiddenTear) |
.locked |
|
Popcorn Time |
.filock |
|
Polyglot
(imita al ransomware CTB-Locker) |
|
|
Potato |
.potato |
|
PowerWare
PoshCoder |
.locky |
|
PowerWorm |
|
|
Princess Locker |
|
|
PRISM |
|
|
Project34 |
|
|
ProposalCrypt |
.crypted |
|
Ps2exe |
|
|
PyL33T
(ransomware
en Python)
|
.d4nk |
|
R |
|
|
R980 |
.crypt |
|
RAA encryptor
RAA
(posible relación con el ransomware Pony) |
.locked |
|
Rabion
(copia de Ranion RaaS) |
|
|
Radamant |
.RDM
.RRK
.RAD
.RADAMANT |
|
Rakhni
Agent.iih
Aura
Autoit
Pletor
Rotor
Lamer
Isda
Cryptokluchen
Bandarchor |
.locked
.kraken
.darkness
.nochance
.oshit
.oplata@qq_com
.relock@qq_com
.crypto
[email protected]
.pizda@qq_com
.dyatel@qq_com
_ryp
.nalog@qq_com
.chifrator@qq_com
.gruzin@qq_com
.troyancoder@qq_com
.encrypted
.cry
.AES256
.enc
.hb15 |
|
Ramsomeer
(basado en el ransomware DUMB) |
|
|
Ranion |
|
|
Rannoh |
|
|
RanRan |
.zXz |
|
Ransoc |
|
|
Ransom32
(no cambia las extensiones, ransomware en Javascript) |
|
|
RansomLock
(bloquea el Escritorio) |
|
|
RansomPlus |
.encrypted |
|
Rapid |
.Rapid
.RPD
.EZYMN |
|
RarVault |
|
|
Razy |
.razy
.fear |
|
Rector |
.vscrypt
.infected
.bloc
.korrektor |
|
Red Alert
(basado en el ransomware Hidden Tear) |
|
|
RektLocker |
.rekt |
|
RemindMe |
.remind
.crashed |
|
Revenge
(variante del ransomware CryptoMix / CryptFile2) |
.REVENGE |
|
Rokku
(posiblemente relacionado con Chimera) |
.rokku |
|
RoshaLock
(guarda los archivos en una carpeta RAR comprimida con
contraseña) |
|
|
RotorCrypt
Rotor
Ransom.FileCryptor
Trojan-Ransom.Win32.Rotor.b
Win32/DH{gVIDgQ5+gUaBDw?} |
.SPG
.PGP
.tar
.c400
.c300
.crypto
.mail
.psd
.RAR |
|
RozaLocker |
.ENC |
|
Runsomewere
(basado en HT/EDA2)
(utiliza el bondo de
Jigsaw) |
|
|
RussianRoulette
(variante del ransomware Philadelphia) |
|
|
Ryuk
(similar a Hermes) |
.RYK
.rcrypted |
|
SADStory
(variante del ransomware CryPy) |
|
|
Sage 2.0
(predecesor del ransomware CryLocker) |
.sage |
|
Sage 2.2 |
.sage |
|
Samas-Samsam
(ataques dirigidos) |
.encryptedAES
.encryptedRSA
.encedRSA
.justbtcwillhelpyou
.btcbtcbtc
.btc-help-you
.only-we_can-help_you
.iwanthelpuuu
.notfoundrans
.encmywork
.VforVendetta
.theworldisyours
.Whereisyourfiles
.helpmeencedfiles
.powerfulldecrypt
.noproblemwedecfiles
.weareyourfriends
.otherinformation
.letmetrydecfiles
.encryptedyourfiles
.weencedufiles
.iaufkakfhsaraf
.cifgksaffsfyghd |
|
Sanction
(basado en el ransomware HiddenTear, pero con la clave
fuertemente modificada) |
.sanction |
|
Sanctions |
.wallet |
|
Sardoninir |
.enc |
|
Satan |
.stn |
|
Satana |
[email protected]___ |
|
Saturn |
|
|
Scarab |
.scarab
.danger |
|
Scraper
(no modifica las extensiones) |
|
|
SerbRansom |
.velikasrbija |
|
Serpent
PayDOS |
.serpent |
|
Serpico
(variante del ransomware DetoxCrypto) |
|
|
Shark
Atom |
.locked |
|
ShellLocker |
.L0cked |
|
ShinoLocker |
.shino |
|
Shujin
KinCrypt |
|
|
Simple_Encoder |
.~ |
|
SkidLocker / Pompous
(basado en EDA2) |
.locked |
|
SkyName
(basado en el ransomware HiddenTear) |
|
|
Smash! |
|
|
Smrss32 |
.encrypted |
|
SNSLocker
(basado en EDA2) |
.RSNSlocked
.RSplited |
|
Sport |
.sport |
|
Stampado
(borra aleatoriamente un archivo cada 6 horas hasta las 96 horas
y luego elimina la clave de descifrado) |
.locked |
|
Strictor
(basado en EDA2, muestra la máscara de Anonymous) |
.locked |
|
Surprise
(basado en EDA2) |
.surprise
.tzu |
|
Spora |
|
|
Survey |
|
|
SynoLocker
(explota vulnerabilidad de
NAS Synology) |
|
|
SZFLocker |
.szf |
|
TeamXrat |
.___xratteamLucked |
|
TeleCrypt |
.xcri |
|
TeslaCrypt 0.x - 2.2.0 |
.vvv
.ecc
.exx
.ezz
.abc
.aaa
.zzz
.xyz |
|
TeslaCrypt 3.0+ |
.micro
.xxx
.ttt
.mp3 |
|
TeslaCrypt 4.1A |
|
|
TeslaCrypt 4.2 |
|
|
Thanksgiving |
|
|
Threat Finder
(tiene interfaz gráfica de usuario) |
|
|
TorrentLocker
Crypt0L0cker
CryptoFortress
Teerac |
.Encrypted
.enc |
|
TowerWeb |
|
|
Toxcrypt |
.toxcrypt |
|
Trojan |
.braincrypt |
|
Troldesh
Shade
XTBL
(puede descargar malware adicional tras el cifrado) |
.breaking_bad
.better_call_saul
.xtbl
.da_vinci_code
.windows10
.no_more_ransom |
|
TrueCrypter |
.enc |
|
Trump Locker |
.TheTrumpLockerf
.TheTrumpLockerfp |
|
Turkish |
.sifreli |
|
Turkish (copia falsa del ransomware CTB-Locker) |
.encrypted |
|
Turkish Ransom |
.locked |
|
UltraLocker
(basado en el ransomware CryptoWire) |
|
|
UmbreCrypt
(de la familia del ransomware CrypBoss) |
|
|
UnblockUPC |
|
|
Ungluk |
.H3LL
.0x0
.1999 |
|
Unlock26 |
.locked-[XXX] |
|
Unlock92 |
.CRRRT
.CCCRRRPPP |
|
Vanguard
(ransomware GO) |
|
|
VapeLauncher
(variante del ransomware CryptoWire) |
|
|
VaultCrypt |
.vault
.xort
.trun |
|
VBRANSOM 7 |
.VBRANSOM |
|
VenisRansomware |
|
|
VenusLocker
(basado en EDA2) |
.Venusf
.Venusp |
|
Vindows Locker |
.vindows |
|
Virlock
(se autorreplica) |
.exe |
|
Virus-Encoder
CrySiS |
.CrySiS
.xtbl
.crypt
.DHARMA |
|
Vortex
(ransomware Ŧl๏tєгค) |
.aes |
|
vxLock |
.vxLock |
|
WannaCry
WannaCrypt
WCry |
.wcry
.wncry
.WNCRY
.WCRY |
|
WildFire Locker
Hades Locker
(variante del ransomware Zyklon) |
.wflx |
|
Winnix Cryptor
(utiliza GPG) |
.wnx |
|
XCrypt |
|
|
XData |
.~xdata~ |
|
Xorist |
.EnCiPhErEd
.73i87A
.p5tkjw
.PoAr2w
.fileiscryptedhard
.encoderpass
.zc3791
.antihacker2017 |
|
XRTN
(de la familia del ransomware VaultCrypt) |
.xrtn |
|
XYZWare
(basado en el ransomware HiddenTear) |
|
|
You Have Been Hacked!!!
(intenta robar las contraseñas) |
.Locked |
|
YourRansom |
.yourransom |
|
Zcrypt
Zcryptor |
.zcrypt |
|
Zeppelin (similitudes con VegaLocker)
|
|
|
Zeta
CryptoMix |
.code
.scl
.rmd |
|
Zimbra |
.crypto |
|
ZinoCrypt |
.ZINO |
|
Zlader / Russian
VaultCrypt
CrypVault |
.vault |
|
Zorro |
.zorro |
|
zScreenLocker |
|
|
Zyka |
.locked |
|
Zyklon
GNL Locker
(de la familia del ransomware Hidden Tear family, variante del
ransomware GNL Locker) |
.zyklon |
|
|
|