Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
ShrinkLocker
Technical ID: win.shrinklocker
MALWARE
Malware family identifying win.shrinklocker. Origin and technical characteristics tracked via Malpedia.
ShortLeash
Technical ID: win.shortleash
MALWAREespionageadvanced
According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network. It generates unique, self-signed TLS certificates with spoofed metadata for each node. Analysis of these certificates revealed over 1000 active nodes globally and victimology supports attribution to China-Nexus APTs.
MALWAREespionageadvanced
SHIPSHAPE is malware developed by APT30 that allows propagation and exfiltration of data over removable devices. APT30 may use this capability to exfiltrate data across air-gaps.
MALWARE
Malware family identifying win.shimrat. Origin and technical characteristics tracked via Malpedia.
Shifu
Technical ID: win.shifu
MALWAREfinancialhigh
Shifu was originally discovered by Trusteer security researchers (Ilya Kolmanovich, Denis Laskov) in the middle of 2015. It is a banking trojan mostly focusing on Japanese banks and has rich features for remote data extraction and control.
Sheriff
Technical ID: win.sheriff
MALWARE
According to IBM X-Force, this is a modular backdoor that was used for targeting the defense sector of Ukraine. It uses the Dropbox API for C2 and data exfiltration.
ShellLocker
Technical ID: win.shelllocker
MALWAREfinancialhigh
PCRIsk states that ShellLocker is a ransomware-type virus developed using .NET framework. It was first discovered by Jakub Kroustek and is virtually identical to another ransomware virus called Exotic.
Following infiltration, this virus encrypts stored data (video, audio, etc.) and renames encrypted files using the "[random_characters].L0cked" pattern (e.g., "sample.jpg" might be renamed to "gd&=AA0fgoi.L0cked"). Following successful encryption, ShellLocker opens a pop-up window containing ransom-demand message.
ShellClient RAT
Technical ID: win.shellclient
MALWARE
Malware family identifying win.shellclient. Origin and technical characteristics tracked via Malpedia.
Also known as: GhostShell
SHEETCREEP
Technical ID: win.sheetcreep
MALWARE
According to Zscaler, SHEETCREEP is a lightweight backdoor written in C# that uses Google Sheets for C2 communication.
MALWAREfinancialhigh
Kaspersky Labs observed Andariel to drop this ransomware in one case within a series of attacks carried out against targets in South Korea in April 2021.
Also known as: Unidentified 081
SharpRhino
Technical ID: win.sharp_rhino
MALWARE
Malware family identifying win.sharp_rhino. Origin and technical characteristics tracked via Malpedia.
MALWARE
SharPyShell is a tiny and obfuscated ASP.NET webshell that executes commands received by an encrypted channel compiling them in memory at runtime.
SharPyShell supports only C# web applications that runs on .NET Framework >= 2.0
VB is not supported atm.
Also known as: ASPSHELL
SharpWMI
Technical ID: win.sharpwmi
MALWARE
According to its Github repository, SharpWMI is a C# implementation of various WMI functionality.
MALWARE
Malware family identifying win.sharpstats. Origin and technical characteristics tracked via Malpedia.
MALWARE
The SharpStage backdoor is a .NET malware with backdoor capabilities. Its name is a derivative of the main activity class called “Stage_One”. SharpStage can take screenshots, run arbitrary commands and downloads additional payloads. It exfiltrates data from the infected machine to a dropbox account by implementing a dropbox client in its code. SharpStage was seen used by the Molerats group in targeted attacks in the middle east.
Also known as: LastConn
SharpMapExec
Technical ID: win.sharpmapexec
MALWARE
This tool is made to simplify penetration testing of networks and to create a Swiss-army knife that is made for running on Windows which is often a requirement during insider threat simulation engagements.
MALWARE
Malware family identifying win.sharpknot. Origin and technical characteristics tracked via Malpedia.
Also known as: Bitrep
SharpHound
Technical ID: win.sharphound
MALWARE
According to its Github repository, SharpHound is a C# Data Collector for BloodHound.
SharpBeacon
Technical ID: win.sharpbeacon
MALWARE
.NET reimplementation of Cobalt Strike beacon/stager
Shark
Technical ID: win.shark
MALWARE
Malware family identifying win.shark. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.shareip. Origin and technical characteristics tracked via Malpedia.
Also known as: remotecmd
MALWARE
Malware family identifying win.shapeshift. Origin and technical characteristics tracked via Malpedia.
Shakti
Technical ID: win.shakti
MALWARE
Malware family identifying win.shakti. Origin and technical characteristics tracked via Malpedia.
ShadyHammock
Technical ID: win.shady_hammock
MALWARE
Malware family identifying win.shady_hammock. Origin and technical characteristics tracked via Malpedia.
Shadow RAT
Technical ID: win.shadow_rat
MALWARE
Malware family identifying win.shadow_rat. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.shadowpad. Origin and technical characteristics tracked via Malpedia.
Also known as: POISONPLUG.SHADOW • XShellGhost
MALWARE
Malware family identifying win.shadowhammer. Origin and technical characteristics tracked via Malpedia.
Also known as: DAYJOB
MALWARE
A malicious IIS module that allows up/download of files, remote command execution, and using the compromised server as a hop into the network behind.
MALWARE
ServHelper is written in Delphi and according to ProofPoint best classified as a backdoor.
ProofPoint noticed two distinct variant - "tunnel" and "downloader" (citation):
"The 'tunnel' variant has more features and focuses on setting up reverse SSH tunnels to allow the threat actor to access the infected host via Remote Desktop Protocol (RDP). Once ServHelper establishes remote desktop access, the malware contains functionality for the threat actor to 'hijack' legitimate user accounts or their web browser profiles and use them as they see fit. The 'downloader' variant is stripped of the tunneling and hijacking functionality and is used as a basic downloader."
Serpico
Technical ID: win.serpico
MALWARE
Malware family identifying win.serpico. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →Serpent Stealer
Technical ID: win.serpent
MALWARE
Malware family identifying win.serpent. Origin and technical characteristics tracked via Malpedia.
MALWARE
This malware is protected using VMProtect and related to the loading of KEYPLUG.
MALWARE
Malware family identifying win.sepulcher. Origin and technical characteristics tracked via Malpedia.
SendSafe
Technical ID: win.sendsafe
MALWARE
Malware family identifying win.sendsafe. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.selfmake. Origin and technical characteristics tracked via Malpedia.
Sekhmet
Technical ID: win.sekhmet
MALWAREfinancialhigh
According to PCrisk, Sekhmet is ransomware. This malicious program operates by encrypting data and demanding ransom payments for decryption. During the encryption process, all affected files are appended with an extension, consisting of random characters (e.g. ".HrUSsw", ".WNgh", ".NdWfEr", etc.).
seinup
Technical ID: win.seinup
MALWARE
Malware family identifying win.seinup. Origin and technical characteristics tracked via Malpedia.
MALWARE
simple tool to facilitate download and persistence of a next-stage tool; collects system information and metadata probably in an attempt to tell sandbox-environments apart from real targets on the server-side; uses domains of search engines like Google to check for Internet connectivity; XOR-based string obfuscation with a 16-byte key
Also known as: jhuhugit • jkeyskw • downrage • carberplike • GAMEFISH