diff --git a/lookups/ransomware_extensions.csv b/lookups/ransomware_extensions.csv deleted file mode 100644 index 145fea7a9f..0000000000 --- a/lookups/ransomware_extensions.csv +++ /dev/null @@ -1,303 +0,0 @@ -Extensions,Name -.enc,.CryptoHasYou. -.777,777 -.R4A,7ev3n -.R5A,7ev3n -.7h9r,7h9r -.8lock8,8lock8 -.encrypt,Alpha Ransomware -.amba,AMBA -.adk,Angry Duck -.encrypted,Apocalypse -.SecureCrypted,Apocalypse -.FuckYourData,Apocalypse -.unavailable,Apocalypse -.bleepYourFiles,Apocalypse -.Where_my_files.txt,Apocalypse -.encrypted,ApocalypseVM -.locked,ApocalypseVM -.locky,AutoLocky -.adr,BaksoCrypt -.avos,AvosLocker -.avos2,AvosLocker -.avoslinux,AvosLocker -.bart.zip,Bart -.bart,Bart -.perl,Bart -.clf,BitCryptor -.bitstak,BitStak -.Silent,BlackShades Crypter -.blocatto,Blocatto -.cry,Central Security Treatment Organization -.cerber,Cerber -.cerber2,Cerber -.cerber3,Cerber -.clf,CoinVault -.coverton,Coverton -.enigma,Coverton -.czvxce,Coverton -.criptiko,CryFile -.criptoko,CryFile -.criptokod,CryFile -.cripttt,CryFile -.aga,CryFile -.cry,CryLocker -.ENCRYPTED,Crypren -.crypt38,Crypt38 -.scl,CryptFIle2 -.crinf,CryptInfinite -.frtrss,CryptoFortress -.clf,CryptoGraphic Locker -.crjoker,CryptoJoker -.encrypted ,CryptoLocker -.ENC,CryptoLocker -.code,CryptoMix -.scl,CryptoMix -.crptrgr,CryptoRoger -.locked,CryptoShocker -.CryptoTorLocker2015!,CryptoTorLocker2015 -.crypt,CryptXXX -.crypt,CryptXXX 2.0 -.crypt,CryptXXX 3.0 -.cryp1,CryptXXX 3.0 -.crypz,CryptXXX 3.0 -.cryptz,CryptXXX 3.0 -.cryp1,CryptXXX 3.1 -.ctbl,CTB-Locker -.encrypted,CuteRansomware -.ded,DEDCryptor -.domino,Domino -.locked,EDA2 / HiddenTear -.isis,EduCrypt -.locked,EduCrypt -.ha3,El-Polocker -.enigma,Enigma -.1txt,Enigma -.exotic,Exotic -.locked,Fakben -.fantom,Fantom -.Z81928819,GhostCrypt -.purge,Globe v1 -.globe,Globe v3 -.locked,GNL Locker -.crypt,Gomasom -.herbst,Herbst -.cry,Hi Buddy! -.locky,Hucky -.crime,iLock -.crime,iLockLight -.btc,Jigsaw -.kkk,Jigsaw -.fun,Jigsaw -.gws,Jigsaw -.porno,Jigsaw -.payransom,Jigsaw -.payms,Jigsaw -.paymst,Jigsaw -.AFD,Jigsaw -.paybtcs,Jigsaw -.epic,Jigsaw -.xyz,Jigsaw -.locked,Job Crypter -.encrypted,KeRanger -.keybtc@inbox_com,KeyBTC -.rip,Killer Locker -.kimcilware,KimcilWare -.locked,KimcilWare -.kostya,Kostya -.kratos,KratosCrypt -.LeChiffre,LeChiffre -.locky,Locky -.zepto,Locky -.odin,Locky -.shit,Locky -.thor,Locky -.asier,Locky -.zzzzz,Locky -.osiris,Locky -.lock93,Lock93 -.crime,Lortok -.oor,LowLevel04 -.magic,Magic -.Lock,MIRCOP -.fucked,MireWare -.fuck,MireWare -.locked,MM Locker -.KEYZ,Mobef -.KEYH0LES,Mobef -.crypted,Nemucod -.odcodc,ODCODC -.cbf,Offline ransomware -.LOL!,OMG! Ransomware -.OMG!,OMG! Ransomware -.padcrypt,PadCrypt -.locked,Philadelphia -.locked,PokemonGO -.filock,Popcorn Time -.locky,PowerWare -.crypt,R980 -.locked,RAA encryptor -.RDM,Radamant -.RRK,Radamant -.RAD,Radamant -.RADAMANT,Radamant -.locked,Rakhni -.kraken,Rakhni -.darkness,Rakhni -.nochance,Rakhni -.oshit,Rakhni -.oplata@qq_com,Rakhni -.relock@qq_com,Rakhni -.crypto,Rakhni -.helpdecrypt@ukr.net,Rakhni -.pizda@qq_com,Rakhni -.dyatel@qq_com,Rakhni -._ryp,Rakhni -.nalog@qq_com,Rakhni -.chifrator@qq_com,Rakhni -.gruzin@qq_com,Rakhni -.troyancoder@qq_com,Rakhni -.encrypted,Rakhni -.cry,Rakhni -.AES256,Rakhni -.enc,Rakhni -.hb15,Rakhni -.vscrypt,Rector -.infected,Rector -.bloc,Rector -.korrektor,Rector -.rekt,RektLocker -.remind,RemindMe -.crashed,RemindMe -.rokku,Rokku -.encryptedAES,Samas-Samsam -.encryptedRSA,Samas-Samsam -.encedRSA,Samas-Samsam -.justbtcwillhelpyou,Samas-Samsam -.btcbtcbtc,Samas-Samsam -.btc-help-you,Samas-Samsam -.only-we_can-help_you,Samas-Samsam -.iwanthelpuuu,Samas-Samsam -.notfoundrans,Samas-Samsam -.encmywork,Samas-Samsam -.weapologize,Samas-Samsam -.stubbin,Samas-Samsam -.areyoulovemyrans,Samas-Samsam -.loveransisgood,Samas-Samsam -.myransext2017,Samas-Samsam -.disposed2017,Samas-Samsam -.prosperous666,Samas-Samsam -.supported2017,Samas-Samsam -.country82000,Samas-Samsam -.moments2900,Samas-Samsam -.breeding123,Samas-Samsam -.mention9823,Samas-Samsam -.suppose666,Samas-Samsam -.skjdthghh,Samas-Samsam -.cifgksaffsfyghd,Samas-Samsam -.iaufkakfhsaraf,Samas-Samsam -.filegofprencrp,Samas-Samsam -.weencedufiles,Samas-Samsam -.encryptedyourfiles,Samas-Samsam -.letmetrydecfiles,Samas-Samsam -.otherinformation,Samas-Samsam -.weareyourfriends,Samas-Samsam -.noproblemwedecfiles,Samas-Samsam -.powerfulldecrypt,Samas-Samsam -.wowreadfordecryp,Samas-Samsam -.wowwhereismyfiles,Samas-Samsam -.helpmeencedfiles,Samas-Samsam -.theworldisyours,Samas-Samsam -.vekanhelpu,Samas-Samsam -.howcanihelpusir,Samas-Samsam -.VforVendetta,Samas-Samsam -.checkdiskenced,Samas-Samsam -.goforhelp,Samas-Samsam -.iloveworld,Samas-Samsam -.canihelpyou,Samas-Samsam -.AreYouLoveMyRansFile,Samas-Samsam -.fucku,Samas-Samsam -.happenencedfiles,Samas-Samsam -.iwishiyou,Samas-Samsam -.powerfulldecryp,Samas-Samsam -.suppose665,Samas-Samsam -.Whereisyourfiles,Samas-Samsam -.sanction,Sanction -.locked,Shark -.shino,ShinoLocker -.locked,SkidLocker / Pompous -.encrypted,Smrss32 -.RSNSlocked,SNSLocker -.RSplited,SNSLocker -.sport,Sport -.locked,Stampado -.locked,Strictor -.surprise,Surprise -.tzu,Surprise -.szf,SZFLocker -.xcri,TeleCrypt -.vvv,TeslaCrypt 0.x - 2.2.0 -.ecc,TeslaCrypt 0.x - 2.2.0 -.exx,TeslaCrypt 0.x - 2.2.0 -.ezz,TeslaCrypt 0.x - 2.2.0 -.abc,TeslaCrypt 0.x - 2.2.0 -.aaa,TeslaCrypt 0.x - 2.2.0 -.zzz,TeslaCrypt 0.x - 2.2.0 -.xyz,TeslaCrypt 0.x - 2.2.0 -.micro,TeslaCrypt 3.0+ -.xxx,TeslaCrypt 3.0+ -.ttt,TeslaCrypt 3.0+ -.mp3,TeslaCrypt 3.0+ -.Encrypted,TorrentLocker -.enc,TorrentLocker -.toxcrypt,Toxcrypt -.better_call_saul,Troldesh -.xtbl,Troldesh -.da_vinci_code,Troldesh -.windows10,Troldesh -.enc,TrueCrypter -.locked,Turkish Ransom -.H3LL,Ungluk -.0x0,Ungluk -.1999,Ungluk -.CRRRT,Unlock92 -.CCCRRRPPP,Unlock92 -.vault,VaultCrypt -.xort,VaultCrypt -.trun,VaultCrypt -.Venusf,VenusLocker -.Venusp,VenusLocker -.CrySiS,Virus-Encoder -.xtbl,Virus-Encoder -.wflx,WildFire Locker -.EnCiPhErEd,Xorist -.73i87A,Xorist -.p5tkjw,Xorist -.PoAr2w,Xorist -.fileiscryptedhard,Xorist -.encoderpass,Xorist -.zc3791,Xorist -.xrtn,XRTN -.zcrypt,Zcrypt -.crypto,Zimbra -.vault,Zlader / Russian -.zyklon,Zyklon -.wncry,WannaCry -.wcry,WannaCry -.wnry,WannaCry -.wncryt,WannaCry -.WNCRYT,WannaCry -.RYK,Ryuk -.Clop,Clop -.Cllp,Clop -.JSWORM,JSWorm -.NEMTY_*,Nemty -.NEFILIM,Nefilim -.OFFWHITE,Offwhite -.TELEGRAM,Telegram -.FUSION,Fusion -.MILIHPEN,Milihpen -.GANGBANG,Gangbang -.reddot,RedDot -.MEDUSA,Medusa -.rhysida,Rhysida diff --git a/lookups/ransomware_notes.csv b/lookups/ransomware_notes.csv deleted file mode 100644 index 5ab10617c1..0000000000 --- a/lookups/ransomware_notes.csv +++ /dev/null @@ -1,75 +0,0 @@ -ransomware_notes, status -HELP_TO_SAVE_FILES.txt,True -BitCryptorFileList.txt,True -BUYUNLOCKCODE,True -YOUR_FILES_ARE_ENCRYPTED.HTML,True -Coin.Locker.txt,True -DECRYPT_INSTRUCTIONS.HTML,True -ReadDecryptFilesHere.txt,True -HOW_DECRYPT.TXT,True -READ IF YOU WANT YOUR FILES BACK.HTML,True -GetYouFiles.txt,True -HOW TO DECRYPT FILES.HTML,True -DECRYPT_INSTRUCTION.TXT,True -HELP_DECRYPT.TXT,True -HELP_YOURFILES.HTML,True -HowDecrypt.gif,True -Decrypt All Files *.bmp,True -cryptinfo.txt,True -DECRYPT_Readme.TXT.ReadMe,True -qwer.html,True -qwer2.html,True -Hellothere.txt,True -FILESAREGONE.TXT,True -HOW TO DECRYPT FILES.TXT,True -DECRYPT_Readme.TXT.ReadMe,True -README_DECRYPT_HYDRA_ID_*.txt,True -DECRYPT_YOUR_FILES.HTML,True -KryptoLocker_README.txt,True -_Locky_recover_instructions.txt,True -DECRYPT_Readme.TXT.ReadMe,True -ATTENTION.RTF,True -how to get data.txt,True -IMPORTANT READ ME.txt,True -UnblockFiles.vbs,True -YOUR_FILES.url,True -exit.hhr.obleep,True -HOW_TO_DECRYPT.HTML,True -HOW-TO-DECRYPT-FILES.HTML,True -HELP_TO_SAVE_FILES.txt,True -HELP_TO_SAVE_FILES.txt,True -HELP_TO_SAVE_FILES.txt,True -_H_e_l_p_RECOVER_INSTRUCTIONS+*.txt,True -DECRYPT_INSTRUCTIONS.HTML,True -README_DECRYPT_UMBRE_ID_*.txt,True -Help_Decrypt.txt,True -CryptLogFile.txt,True -*@Please_Read_Me@.txt*,True -*@WanaDecryptor@.exe*,True -# DECRYPT MY FILES #.vbs,True -# DECRYPT MY FILES #.html,True -# DECRYPT MY FILES #.txt,True -# DECRYPT MY FILES #.vbs,True -# DECRYPT MY FILES #.html,True -# DECRYPT MY FILES #.txt,True -HELP_DECRYPT_YOUR_FILES.HTML,True -*-HELP_FOR_DECRYPT_FILE.html,True -*-SORRY-FOR-FILES.html,True -*-READ-FOR-HELLPP.html,True -RyukReadMe.html,True -ClopReadMe.txt,True -README_README.txt,True -JSWORM-DECRYPT.html,True -NEMTY_*-DECRYPT.txt,True -NEFILIM-DECRYPT.txt,True -OFFWHITE-MANUAL.txt,True -TELEGRAM-RECOVER.txt,True -FUSION-README.txt,True -MILIHPEN-INSTRUCT.txt,True -GANGBANG-NOTE.txt,True -GET_YOUR_FILES_BACK.txt,True -read_it.txt,True -*.README.txt, True -*READ_ME_MEDUSA*.TXT,True -How_to_back_files.HTML,True -CriticalBreachDetected.pdf,True \ No newline at end of file