# Malware Corpus The MBC malware corpus comprises a variety of malware where each entry is decomposed into behaviors that are mapped to ATT&CK and MBC. The mappings are based on open source malware analysis reports and are separated into three categories: "ATT&CK Techniques," "Enhanced ATT&CK Techniques," and "MBC Behaviors." **ATT&CK Techniques** - If a malware entry *is not* included in ATT&CK's software collection, then all ATT&CK techniques to which its malware behaviors map are listed. If a malware entry *is* included in ATT&CK's software collection, then the corresponding software page is referenced under "ATT&CK Techniques" (individual mappings *not* captured in ATT&CK are still listed). These techniques have T identifiers (e.g., T1012). **Enhanced ATT&CK Techniques** - Any ATT&CK techniques that would be listed under "ATT&CK Techniques" but have been enhanced in MBC are listed in this section instead. These techniques have E and F identifiers (e.g., E1560, F0008). **MBC Behaviors** - This section lists all MBC behaviors to which an entry's malware behaviors map. These techniques have B and C identifiers (e.g., B0032, C0010). ### Notes * Each entry is mapped to one or more [malware types](./malware-types.md). * Poison-Ivy [X0014](../xample-malware/poison-ivy.md) and Kovter [X0009](../xample-malware/kovter.md) are examples of malware samples included and *not* included in ATT&CK's collection, respectively. * The [FAQ](../yfaq/README.md/#other) includes information about the malware used to illustrate the use of MBC in [Attack Flow](https://mitre-engenuity.org/cybersecurity/center-for-threat-informed-defense/our-work/attack-flow/) and [CACAO](https://github.com/oasis-tcs/cacao). ## The List * **Adwind jRAT** [X0048](../xample-malware/adwind-jrat.md) * **Attor** [X0049](../xample-malware/attor.md) * **BadUSB** [X0046](../xample-malware/badusb.md) * **Bagle** [X0001](../xample-malware/bagle.md) * **Black Energy** [X0002](../xample-malware/blackenergy.md) * **Chopstick** [X0035](../xample-malware/chopstick.md) * **Clipminer** [X0038](../xample-malware/clipminer.md) * **Conficker** [X0003](../xample-malware/conficker.md) * **Conti** [X0050](../xample-malware/conti.md) * **CozyCar** [X0034](../xample-malware/cozycar.md) * **CryptoLocker** [X0030](../xample-malware/cryptolocker.md) * **CryptoWall** [X0029](../xample-malware/cryptowall.md) * **Dark Comet** [X0004](../xample-malware/dark-comet.md) * **DNSChanger** [X0005](../xample-malware/dnschanger.md) * **Drovorub** [X0045](../xample-malware/drovorub.md) * **DYEPACK** [X0042](../xample-malware/dyepack.md) * **ElectroRAT** [X0044](../xample-malware/electrorat.md) * **Emotet** [X0028](../xample-malware/emotet.md) * **EvilBunny** [X0036](../xample-malware/evilbunny.md) * **Gamut** [X0006](../xample-malware/gamut.md) * **Geneio** [X0007](../xample-malware/geneio.md) * **GoBotKR** [X0027](../xample-malware/gobotkr.md) * **GravityRAT** [X0032](../xample-malware/gravity-rat.md) * **Heriplor** [X0026](../xample-malware/heriplor.md) * **Hupigon** [X0008](../xample-malware/hupigon.md) * **Kovter** [X0009](../xample-malware/kovter.md) * **Kraken** [X0010](../xample-malware/kraken.md) * **Locky Bart** [X0011](../xample-malware/locky-bart.md) * **Matanbuchus** [X0040](../xample-malware/matanbuchus.md) * **Mazarbot** [X0012](../xample-malware/mazarbot.md) * **Mebromi** [X0013](../xample-malware/mebromi.md) * **Netwalker** [X0037](../xample-malware/netwalker.md) * **Poison-Ivy** [X0014](../xample-malware/poison-ivy.md) * **Redhip** [X0015](../xample-malware/redhip.md) * **Rombertik** [X0031](../xample-malware/rombertik.md) * **SamSam** [X0016](../xample-malware/samsam.md) * **SearchAwesome** [X0017](../xample-malware/searchawesome.md) * **Shamoon** [X0018](../xample-malware/shamoon.md) * **Snake** [X0047](../xample-malware/snake.md) * **Stuxnet** [X0019](../xample-malware/stuxnet.md) * **SYNful Knock** [X0020](../xample-malware/synful-knock.md) * **TEARDROP** [X0041](../xample-malware/teardrop.md) * **Terminator** [X0021](../xample-malware/terminator.md) * **TrickBot** [X0025](../xample-malware/trickbot.md) * **UP007** [X0033](../xample-malware/up007.md) * **Ursnif** [X0022](../xample-malware/ursnif.md) * **Vobfus** [X0039](../xample-malware/vobfus.md) * **WannaCry** [X0043](../xample-malware/wannacry.md) * **WebCobra** [X0023](../xample-malware/webcobra.md) * **YiSpecter** [X0024](../xample-malware/yispecter.md)