Skip to main content
Powered by ShareScore

Find research datasets worth reusing

Search datasets from major research repositories and use ShareScore to quickly assess how well each record supports discovery, access, and reuse.

3

datasets available to search

ShareScore release 0.9.0

Reset

Dataset results

3 results for “ransomware dataset”

Learn how ShareScore rates datasets ↗
zenodo44/100

Ransomware Dataset 2024

<p>The dataset we have created is focused on malware analysis and consists of 26 different malware families, categorized into four main categories. It includes both malicious and benign samples, providing a balanced total of 21,752 samples, with 10,876 malicious and 10,876 benign files.</p> <h3>Key Aspects of the Dataset:</h3> <ol> <li> <p><strong>Total Samples</strong>: 21,752 files (10,876 malicious and 10,876 benign).</p> </li> <li> <p><strong>Malware Families</strong>: The dataset contains 26 distinct malware families, with a strong focus on ransomware, which includes:</p> <ul> <li><strong>Cerber</strong></li> <li><strong>DarkSide</strong></li> <li><strong>Dharma</strong></li> <li><strong>GandCrab</strong></li> <li><strong>LockBit</strong></li> <li><strong>Maze</strong></li> <li><strong>Phobos</strong></li> <li><strong>REvil</strong></li> <li><strong>Ragnar Locker</strong></li> <li><strong>Ryuk</strong></li> <li><strong>Shade</strong></li> <li><strong>WannaCry</strong></li> </ul> <p>These 11 ransomware families represent some of the most notorious strains responsible for large-scale attacks in recent years.</p> </li> <li> <p><strong>Categories</strong>: The dataset is divided into four categories, although you haven&rsquo;t specified the exact categorization scheme (it could be based on behavior, type of attack, or other malware features). Typical categories could include <strong>Trojan</strong>, <strong>Ransomware</strong>, <strong>Spyware</strong>, and <strong>Adware</strong>.</p> </li> </ol> <h3>Significance of the Dataset:</h3> <ul> <li><strong>Balanced Distribution</strong>: The dataset is evenly distributed between malicious and benign files, making it ideal for machine learning models that can differentiate between malware and benign software.</li> <li><strong>Ransomware Focus</strong>: By including major ransomware families, this dataset allows for specialized research in ransomware detection, mitigation, and family classification.</li> <li><strong>Diversity in Malware Types</strong>: The inclusion of 26 malware families ensures a wide spectrum of malware behavior and characteristics, making the dataset versatile for research in various malware categories.</li> </ul> <h3>Applications:</h3> <ul> <li><strong>Machine Learning and AI</strong>: This dataset can be used to train models for malware classification, detection, and family identification.</li> <li><strong>Cybersecurity Research</strong>: It supports analysis and countermeasure development against ransomware and other forms of malware.</li> <li><strong>Forensic Analysis</strong>: Researchers can use it to investigate attack patterns, signature generation, and the impact of ransomware on different systems.</li> </ul> <p>This dataset is valuable for advancing malware analysis, specifically in understanding ransomware behavior, and for building robust defenses against increasingly sophisticated attacks.</p>

opencc-by-4.0Oct 2024View details →
zenodo44/100

Ransomwhere: A Crowdsourced Ransomware Payment Dataset

<p>Ransomwhere is the largest dataset of ransomware payment addresses, comprising over a billion dollars in payments. The dataset contains payment addresses, transactions, and the associated ransomware family. Anyone &mdash; whether a victim, a firm, or a security researcher &mdash; can help grow the data by submitting addresses of ransomware actors. For more information and to submit data, see <a href="https://ransomwhe.re/">ransomwhe.re</a>.</p>

opencc-by-4.0May 2022View details →
zenodo20/100

Dataset of "Extinguishing Ransomware - A Hybrid Approach to Android Ransomware Detection"

<p>Protection against ransomware is particularly relevant in systems running the Android operating system, due to its huge users&#39; base and, therefore, its potential for monetization from the attackers. In &quot;Extinguishing Ransomware - A Hybrid Approach to Android Ransomware Detection&quot; (see references for details), we describe a hybrid (static + dynamic) malware detection method that has extremely good accuracy (100% detection rate, with false positive below 4%).</p> <p>&nbsp;</p> <p>We release a dataset related to the dynamic detection part of the aforementioned methods and containing execution traces of ransomware Android applications, in order to facilitate further research as well as to facilitate the adoption of dynamic detection in practice. The dataset contains execution traces from 666 ransomware applications taken from the Heldroid project [https://github.com/necst/heldroid] (the app repository is unavailable at the moment). Execution records were obtained by running the applications, one at a time, on the Android emulator. For each application, a maximum of 20,000 stimuli were applied with a maximum execution time of 15 minutes. For most of the applications, all the stimuli could be applied in this timeframe. In some of the traces none of the two limits is reached due to emulator hiccups. Collected features are related to the memory and CPU usage, network interaction and system calls and their monitoring is performed with a period of two seconds. The Android emulator of the Android Software Development Kit for Android 4.0 (release 20140702) was used. To guarantee that the system was always in a mint condition when a new sample is started, thus avoiding possible interference (e.g., changed settings, running processes, and modifications of the operating system files) from previously run samples, the Android operating system was each time re-initialized before running each application. The application execution process was automated by means of a shell script that made use of Android Debug Bridge (adb) and that was run on a Linux PC. The Monkey application exerciser was used in the script as a generator of the aforementioned stimuli. The Monkey is a command-line tool that can be run on any emulator instance or on a device; it sends a pseudo-random stream of user events (stimuli) into the system, which acts as a stress test on the application software.</p> <p>In this dataset, we provide both per-app CSV files as well as unified files, in which CSV files of single applications have been concatenated. The CSV files contain the features extracted from the raw execution record. The provided files are listed below:</p> <ul> <li> <p>ransom-per_app-csv.zip - features obtained by executing ransomware applications, one CSV per application</p> </li> <li> <p>ransom-unified-csv.zip - features obtained by executing ransomware applications, only one CSV file</p> </li> </ul>

restrictedSep 2018View details →

ScienceDex guides

Understand access before you commit

These curated guides explain access requirements, typical timelines, costs, and reuse considerations for widely used research datasets.

Compare curated datasets

Allen Brain Atlas

Allen Brain Atlas is an Allen Institute collection of brain map atlases, datasets, APIs, and analysis tools covering mouse, human, and non-human primate brain resources.

allen-brain-atlas
neuroscienceopenDocumentation, web resources, and API references are available online.
Last verified 2026-04-30Open record

Annotated Behaviour and Observability Dataset (ABODe)

ABODe is a University of Edinburgh DataShare dataset for behavior classification in group-housed mice using home-cage video, identities, bounding boxes, ground-plate positions, and annotator labels.

abode-home-cage
behavioral-neuroscienceopenThe DataShare record exposes download links for annotations, documentation, license text, and the zipped per-snippet data directory.
Last verified 2026-04-30Open record

DANDI Archive for NWB datasets

DANDI is a BRAIN Initiative archive for publishing and sharing neurophysiology data, including electrophysiology, optophysiology, and behavioral data packaged as NWB and related standards.

dandi-nwb
electrophysiologyopenPublished Dandiset metadata and archive endpoints are available through the production DANDI API.
Last verified 2026-04-30Open record

International Brain Laboratory public data

The International Brain Laboratory public data releases expose standardized mouse decision-making experiments, including Neuropixels recordings, widefield calcium imaging, behavior, and session metadata accessed through the ONE API.

ibl
behavioral-neuroscienceopenPublic sessions can be searched and loaded from the IBL public data server through ONE.
Last verified 2026-04-29Open record

OpenNeuro

OpenNeuro is a free, open platform for sharing neuroimaging datasets, with public search, dataset pages, and download paths for web, S3, DataLad, and the OpenNeuro CLI.

openneuro
neuroscienceopenPublished datasets are available on demand over the internet.
Last verified 2026-04-29Open record