API Call Dataset of LockBit, Netwalker, WannaCry, and Petya Ransomware

Published: 24 August 2026| Version 1 | DOI: 10.17632/yh9p6vs53y.1
Contributors:
,
,
,

Description

This dataset comprises sequences of Windows API calls collected from ransomware and benign program samples in a controlled sandboxed environment. The ransomware samples belong to four families, namely LockBit, NetWalker, WannaCry, and Petya. This dataset provides host-based behavioral information about the samples during their execution. The underlying hypothesis behind this data collection is that ransomware exhibits distinct API call behavioral patterns compared with benign software. The data can be used to study ransomware-related behavioral patterns, perform feature extraction, and develop ransomware detection methods using machine learning techniques.

Files

Institutions

Categories

Cybersecurity, Machine Learning, Malware Mitigation

Licence