Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2022-08-29InQuestDavid Ledbetter
@online{ledbetter:20220829:office:efe24cb, author = {David Ledbetter}, title = {{Office Files, RTF files, Shellcode and more shenanigans}}, date = {2022-08-29}, organization = {InQuest}, url = {https://inquest.net/blog/2022/08/29/office-files-rtf-files-shellcode-and-more-shenanigans}, language = {English}, urldate = {2022-08-31} } Office Files, RTF files, Shellcode and more shenanigans
CloudEyE
2022-06-27InQuestIsabelle Quinn
@online{quinn:20220627:glowsand:deff96a, author = {Isabelle Quinn}, title = {{GlowSand}}, date = {2022-06-27}, organization = {InQuest}, url = {https://inquest.net/blog/2022/06/27/glowsand}, language = {English}, urldate = {2022-06-30} } GlowSand
2022-06-23InQuestPedram Amini
@online{amini:20220623:follina:60ea599, author = {Pedram Amini}, title = {{Follina, the Latest in a Long Chain of Microsoft Office Exploits}}, date = {2022-06-23}, organization = {InQuest}, url = {https://inquest.net/blog/2022/06/23/follina-latest-long-chain-microsoft-office-exploits}, language = {English}, urldate = {2023-03-24} } Follina, the Latest in a Long Chain of Microsoft Office Exploits
2022-04-18InQuestDmitry Melikov
@online{melikov:20220418:nobelium:536804e, author = {Dmitry Melikov}, title = {{Nobelium - Israeli Embassy Maldoc}}, date = {2022-04-18}, organization = {InQuest}, url = {https://inquest.net/blog/2022/04/18/nobelium-israeli-embassy-maldoc}, language = {English}, urldate = {2022-05-09} } Nobelium - Israeli Embassy Maldoc
2022-04-07InQuestWill MacArthur, Nick Chalard
@online{macarthur:20220407:ukraine:99bef5a, author = {Will MacArthur and Nick Chalard}, title = {{Ukraine CyberWar Overview}}, date = {2022-04-07}, organization = {InQuest}, url = {https://inquest.net/blog/2022/04/07/ukraine-cyberwar-overview}, language = {English}, urldate = {2022-04-29} } Ukraine CyberWar Overview
CyclopsBlink Cobalt Strike GraphSteel GrimPlant HermeticWiper HermeticWizard MicroBackdoor PartyTicket Saint Bot Scieron WhisperGate
2022-03-30InQuestDmitry Melikov
@online{melikov:20220330:cloud:f8d985e, author = {Dmitry Melikov}, title = {{Cloud Atlas Maldoc}}, date = {2022-03-30}, organization = {InQuest}, url = {https://inquest.net/blog/2022/03/30/cloud-atlas-maldoc}, language = {English}, urldate = {2022-08-02} } Cloud Atlas Maldoc
2022-02-10InQuestJosiah Smith
@online{smith:20220210:380glowspark:6e3a6c6, author = {Josiah Smith}, title = {{+380-GlowSpark}}, date = {2022-02-10}, organization = {InQuest}, url = {https://inquest.net/blog/2022/02/10/380-glowspark}, language = {English}, urldate = {2022-02-17} } +380-GlowSpark
GlowSpark WhisperGate
2021-12-20InQuestNick Chalard
@online{chalard:20211220:dont:0aad3db, author = {Nick Chalard}, title = {{(Don't) Bring Dridex Home for the Holidays}}, date = {2021-12-20}, organization = {InQuest}, url = {https://inquest.net/blog/2021/12/20/dont-bring-dridex-home-holidays}, language = {English}, urldate = {2021-12-22} } (Don't) Bring Dridex Home for the Holidays
DoppelDridex Dridex
2021-11-02InQuestDmitry Melikov
@online{melikov:20211102:adults:cc39000, author = {Dmitry Melikov}, title = {{Adults Only Malware Lures}}, date = {2021-11-02}, organization = {InQuest}, url = {https://inquest.net/blog/2021/11/02/adults-only-malware-lures}, language = {English}, urldate = {2021-11-08} } Adults Only Malware Lures
Agent Tesla
2021-08-23InQuestDmitry Melikov
@online{melikov:20210823:kimsuky:e899bfa, author = {Dmitry Melikov}, title = {{Kimsuky Espionage Campaign}}, date = {2021-08-23}, organization = {InQuest}, url = {https://inquest.net/blog/2021/08/23/kimsuky-espionage-campaign}, language = {English}, urldate = {2021-08-30} } Kimsuky Espionage Campaign
Kimsuky
2021-08-05InQuestInQuest Labs
@online{labs:20210805:trystero:69ae6fb, author = {InQuest Labs}, title = {{The Trystero Project}}, date = {2021-08-05}, organization = {InQuest}, url = {https://labs.inquest.net/trystero}, language = {English}, urldate = {2021-08-09} } The Trystero Project
2021-05-26InQuestDmitry Melikov
@online{melikov:20210526:pschain:e8cbc2d, author = {Dmitry Melikov}, title = {{PSChain}}, date = {2021-05-26}, organization = {InQuest}, url = {https://inquest.net/blog/2021/05/26/pschain}, language = {English}, urldate = {2021-06-09} } PSChain
2021-04-16InQuestDmitry Melikov
@online{melikov:20210416:unearthing:4ff003c, author = {Dmitry Melikov}, title = {{Unearthing Hancitor Infrastructure}}, date = {2021-04-16}, organization = {InQuest}, url = {https://inquest.net/blog/2021/04/16/unearthing-hancitor-infrastructure}, language = {English}, urldate = {2021-04-28} } Unearthing Hancitor Infrastructure
Hancitor
2020-07-20Twitter (@InQuest)InQuest
@online{inquest:20200720:tweets:8920a27, author = {InQuest}, title = {{Tweets on PowerPepper decryption}}, date = {2020-07-20}, organization = {Twitter (@InQuest)}, url = {https://twitter.com/InQuest/status/1285295975347650562}, language = {English}, urldate = {2020-12-08} } Tweets on PowerPepper decryption
PowerPepper
2019-08-26InQuestJosiah Smith
@online{smith:20190826:memory:c4cea9b, author = {Josiah Smith}, title = {{Memory Analysis of TrickBot}}, date = {2019-08-26}, organization = {InQuest}, url = {https://inquest.net/blog/2019/08/26/TrickBot-Memory-Analysis}, language = {English}, urldate = {2020-01-10} } Memory Analysis of TrickBot
TrickBot
2019-03-09InQuestAmirreza Niakanlahiji
@online{niakanlahiji:20190309:analyzing:b88d299, author = {Amirreza Niakanlahiji}, title = {{Analyzing Sophisticated PowerShell Targeting Japan}}, date = {2019-03-09}, organization = {InQuest}, url = {http://blog.inquest.net/blog/2019/03/09/Analyzing-Sophisticated-PowerShell-Targeting-Japan/}, language = {English}, urldate = {2019-12-24} } Analyzing Sophisticated PowerShell Targeting Japan
UrlZone
2018-06-22InQuestAswanda
@online{aswanda:20180622:formbook:ce3c98b, author = {Aswanda}, title = {{FormBook stealer: Data theft made easy}}, date = {2018-06-22}, organization = {InQuest}, url = {http://blog.inquest.net/blog/2018/06/22/a-look-at-formbook-stealer/}, language = {English}, urldate = {2020-01-09} } FormBook stealer: Data theft made easy
Formbook