Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2021-07-23Github (Lastline-Inc)Quentin Fois, Pavankumar Chaudhari
@online{fois:20210723:yara:e9a8a22, author = {Quentin Fois and Pavankumar Chaudhari}, title = {{YARA rules, IOCs and Scripts for extracting IcedID C2s}}, date = {2021-07-23}, organization = {Github (Lastline-Inc)}, url = {https://github.com/Lastline-Inc/iocs-tools/tree/main/2021-07-IcedID-Part-2}, language = {English}, urldate = {2021-07-27} } YARA rules, IOCs and Scripts for extracting IcedID C2s
IcedID
2020-06-02Lastline LabsJames Haughom, Stefano Ortolani
@online{haughom:20200602:evolution:3286d87, author = {James Haughom and Stefano Ortolani}, title = {{Evolution of Excel 4.0 Macro Weaponization}}, date = {2020-06-02}, organization = {Lastline Labs}, url = {https://www.lastline.com/labsblog/evolution-of-excel-4-0-macro-weaponization/}, language = {English}, urldate = {2020-06-03} } Evolution of Excel 4.0 Macro Weaponization
Agent Tesla DanaBot ISFB TrickBot Zloader
2020-03-10LastlineJames Haughom
@online{haughom:20200310:iqy:1844f48, author = {James Haughom}, title = {{IQY files and Paradise Ransomware}}, date = {2020-03-10}, organization = {Lastline}, url = {https://www.lastline.com/labsblog/iqy-files-and-paradise-ransomware/}, language = {English}, urldate = {2020-06-17} } IQY files and Paradise Ransomware
Paradise
2020-02-18LastlineJason Zhang, Stefano Ortolani
@online{zhang:20200218:nemty:8d6340a, author = {Jason Zhang and Stefano Ortolani}, title = {{Nemty Ransomware Scaling UP: APAC Mailboxes Swarmed by Dual Downloaders}}, date = {2020-02-18}, organization = {Lastline}, url = {https://www.lastline.com/labsblog/nemty-ransomware-scaling-up-apac-mailboxes-swarmed-dual-downloaders/}, language = {English}, urldate = {2020-02-23} } Nemty Ransomware Scaling UP: APAC Mailboxes Swarmed by Dual Downloaders
Nemty Phorpiex
2019-09-30LastlineJason Zhang, Stefano Ortolani
@online{zhang:20190930:helo:559ed11, author = {Jason Zhang and Stefano Ortolani}, title = {{HELO Winnti: Attack or Scan?}}, date = {2019-09-30}, organization = {Lastline}, url = {https://www.lastline.com/labsblog/helo-winnti-attack-scan/}, language = {English}, urldate = {2019-10-23} } HELO Winnti: Attack or Scan?
Winnti
2019-01-11LastlineQuentin Fois
@online{fois:20190111:threat:5be977b, author = {Quentin Fois}, title = {{Threat Actor “Cold River”: Network Traffic Analysis and a Deep Dive on Agent Drable}}, date = {2019-01-11}, organization = {Lastline}, url = {https://www.lastline.com/labsblog/threat-actor-cold-river-network-traffic-analysis-and-a-deep-dive-on-agent-drable/}, language = {English}, urldate = {2020-01-09} } Threat Actor “Cold River”: Network Traffic Analysis and a Deep Dive on Agent Drable
Cold River
2018-05-31LastlineDavid Wells, Stefano Ortolani, Andy Norton, Luukas Larinkoski
@online{wells:20180531:apt28:2b7cdb5, author = {David Wells and Stefano Ortolani and Andy Norton and Luukas Larinkoski}, title = {{APT28 Rollercoaster: The Lowdown on Hijacked Lo}}, date = {2018-05-31}, organization = {Lastline}, url = {https://www.lastline.com/labsblog/apt28-rollercoaster-the-lowdown-on-hijacked-lojack/}, language = {English}, urldate = {2020-01-10} } APT28 Rollercoaster: The Lowdown on Hijacked Lo
2018-03-09Lastlinelastline Labs Team
@online{team:20180309:from:7820406, author = {lastline Labs Team}, title = {{From Russia(?) with Code}}, date = {2018-03-09}, organization = {Lastline}, url = {https://www.lastline.com/labsblog/attribution-from-russia-with-code/}, language = {English}, urldate = {2020-01-07} } From Russia(?) with Code
Olympic Destroyer
2018-02-21LastlineAlexander Sevtsov, Stefano Ortolani
@online{sevtsov:20180221:olympic:6584ecb, author = {Alexander Sevtsov and Stefano Ortolani}, title = {{Olympic Destroyer: A new Candidate in South Korea}}, date = {2018-02-21}, organization = {Lastline}, url = {https://www.lastline.com/labsblog/olympic-destroyer-south-korea/}, language = {English}, urldate = {2019-10-23} } Olympic Destroyer: A new Candidate in South Korea
Olympic Destroyer
2017-12-19LastlineAndy Norton
@online{norton:20171219:novel:2a852a7, author = {Andy Norton}, title = {{Novel Excel Spreadsheet Attack Launches Password Stealing Malware Loki Bot}}, date = {2017-12-19}, organization = {Lastline}, url = {https://www.lastline.com/blog/password-stealing-malware-loki-bot/}, language = {English}, urldate = {2020-01-13} } Novel Excel Spreadsheet Attack Launches Password Stealing Malware Loki Bot
Loki Password Stealer (PWS)
2017-12-13LastlineAlexander Sevtsov
@online{sevtsov:20171213:tyupkin:71f090d, author = {Alexander Sevtsov}, title = {{Tyupkin ATM Malware: Take The Money Now Or Never!}}, date = {2017-12-13}, organization = {Lastline}, url = {https://www.lastline.com/labsblog/tyupkin-atm-malware/}, language = {English}, urldate = {2019-10-21} } Tyupkin ATM Malware: Take The Money Now Or Never!
Tyupkin
2016-10-24Lastlinelastline Labs Team
@online{team:20161024:evasive:063b4ce, author = {lastline Labs Team}, title = {{Evasive Malware Detects and Defeats Virtual Machine Analysis}}, date = {2016-10-24}, organization = {Lastline}, url = {https://www.lastline.com/blog/evasive-malware-detects-and-defeats-virtual-machine-analysis/}, language = {English}, urldate = {2021-05-25} } Evasive Malware Detects and Defeats Virtual Machine Analysis