Click here to download all references as Bib-File.
2023-04-13 ⋅ Trellix ⋅ Read The Manual Locker: A Private RaaS Provider RTM Locker |
2023-04-03 ⋅ Trellix ⋅ A Royal Analysis of Royal Ransom Royal Ransom |
2022-11-15 ⋅ Trellix ⋅ Wipermania: An All You Can Wipe Buffet dnWipe NominatusToxicBattery |
2022-04-12 ⋅ Max Kersten's Blog ⋅ Ghidra script to handle stack strings CaddyWiper PlugX |
2022-03-28 ⋅ Trellix ⋅ PlugX: A Talisman to Behold PlugX |
2022-03-02 ⋅ Trellix ⋅ Digging into HermeticWiper HermeticWiper |
2022-02-01 ⋅ Max Kersten's Blog ⋅ Dumping WhisperGate’s wiper from an Eazfuscator obfuscated loader WhisperGate |
2022-01-25 ⋅ Trellix ⋅ Prime Minister’s Office Compromised: Details of Recent Espionage Campaign Graphite |
2022-01-20 ⋅ Trellix ⋅ Return of Pseudo Ransomware WhisperGate |
2022-01-17 ⋅ Twitter (@Libranalysis) ⋅ Tweet on short analysis of WHISPERGATE stage 3 malware WhisperGate |
2021-09-08 ⋅ McAfee ⋅ How Groove Gang is Shaking up the Ransomware-as-a-Service Market to Empower Affiliates Babuk BlackMatter Babuk BlackMatter CTB Locker |
2021-08-04 ⋅ McAfee ⋅ See Ya Sharp: A Loader’s Tale |
2021-07-25 ⋅ Max Kersten's Blog ⋅ Ghidra script to decrypt a string array in XOR DDoS XOR DDoS |
2021-02-09 ⋅ Max Kersten's Blog ⋅ Ghidra script to decrypt strings in Amadey 1.09 Amadey |
2020-09-17 ⋅ Max Kersten's Blog ⋅ Automatic ReZer0 payload and configuration extraction |
2020-08-26 ⋅ Max Kersten's Blog ⋅ ReZer0v4 loader MASS Logger |
2020-04-14 ⋅ Emotet JavaScript downloader Unidentified JS 003 (Emotet Downloader) |
2020-03-26 ⋅ Max Kersten's Blog ⋅ Azorult loader stages Azorult |
2020-02-24 ⋅ Max Kersten's Blog ⋅ Closing in on MageCart 12 magecart |
2020-02-17 ⋅ Max Kersten's Blog ⋅ Following the tracks of MageCart 12 magecart |