Click here to download all references as Bib-File.
2022-05-20 ⋅ SANS ISC ⋅ A 'Zip Bomb' to Bypass Security Controls & Sandboxes BitRAT |
2022-05-11 ⋅ SANS ISC ⋅ TA578 using thread-hijacked emails to push ISO files for Bumblebee malware BumbleBee |
2022-04-25 ⋅ SANS ISC ⋅ Simple PDF Linking to Malicious Content |
2022-04-20 ⋅ SANS ISC ⋅ 'aa' distribution Qakbot (Qbot) infection with DarkVNC traffic QakBot |
2022-03-31 ⋅ SANS ISC ⋅ Spring Vulnerability Update - Exploitation Attempts CVE-2022-22965 |
2022-03-25 ⋅ SANS ISC ⋅ XLSB Files: Because Binary is Stealthier Than XML QakBot |
2022-03-16 ⋅ SANS ISC ⋅ Qakbot infection with Cobalt Strike and VNC activity Cobalt Strike QakBot |
2022-02-18 ⋅ SANS ISC ⋅ Remcos RAT Delivered Through Double Compressed Archive Remcos |
2022-02-11 ⋅ blog.rootshell.be ⋅ [SANS ISC] CinaRAT Delivered Through HTML ID Attributes Quasar RAT |
2022-01-25 ⋅ SANS ISC ⋅ Emotet Stops Using 0.0.0.0 in Spambot Traffic Emotet |
2022-01-20 ⋅ SANS ISC InfoSec Forums ⋅ RedLine Stealer Delivered Through FTP RedLine Stealer |
2022-01-20 ⋅ blog.rootshell.be ⋅ [SANS ISC] RedLine Stealer Delivered Through FTP RedLine Stealer |
2021-12-03 ⋅ SANS ISC InfoSec Forums ⋅ TA551 (Shathak) pushes IcedID (Bokbot) IcedID |
2020-11-19 ⋅ SANS ISC InfoSec Forums ⋅ PowerShell Dropper Delivering Formbook Formbook |
2020-10-26 ⋅ SANS ISC InfoSec Forums ⋅ Excel 4 Macros: "Abnormal Sheet Visibility" |
2020-09-10 ⋅ SANS ISC InfoSec Forums ⋅ Recent Dridex activity Dridex |
2020-03-23 ⋅ SANS ISC ⋅ KPOT Deployed via AutoIt Script KPOT Stealer |
2020-02-03 ⋅ SANS ISC ⋅ Analysis of a triple-encrypted AZORult downloader Azorult |
2020-01-23 ⋅ SANS ISC InfoSec Forums ⋅ German language malspam pushes Ursnif ISFB |
2019-05-07 ⋅ SANS ISC InfoSec Forums ⋅ Vulnerable Apache Jenkins exploited in the wild kerberods |