Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2021-07-04Twitter (@svch0st)Zach
Tweet on #Kaseya detection tool for detecting REvil
REvil
2021-07-04Twitter (@PolarToffee)Toffee
Tweet on AvosLocker, ransomware advertising for affiliates through Dread
2021-07-03Twitter (@fwosar)Fabian Wosar
Twitter thread on REvil's cryptographic scheme
REvil
2021-07-03Twitter (@LloydLabs)Lloyd
Twitter Thread on Revil sideloading DLL used in Kaseya attack
REvil
2021-07-02Twitter (@VK_intel)Vitali Kremez
Tweet on Revil ransomware analysis used in Kaseya attack
REvil
2021-07-02Twitter (@SyscallE)SeAccessCheck
Tweet on Revil dropper used in Kaseya attack
REvil
2021-06-29Twitter (@IntezerLabs)Intezer
Tweet on unknown elf backdoor based on an open source remote shell named "amcsh"
BioSet
2021-06-29Twitter (@sisoma2)sisoma2
Tweet on vidar stealer using Tumblr to obtain dynamic config
Vidar
2021-06-29Twitter (@VK_intel)Vitali Kremez
Tweet on Linux version of REvil ransomware
REvil
2021-06-28Twitter (@AdamTheAnalyst)AdamTheAnalyst
Tweet on suspected REvil exfiltration (over RClone FTP) server
REvil REvil
2021-06-28Twitter (@VK_intel)Vitali Kremez
Tweet on ELF version of REvil
REvil
2021-06-27Twitter (@GossiTheDog)Kevin Beaumont
Tweet on babuk ransomware builder
Babuk
2021-06-23Twitter (@IntezerLabs)Intezer
Tweet on linux version of Derusbi
Derusbi
2021-06-22Twitter (@Cryptolaemus1)Cryptolaemus, dao ming si, Kirk Sayre
Tweet on TA575, a Dridex affiliate delivering cobaltstrike (packed withe Cryptone) directly via the macro docs
Cobalt Strike Dridex
2021-06-18YouTube (jnpc)Twitter (@yarai1978), Yuu Arai
"Cyber ​​Security" Yu Arai, NTT DATA Executive Security Analyst
2021-06-16Twitter (@ChouchWard)ch0uch ward
Tweet on Qbot operators left their web server's access.log file unsecured
QakBot
2021-06-16nur.pubTwitter (@1umos_)
Cerberus Analysis - Android Banking Trojan
Cerberus
2021-06-13Twitter (@alberto__segura)Alberto Segura
Tweet on Flubot version 4.6
FluBot
2021-06-12Twitter (@AltShiftPrtScn)Peter Mackenzie
A thread on RagnarLocker ransomware group's TTP seen in an Incident Response
Cobalt Strike RagnarLocker
2021-06-11Twitter (@MsftSecIntel)Microsoft Security Intelligence
Tweet on solarmarker/Jupyter malware
solarmarker