Click here to download all references as Bib-File.•
2022-05-17
⋅
Palo Alto Networks Unit 42
⋅
Emotet Summary: November 2021 Through January 2022 Emotet |
2022-05-11
⋅
SANS ISC
⋅
TA578 using thread-hijacked emails to push ISO files for Bumblebee malware BumbleBee |
2022-05-11
⋅
InfoSec Handlers Diary Blog
⋅
TA578 using thread-hijacked emails to push ISO files for Bumblebee malware BumbleBee Cobalt Strike IcedID PhotoLoader |
2022-04-20
⋅
SANS ISC
⋅
'aa' distribution Qakbot (Qbot) infection with DarkVNC traffic QakBot |
2022-04-06
⋅
SANS ISC
⋅
Windows MetaStealer Malware |
2022-04-06
⋅
InfoSec Handlers Diary Blog
⋅
Windows MetaStealer Malware MetaStealer |
2022-03-23
⋅
InfoSec Handlers Diary Blog
⋅
Arkei Variants: From Vidar to Mars Stealer Arkei Stealer Mars Stealer Oski Stealer Vidar |
2022-03-23
⋅
InfoSec Handlers Diary Blog
⋅
Arkei Variants: From Vidar to Mars Stealer Arkei Stealer Mars Stealer Vidar |
2022-03-16
⋅
InfoSec Handlers Diary Blog
⋅
Qakbot infection with Cobalt Strike and VNC activity Cobalt Strike QakBot |
2022-03-16
⋅
SANS ISC
⋅
Qakbot infection with Cobalt Strike and VNC activity Cobalt Strike QakBot |
2022-02-15
⋅
Palo Alto Networks Unit 42
⋅
New Emotet Infection Method Emotet |
2022-01-25
⋅
SANS ISC
⋅
Emotet Stops Using 0.0.0.0 in Spambot Traffic Emotet |
2022-01-19
⋅
InfoSec Handlers Diary Blog
⋅
0.0.0.0 in Emotet Spambot Traffic Emotet |
2022-01-17
⋅
Github (pan-unit42)
⋅
IOCs for Astaroth/Guildma malware infection Astaroth |
2021-12-30
⋅
InfoSec Handlers Diary Blog
⋅
Agent Tesla Updates SMTP Data Exfiltration Technique Agent Tesla |
2021-12-16
⋅
InfoSec Handlers Diary Blog
⋅
How the "Contact Forms" campaign tricks people IcedID |
2021-12-03
⋅
SANS ISC InfoSec Forums
⋅
TA551 (Shathak) pushes IcedID (Bokbot) IcedID |
2021-11-16
⋅
InfoSec Handlers Diary Blog
⋅
Emotet Returns Emotet |
2021-10-18
⋅
paloalto Netoworks: Unit42
⋅
Case Study: From BazarLoader to Network Reconnaissance BazarBackdoor Cobalt Strike |
2021-09-29
⋅
Malware Traffic Analysis
⋅
Hancitor with Cobalt Strike Cobalt Strike Hancitor |