Click here to download all references as Bib-File.•
2021-01-19
⋅
HP
⋅
Dridex Malicious Document Analysis: Automating the Extraction of Payload URLs Dridex |
2021-01-19
⋅
Malwarebytes
⋅
Malwarebytes targeted by Nation State Actor implicated in SolarWinds breach. Evidence suggests abuse of privileged access to Microsoft Office 365 and Azure environments |
2021-01-19
⋅
Github (fireeye)
⋅
Mandiant Azure AD Investigator: Focusing on UNC2452 TTPs SUNBURST |
2021-01-19
⋅
Mandiant
⋅
Remediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452 (WHITE PAPER) |
2021-01-19
⋅
FireEye
⋅
Remediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452 |
2021-01-19
⋅
Checkpoint
⋅
FreakOut – Leveraging Newest Vulnerabilities for creating a Botnet N3Cr0m0rPh |
2021-01-19
⋅
Trend Micro
⋅
VPNFilter Two Years Later: Routers Still Compromised VPNFilter |
2021-01-19
⋅
⋅
JPCERT/CC
⋅
Tools used within the network invaded by attack group Lazarus |
2021-01-18
⋅
Symantec
⋅
Raindrop: New Malware Discovered in SolarWinds Investigation Cobalt Strike Raindrop SUNBURST TEARDROP |
2021-01-18
⋅
Arxiv
⋅
Identifying Authorship Style in Malicious Binaries: Techniques, Challenges & Datasets |
2021-01-18
⋅
Twitter (@teamcymru)
⋅
Tweet on APT36 CrimsonRAT C2 Crimson RAT |
2021-01-18
⋅
aaqeel01
⋅
Docx Files Template-Injection Unidentified 003 (Gamaredon Downloader) |
2021-01-18
⋅
Bleeping Computer
⋅
IObit forums hacked in widespread DeroHE ransomware attack |
2021-01-18
⋅
The DFIR Report
⋅
All That for a Coinminer? Coinminer Monero Miner |
2021-01-18
⋅
Wired
⋅
Trump’s Worst, Most Bizarre Statements About ‘the Cyber’ |
2021-01-18
⋅
Cado Security
⋅
Botnet Deploys Cloud and Container Attack Techniques |
2021-01-17
⋅
Twitter (@AltShiftPrtScn)
⋅
Tweet on Conti Ransomware group exploiting FortiGate VPNs to drop in CobaltStrike loaders Cobalt Strike Conti |
2021-01-15
⋅
The Hacker News
⋅
Researchers Disclose Undocumented Chinese Malware Used in Recent Attacks CROSSWALK |
2021-01-15
⋅
nccgroup
⋅
Sign over Your Hashes – Stealing NetNTLM Hashes via Outlook Signatures |
2021-01-15
⋅
Medium Dansec
⋅
Detecting Malicious C2 Activity -SpawnAs & SMB Lateral Movement in CobaltStrike Cobalt Strike |