Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2021-07-09 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
Hancitor tries XLL as initial malware file
Cobalt Strike Hancitor
2021-06-21 ⋅ RECON INFOSEC ⋅ Andrew Cook
An Encounter With Ransomware-as-a-Service: MEGAsync Analysis
2021-06-14 ⋅ CYBER GEEKS All Things Infosec ⋅ CyberMasterV
A Step-by-Step Analysis of a New Version of DarkSide Ransomware
DarkSide
2021-05-18 ⋅ RECON INFOSEC ⋅ Andrew Cook
An Encounter With TA551/Shathak
IcedID
2021-04-19 ⋅ InfoSec Handlers Diary Blog ⋅ Jan Kopriva
Hunting phishing websites with favicon hashes
2021-04-14 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
April 2021 Forensic Quiz: Answers and Analysis
Anchor BazarBackdoor Cobalt Strike
2021-04-06 ⋅ InfoSec Handlers Diary Blog ⋅ Jan Kopriva
Malspam with Lokibot vs. Outlook and RFCs
Loki Password Stealer (PWS)
2021-03-31 ⋅ InfoSec Handlers Diary Blog ⋅ Xavier Mertens
Quick Analysis of a Modular InfoStealer
Amadey
2021-03-29 ⋅ InfoSec Handlers Diary Blog ⋅ Xavier Mertens
Jumping into Shellcode
2021-03-27 ⋅ InfoSec Handlers Diary Blog ⋅ Guy Bruneau
Malware Analysis with elastic-agent and Microsoft Sandbox
2021-03-12 ⋅ HealthcareInfoSecurity ⋅ Prajeet Nair
Spear-Phishing Campaign Distributes Nim-Based Malware
BazarNimrod
2021-03-10 ⋅ Lemon's InfoSec Ramblings ⋅ Josh Lemon
Microsoft Exchange & the HAFNIUM Threat Actor
CHINACHOPPER
2021-03-07 ⋅ InfoSec Handlers Diary Blog ⋅ Didier Stevens
PCAPs and Beacons
Cobalt Strike
2021-02-12 ⋅ InfoSec Handlers Diary Blog ⋅ Xavier Mertens
AgentTesla Dropped Through Automatic Click in Microsoft Help File
Agent Tesla
2021-02-11 ⋅ InfoSec Handlers Diary Blog ⋅ Jan Kopriva
Agent Tesla hidden in a historical anti-malware tool
Agent Tesla
2021-02-04 ⋅ InfoSec Handlers Diary Blog ⋅ Bojan Zdrnja
Abusing Google Chrome extension syncing for data exfiltration and C&C
2021-02-03 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
Excel spreadsheets push SystemBC malware
Cobalt Strike SystemBC
2021-01-31 ⋅ Twitter (@NCCGroupInfosec) ⋅ NCCGroup
Tweet on ITW exploitation of 0-day in SonicWall SMA 100 series
2021-01-28 ⋅ InfoSec Handlers Diary Blog ⋅ Daniel Wesemann
Emotet vs. Windows Attack Surface Reduction
Emotet
2021-01-25 ⋅ CYBER GEEKS All Things Infosec ⋅ CyberMasterV
A detailed analysis of ELMER Backdoor used by APT16
ELMER