Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2021-11-10CrowdStrikeAntonio Parata
Ploutus ATM Malware Case Study: Automated Deobfuscation of a Strongly Obfuscated .NET Binary
Ploutus ATM
2021-11-10open source dfirAlexander Jäger
Use EVTX files on VirusTotal with Timesketch and Sigma (Part 2)
2021-11-10BlackberryCodi Starks, Ryan Chapman
REvil Under the Microscope
GootKit REvil
2021-11-10MicrosoftJohn Lambert
The hunt for NOBELIUM, the most sophisticated nation-state attack in history
2021-11-10Cisco TalosAsheer Malhotra, Jungsoo An, Kendall McKay
North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets
GoldDragon
2021-11-10RandoriRandori Attack Team
Zero-Day Disclosure: Palo Alto Networks GlobalProtect VPN CVE-2021-3064
2021-11-10Twitter (@billyleonard)Billy Leonard, Google Threat Analysis Group
Tweet on Rekoobe (used by APT31), being a fork of open source tool called Tiny SHell, used by different actor since at least 2012
Rekoobe
2021-11-10AT&TJosh Gomez
Stories from the SOC - Powershell, Proxyshell, Conti TTPs OH MY!
Cobalt Strike Conti
2021-11-10McAfeeKiran Raj
The Newest Malicious Actor: “Squirrelwaffle” Malicious Doc.
Squirrelwaffle
2021-11-10SekoiaCyber Threat Intelligence team
Walking on APT31 infrastructure footprints
Rekoobe Unidentified ELF 004 Cobalt Strike
2021-11-10mai1zhi2
mai1zhi2 / SharpBeacon - CobaltStrike Beacon written in .Net 4
SharpBeacon
2021-11-09CybereasonAleksandar Milenkoski, Eli Salem
THREAT ANALYSIS REPORT: From Shatak Emails to the Conti Ransomware
Cobalt Strike Conti
2021-11-09CertitudeWolfgang Ettlinger
The Invisible JavaScript Backdoor
2021-11-09Trend MicroTrend Micro Research
Compromised Docker Hub Accounts Abused for Cryptomining Linked to TeamTNT
2021-11-09CloudflareOmer Yoachimik, Vivek Ganti
A Brief History of the Meris Botnet
2021-11-09CrowdStrikeLukas Kupczyk, Max Julian Hofmann
Scheming with URLs: One-Click Attack Surface in Linux Desktop Environments
2021-11-09360 netlabAlex.Turing, Hui Wang
Abcbot, an evolving botnet
Abcbot
2021-11-09MinervaLabsMinerva Labs
A New DatopLoader Delivers QakBot Trojan
QakBot Squirrelwaffle
2021-11-09SpecterOpsMichael Barclay
Capability Abstraction Case Study: Detecting Malicious Boot Configuration Modifications
2021-11-09VinCSSVinCSS
[EX008] The exploit chain allows to take control of Zalo user accounts