Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2021-01-22 ⋅ InfoSec Handlers Diary Blog ⋅ Xavier Mertens
Another File Extension to Block in your MTA: .jnlp
2021-01-21 ⋅ InfoSec Handlers Diary Blog ⋅ Xavier Mertens
Powershell Dropping a REvil Ransomware
REvil
2021-01-13 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
Hancitor activity resumes after a hoilday break
Hancitor
2020-12-26 ⋅ CYBER GEEKS All Things Infosec ⋅ CyberMasterV
Analyzing APT19 malware using a step-by-step method
Derusbi
2020-12-24 ⋅ InfoSec Handlers Diary Blog ⋅ Xavier Mertens
Malicious Word Document Delivering an Octopus Backdoor
Octopus
2020-12-15 ⋅ InfoSec Handlers Diary Blog ⋅ Didier Stevens
Analyzing FireEye Maldocs
2020-12-09 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
Recent Qakbot (Qbot) activity
Cobalt Strike QakBot
2020-11-27 ⋅ CYBER GEEKS All Things Infosec ⋅ CyberMasterV
Dissecting APT21 samples using a step-by-step approach
NetTraveler
2020-11-19 ⋅ SANS ISC InfoSec Forums ⋅ Xavier Mertens
PowerShell Dropper Delivering Formbook
Formbook
2020-11-03 ⋅ InfoSec Handlers Diary Blog ⋅ Renato Marinho
Attackers Exploiting WebLogic Servers via CVE-2020-14882 to install Cobalt Strike
Cobalt Strike
2020-10-26 ⋅ SANS ISC InfoSec Forums ⋅ Didier Stevens
Excel 4 Macros: "Abnormal Sheet Visibility"
2020-09-10 ⋅ SANS ISC InfoSec Forums ⋅ Brad Duncan
Recent Dridex activity
Dridex
2020-05-31 ⋅ InfoSec Handlers Diary Blog ⋅ Renato Marinho
Guildma is now using Finger and Signed Binary Proxy Execution to evade defenses
Astaroth
2020-05-23 ⋅ InfoSec Handlers Diary Blog ⋅ Xavier Mertens
AgentTesla Delivered via a Malicious PowerPoint Add-In
Agent Tesla
2020-04-22 ⋅ Youtube (Infosec Alpha) ⋅ Raashid Bhat
FlattenTheCurve - Emotet Control Flow Unflattening | Episode 2
Emotet
2020-04-12 ⋅ InfoSec Handlers Diary Blog ⋅ Vinnie
Dynamic analysis technique to get decrypted KPOT Malware
KPOT Stealer
2020-03-31 ⋅ Youtube (Infosec Alpha) ⋅ Raashid Bhat
Emotet Binary Deobfuscation | Coconut Paradise | Episode 1
Emotet
2020-03-20 ⋅ RECON INFOSEC ⋅ Luke Rusten
Analysis Of Exploitation: CVE-2020-10189 ( exploited by APT41)
Cobalt Strike
2020-01-23 ⋅ SANS ISC InfoSec Forums ⋅ Brad Duncan
German language malspam pushes Ursnif
ISFB
2019-08-26 ⋅ InfoSec Handlers Diary Blog ⋅ Didier Stevens
The DAA File Format