Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2020-08-14Twitter (@James_inthe_box)James_inthe_box
Tweet on Echelon Stealer
2020-06-11Cado SecurityChris Doman, James Campbell
An Ongoing AWS Phishing Campaign
2020-06-10James_inthe_box, jeFF0Falltrades, _re_fox
FRat Reporting, YARA, and IoCs
FRat Loader FRat
2020-06-02Lastline LabsJames Haughom, Stefano Ortolani
Evolution of Excel 4.0 Macro Weaponization
Agent Tesla DanaBot ISFB TrickBot Zloader
2020-05-25Twitter (@JAMESWT_MHT)JamesWT
Tweet on FuckUnicorn instance of HiddenTear
HiddenTear
2020-05-16Cado SecurityChris Doman, James Campbell
Recent Attacks Against Supercomputers
Loerbas
2020-05-12Twitter (@James_inthe_box)James_inthe_box
Tweet on Himera Loader
Himera Loader
2020-03-10LastlineJames Haughom
IQY files and Paradise Ransomware
Paradise
2020-03-06Binary DefenseJames Quinn
Emotet Wi-Fi Spreader Upgraded
Emotet
2020-02-07Binary DefenseJames Quinn
Emotet Evolves With New Wi-Fi Spreader
Emotet
2019-12-20Binary DefenseJames Quinn
An Updated ServHelper Tunnel Variant
ServHelper
2019-04-25FireEyeJames T. Bennett, Michael Bailey
CARBANAK Week Part Four: The CARBANAK Desktop Video Player
2019-04-24FireEyeJames T. Bennett, Michael Bailey
CARBANAK Week Part Three: Behind the CARBANAK Backdoor
Carbanak
2019-04-23FireEyeJames T. Bennett, Michael Bailey
CARBANAK Week Part Two: Continuing the CARBANAK Source Code Analysis
2019-04-22FireEyeJames T. Bennett, Michael Bailey
CARBANAK Week Part One: A Rare Occurrence
Carbanak
2019-03-21CrowdStrikeJames Scalise, Shaun Hurley
Interception: Dissecting BokBot’s “Man in the Browser”
IcedID
2019-03-08The Daily SwigJames Walker
Emotet trojan implicated in Wolverine Solutions ransomware attack
Emotet
2019-01-03CrowdStrikeJames Scalise, Shaun Hurley
Digging into BokBot’s Core Module
IcedID
2018-12-29Los Angeles TimesEmily Alpert Reyes, Meg James, Tony Barboza
Malware attack disrupts delivery of L.A. Times and Tribune papers across the U.S.
Ryuk
2018-10-01Twitter (@James_inthe_box)James_inthe_box
Tweet on DGA using TLD xyz
MakLoader