Click here to download all references as Bib-File.•
2020-08-14
⋅
Twitter (@James_inthe_box)
⋅
Tweet on Echelon Stealer |
2020-06-11
⋅
Cado Security
⋅
An Ongoing AWS Phishing Campaign |
2020-06-10
⋅
FRat Reporting, YARA, and IoCs FRat Loader FRat |
2020-06-02
⋅
Lastline Labs
⋅
Evolution of Excel 4.0 Macro Weaponization Agent Tesla DanaBot ISFB TrickBot Zloader |
2020-05-25
⋅
Twitter (@JAMESWT_MHT)
⋅
Tweet on FuckUnicorn instance of HiddenTear HiddenTear |
2020-05-16
⋅
Cado Security
⋅
Recent Attacks Against Supercomputers Loerbas |
2020-05-12
⋅
Twitter (@James_inthe_box)
⋅
Tweet on Himera Loader Himera Loader |
2020-03-10
⋅
Lastline
⋅
IQY files and Paradise Ransomware Paradise |
2020-03-06
⋅
Binary Defense
⋅
Emotet Wi-Fi Spreader Upgraded Emotet |
2020-02-07
⋅
Binary Defense
⋅
Emotet Evolves With New Wi-Fi Spreader Emotet |
2019-12-20
⋅
Binary Defense
⋅
An Updated ServHelper Tunnel Variant ServHelper |
2019-04-25
⋅
FireEye
⋅
CARBANAK Week Part Four: The CARBANAK Desktop Video Player |
2019-04-24
⋅
FireEye
⋅
CARBANAK Week Part Three: Behind the CARBANAK Backdoor Carbanak |
2019-04-23
⋅
FireEye
⋅
CARBANAK Week Part Two: Continuing the CARBANAK Source Code Analysis |
2019-04-22
⋅
FireEye
⋅
CARBANAK Week Part One: A Rare Occurrence Carbanak |
2019-03-21
⋅
CrowdStrike
⋅
Interception: Dissecting BokBot’s “Man in the Browser” IcedID |
2019-03-08
⋅
The Daily Swig
⋅
Emotet trojan implicated in Wolverine Solutions ransomware attack Emotet |
2019-01-03
⋅
CrowdStrike
⋅
Digging into BokBot’s Core Module IcedID |
2018-12-29
⋅
Los Angeles Times
⋅
Malware attack disrupts delivery of L.A. Times and Tribune papers across the U.S. Ryuk |
2018-10-01
⋅
Twitter (@James_inthe_box)
⋅
Tweet on DGA using TLD xyz MakLoader |