Click here to download all references as Bib-File.•
| 2023-08-08
⋅
Twitter (@malwrhunterteam)
⋅
Tweet about INC ransomware INC |
| 2023-08-08
⋅
Twitter (@suyog41)
⋅
Twitter Thread describing the Stealer 0bj3ctivityStealer |
| 2023-07-19
⋅
Twitter (@h2jazi)
⋅
Tweet on observation with Korean targeting, suspecting Lazarus Unidentified 105 |
| 2023-07-19
⋅
Twitter (@MsftSecIntel)
⋅
Tweet on targeted attacks against the defense sector in Ukraine and Eastern Europe by the threat actor Secret Blizzard DeliveryCheck Kazuar |
| 2023-07-11
⋅
Twitter (@embee_research)
⋅
Tweets on Ransomware Infrastructure Analysis With Censys and GrabbrApp DarkSide |
| 2023-06-30
⋅
Twitter (@rivitna2)
⋅
Twitter thread about relationship between 8Base and Phobos ransomware 8Base Phobos |
| 2023-06-24
⋅
Twitter (@embee_research)
⋅
SmokeLoader - Malware Analysis and Decoding With Procmon SmokeLoader |
| 2023-06-08
⋅
Twitter (@embee_research)
⋅
Practical Queries for Identifying Malware Infrastructure: An informal page for storing Censys/Shodan queries Amadey AsyncRAT Cobalt Strike QakBot Quasar RAT Sliver solarmarker |
| 2023-05-31
⋅
Twitter (@jaydinbas)
⋅
Tweet about C++ payload delivered via ISO Unidentified 104 |
| 2023-05-19
⋅
Twitter (@embee_research)
⋅
Analysis of Amadey Bot Infrastructure Using Shodan Amadey |
| 2023-05-18
⋅
Twitter (@embee_research)
⋅
Identifying Laplas Infrastructure Using Shodan and Censys LaplasClipper |
| 2023-05-07
⋅
Twitter (@embee_research)
⋅
AgentTesla - Full Loader Analysis - Resolving API Hashes Using Conditional Breakpoints Agent Tesla |
| 2023-04-28
⋅
Twitter (@MichalKoczwara)
⋅
Tweet on hunting BRC4 infrastructure Brute Ratel C4 |
| 2023-04-28
⋅
Twitter (@MalGamy12)
⋅
Tweet explaning similarity between Conti and Akira code Akira |
| 2023-04-18
⋅
Twitter (@1ZRR4H)
⋅
Tweet on CrossLock CrossLock |
| 2023-04-18
⋅
Twitter (@threatinsight)
⋅
Tweet on TA581 using Keitaro TDS URL to download a .MSI file to deliver BumbleBee malware BumbleBee |
| 2023-04-16
⋅
Twitter (@malwrhunterteam)
⋅
Tweet on MacOS Lockbit sample LockBit |
| 2023-04-11
⋅
Twitter (@Unit42_Intel)
⋅
Tweet on change of IcedID backconnect traffic port from 8080 to 443 IcedID |
| 2023-04-10
⋅
Twitter (@embee_research)
⋅
Redline Stealer - Static Analysis and C2 Extraction Amadey RedLine Stealer |
| 2023-04-08
⋅
Twitter (@embee_research)
⋅
Dcrat - Manual De-obfuscation of .NET Malware DCRat |