Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2020-05-25 ⋅ Twitter (@JAMESWT_MHT) ⋅ JamesWT
Tweet on FuckUnicorn instance of HiddenTear
HiddenTear
2020-05-25 ⋅ Elastic ⋅ Brent Murphy, David French, Jamie Butler
The Elastic Guide to Threat Hunting
2020-05-25 ⋅ ⋅ CERT-FR ⋅ CERT-FR
INDICATEURS DE COMPROMISSION DU CERT-FR - Objet: Le code malveillant Dridex
Dridex
2020-05-25 ⋅ ⋅ CERT-FR ⋅ CERT-FR
Le Code Malveillant Dridex: Origines et Usages
Dridex
2020-05-25 ⋅ ⋅ AhnLab ⋅ AhnLab ASEC Analysis Team
Hangul malware distributed in real estate investment related emails (using EPS)
2020-05-24 ⋅ or10nlabs ⋅ oR10n
Reverse Engineering the Mustang Panda PlugX Loader
PlugX
2020-05-24 ⋅ Palo Alto Networks Unit 42 ⋅ Ajaya Neupane, Stefan Achleitner
Using AI to Detect Malicious C2 Traffic
Emotet Sality
2020-05-24 ⋅ Positive Technologies ⋅ PT ESC Threat Intelligence
Operation TA505: network infrastructure. Part 3.
AndroMut Buhtrap SmokeLoader
2020-05-24 ⋅ Nullteilerfrei Blog ⋅ Lars Wallenborn
Zloader String Obfuscation
Zloader
2020-05-24 ⋅ Malware and Stuff ⋅ Andreas Klopsch
Examining Smokeloader’s Anti Hooking technique
SmokeLoader
2020-05-23 ⋅ InfoSec Handlers Diary Blog ⋅ Xavier Mertens
AgentTesla Delivered via a Malicious PowerPoint Add-In
Agent Tesla
2020-05-23 ⋅ 360 netlab ⋅ Jinye
New activity of DoubleGuns Group, control hundreds of thousands of bots via public cloud service
2020-05-23 ⋅ Australian Cyber Security Centre ⋅ Australian Cyber Security Centre (ACSC)
Summary of Tradecraft Trends for 2019-20: Tactics, Techniques and Procedures Used to Target Australian Networks
2020-05-22 ⋅ Yoroi ⋅ Antonio Pirozzi, Giacomo d'Onofrio, Luca Mella, Luigi Martire
Cyber-Criminal espionage Operation insists on Italian Manufacturing
Agent Tesla
2020-05-22 ⋅ Positive Technologies ⋅ PT ESC Threat Intelligence
Operation TA505: investigating the ServHelper backdoor with NetSupport RAT. Part 2.
NetSupportManager RAT ServHelper
2020-05-22 ⋅ ESET Research ⋅ Lukáš Štefanko
Insidious Android malware gives up all malicious features but one to gain stealth
DEFENSOR ID
2020-05-22 ⋅ ThreatConnect ⋅ ThreatConnect Research Team
ThreatConnect Research Roundup: Possible APT33 Infrastructure
2020-05-22 ⋅ ⋅ Antiy CERT ⋅ Antiy CERT
Analysis of Ramsay components of Darkhotel's infiltration and isolation network
Ramsay DarkHotel
2020-05-21 ⋅ Sophos ⋅ SophosLabs Uncut
Asnarök attackers twice modified attack midstream
NOTROBIN Ragnarok
2020-05-21 ⋅ Intel 471 ⋅ Intel 471
A brief history of TA505
AndroMut Bart Dridex FlawedAmmyy FlawedGrace Gandcrab Get2 GlobeImposter Jaff Kegotip Locky Necurs Philadephia Ransom Pony QuantLoader Rockloader SDBbot ServHelper Shifu Snatch TrickBot