Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2024-01-17TrellixMax Kersten
Kuiper Ransomware’s Evolution
Kuiper Kuiper Kuiper
2023-11-29TrellixAlexandre Mundo, Max Kersten
Akira Ransomware
Akira Akira Storm-1567
2023-11-29TrellixAlexandre Mundo, Max Kersten
Akira Ransomware
Akira
2023-04-13TrellixMax Kersten
Read The Manual Locker: A Private RaaS Provider
RTM Locker
2023-04-03TrellixAlexandre Mundo, Max Kersten
A Royal Analysis of Royal Ransom
Royal Ransom
2022-11-15TrellixMax Kersten
Wipermania: An All You Can Wipe Buffet
dnWipe NominatusToxicBattery
2022-04-12Max Kersten's BlogMax Kersten
Ghidra script to handle stack strings
CaddyWiper PlugX
2022-03-28TrellixMarc Elias, Max Kersten
PlugX: A Talisman to Behold
PlugX
2022-03-02TrellixMax Kersten
Digging into HermeticWiper
HermeticWiper
2022-02-01Max Kersten's BlogMax Kersten
Dumping WhisperGate’s wiper from an Eazfuscator obfuscated loader
WhisperGate
2022-01-25TrellixAlexandre Mundo, Christiaan Beek, Leandro Velasco, Marc Elias, Max Kersten
Prime Minister’s Office Compromised: Details of Recent Espionage Campaign
Graphite
2022-01-20TrellixChristiaan Beek, Max Kersten, Raj Samani
Return of Pseudo Ransomware
WhisperGate
2022-01-17Twitter (@Libranalysis)Max Kersten
Tweet on short analysis of WHISPERGATE stage 3 malware
WhisperGate
2021-09-08McAfeeJohn Fokker, Max Kersten, Thibault Seret
How Groove Gang is Shaking up the Ransomware-as-a-Service Market to Empower Affiliates
Babuk BlackMatter Babuk BlackMatter CTB Locker
2021-08-04McAfeeMax Kersten
See Ya Sharp: A Loader’s Tale
2021-07-25Max Kersten's BlogMax Kersten
Ghidra script to decrypt a string array in XOR DDoS
XOR DDoS
2021-02-09Max Kersten's BlogMax Kersten
Ghidra script to decrypt strings in Amadey 1.09
Amadey
2020-09-17Max Kersten's BlogMax Kersten
Automatic ReZer0 payload and configuration extraction
2020-08-26Max Kersten's BlogMax Kersten
ReZer0v4 loader
MASS Logger
2020-04-14Max Kersten
Emotet JavaScript downloader
Unidentified JS 003 (Emotet Downloader)
2020-03-26Max Kersten's BlogMax Kersten
Azorult loader stages
Azorult
2020-02-24Max Kersten's BlogMax Kersten
Closing in on MageCart 12
magecart
2020-02-17Max Kersten's BlogMax Kersten
Following the tracks of MageCart 12
magecart
2020-01-20Max Kersten's BlogMax Kersten
Ticket resellers infected with a credit card skimmer
magecart
2019-10-14Max Kersten's BlogMax Kersten
Corona DDoS bot
Bashlite
2019-02-16Max Kersten's BlogMax Kersten
Emotet droppers
Emotet