Click here to download all references as Bib-File.
2023-05-19 ⋅ Twitter (@embee_research) ⋅ Analysis of Amadey Bot Infrastructure Using Shodan Amadey |
2023-05-18 ⋅ Twitter (@embee_research) ⋅ Identifying Laplas Infrastructure Using Shodan and Censys LaplasClipper |
2023-05-17 ⋅ Medium (@DCSO_CyTec) ⋅ Andariel’s “Jupiter” malware and the case of the curious C2 Jupiter |
2023-05-15 ⋅ embeeresearch ⋅ Quasar Rat Analysis - Identification of 64 Quasar Servers Using Shodan and Censys Quasar RAT |
2023-05-07 ⋅ Twitter (@embee_research) ⋅ AgentTesla - Full Loader Analysis - Resolving API Hashes Using Conditional Breakpoints Agent Tesla |
2023-04-21 ⋅ Symantec ⋅ X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe VEILEDSIGNAL |
2023-04-20 ⋅ Securonix ⋅ New OCX#HARVESTER Attack Campaign Leverages a Modernized More_eggs Suite to Target Victims More_eggs |
2023-04-11 ⋅ Twitter (@Unit42_Intel) ⋅ Tweet on change of IcedID backconnect traffic port from 8080 to 443 IcedID |
2023-04-10 ⋅ Twitter (@embee_research) ⋅ Redline Stealer - Static Analysis and C2 Extraction Amadey RedLine Stealer |
2023-04-08 ⋅ Twitter (@embee_research) ⋅ Dcrat - Manual De-obfuscation of .NET Malware DCRat |
2023-03-21 ⋅ Twitter (@splinter_code) ⋅ Tweet on BlackByte ransomware rewrite in C++ BlackByte |
2023-03-10 ⋅ Security0wnage ⋅ How Do You Like Dem Eggs? I like Mine Scrambled, Really Scrambled - A Look at Recent more_eggs Samples More_eggs |
2022-12-01 ⋅ Malware Analysis and Triage Report : PirateStealer - Discord_beta.exe PirateStealer |
2022-11-19 ⋅ Malwarology ⋅ Malicious Packer pkr_ce1a SmokeLoader Vidar |
2022-11-16 ⋅ Medium (@DCSO_CyTec) ⋅ HZ RAT goes China HZ RAT |
2022-11-14 ⋅ Twitter (@embee_research) ⋅ Twitter thread on Yara Signatures for Qakbot Encryption Routines IcedID QakBot |
2022-11-02 ⋅ Twitter (@_CPResearch_) ⋅ Tweet on Azov Wiper Azov Wiper |
2022-10-12 ⋅ Twitter (@embee_research) ⋅ Tweets on detection of Brute Ratel via API Hashes Brute Ratel C4 |
2022-10-11 ⋅ Twitter (@embee_research) ⋅ Tweet on Havoc C2 - Static Detection Via Ntdll API Hashes Havoc |
2022-10-11 ⋅ Medium (@DCSO_CyTec) ⋅ Tracking down Maggie Maggie |