Emotet: Dangerous Malware Keeps on Evolving
ID: 01d947bb-fdf5-5a56-9671-3bc52b572d72
STIX ID: report--01d947bb-fdf5-5a56-9671-3bc52b572d72
Feed Name: Symantec Threat Intel
Threat Score
**Emotet variant (Version 5) technical analysis:** This report analyzes an updated Emotet sample, detailing new anti-analysis features (control-flow flattening, encrypted strings, dynamic API resolution), a change to its C2 protocol (AES-128-CBC with RSA-wrapped session keys and multipart/form-data HTTP POSTs), modified LibLZF compression integration, droppers/persistence behavior, and supported C2 commands; it also provides an analyzed sample hash as an IOC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
