EmoCrash: Exploiting a Vulnerability in Emotet Malware for Defense
ID: 399d56b4-188c-51ee-9a07-fd8e3b2491e6
STIX ID: report--399d56b4-188c-51ee-9a07-fd8e3b2491e6
Feed Name: Binary Defense Blog
Binary Defense discovered a buffer-overflow vulnerability in Emotet's updated installer and privately distributed a PowerShell 'killswitch' (EmoCrash) that wrote a crafted registry value to crash the loader and prevent installation; this mitigation provided protection between Feb 6 and Aug 6, 2020, until Emotet removed the vulnerable code. The report describes Emotet's persistence changes, the two versions of the killswitch, deployment coordination with CERTs, and the timeline of Emotet's reduced activity and eventual return.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
