Analysis of Emotet v4
ID: 111a4199-f21e-5465-b238-e5ef32aad7d5
STIX ID: report--111a4199-f21e-5465-b238-e5ef32aad7d5
Feed Name: CERT Polska
Threat Score
**Emotet v4 malspam campaign analysis:** The report documents a Polish malspam campaign distributing a new Emotet v4 variant (JavaScript dropper) that uses modular payloads, AES-128-CBC encrypted HTTP communication with RSA-protected AES keys, a protobuf-like C2 protocol, and modules for stealing browser/mail credentials and sending spam; it includes C2 IPs, module hashes, YARA rules, and mitigation advice (change passwords).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
