logo

Analysis of Emotet v4

ID: 111a4199-f21e-5465-b238-e5ef32aad7d5

STIX ID: report--111a4199-f21e-5465-b238-e5ef32aad7d5

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2017-05-24

Date Updated: 2026-04-19

Author: Paweł Srokosz

...
...

**Emotet v4 malspam campaign analysis:** The report documents a Polish malspam campaign distributing a new Emotet v4 variant (JavaScript dropper) that uses modular payloads, AES-128-CBC encrypted HTTP communication with RSA-protected AES keys, a protobuf-like C2 protocol, and modules for stealing browser/mail credentials and sending spam; it includes C2 IPs, module hashes, YARA rules, and mitigation advice (change passwords).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.