What’s up Emotet?
ID: b386c998-5521-5f4a-9dd8-f6f5473592e3
STIX ID: report--b386c998-5521-5f4a-9dd8-f6f5473592e3
Feed Name: CERT Polska
Threat Score
This report analyzes the Emotet malware family, documenting recent changes in obfuscation and communication (VM-like control-flow obfuscation, encrypted strings and RSA-encrypted AES keys, custom binary protocol with AES-CBC and SHA-1 integrity, new compression and multipart/form-data exfiltration), C2 storage and path generation, and provides sample hashes and packet/register dissections to aid detection and research.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
