logo

What’s up Emotet?

ID: b386c998-5521-5f4a-9dd8-f6f5473592e3

STIX ID: report--b386c998-5521-5f4a-9dd8-f6f5473592e3

Feed Name: CERT Polska

Threat Score
80/100

Date Published: 2020-02-18

Date Updated: 2026-04-19

Author: Michał Praszmo

...
...

This report analyzes the Emotet malware family, documenting recent changes in obfuscation and communication (VM-like control-flow obfuscation, encrypted strings and RSA-encrypted AES keys, custom binary protocol with AES-CBC and SHA-1 integrity, new compression and multipart/form-data exfiltration), C2 storage and path generation, and provides sample hashes and packet/register dissections to aid detection and research.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.