A look at recent Emotet Campaigns - Aug, 2017
ID: 391d8d30-480c-55da-8506-8845c4e17cdb
STIX ID: report--391d8d30-480c-55da-8506-8845c4e17cdb
Feed Name: Zscaler Security Research Blog
Threat Score
**Emotet technical analysis:** This report describes a recent Emotet campaign that distributes a credential‑stealing banking Trojan via malspam and malicious Office documents with obfuscated macros/VBS, explains the custom packer and in‑memory decryption, persistence mechanisms (service + timer queue), C2 registration and HTTP POST exfiltration behavior, and provides hard‑coded C2 IPs, filename generation logic, and other indicators observed by Zscaler.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
