Independence Day greeting campaign delivers Emotet
ID: 99e9e8f5-7df1-52d0-b6ba-87fbd09f0275
STIX ID: report--99e9e8f5-7df1-52d0-b6ba-87fbd09f0275
Feed Name: Zscaler Security Research Blog
**Executive Summary:** Zscaler ThreatLabZ observed an active Emotet campaign (July 2–4) distributing malicious Microsoft Office "Greeting Card" attachments that prompt users to enable macros; an obfuscated VBA macro launches a heavily obfuscated PowerShell payload downloader which installs Emotet (copies to system32, creates mutex PEM). The report includes de-obfuscation details, attack TTPs, and comprehensive IOCs: document and executable MD5s, download URLs/domains, and numerous C2 IP addresses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
