Emotet Malware Returns: Malspammer Strikes Again
ID: 9b9f1a5a-9f25-5d9b-ae26-b31714c1ff4c
STIX ID: report--9b9f1a5a-9f25-5d9b-ae26-b31714c1ff4c
Feed Name: Cyble Blog
Threat Score
### Executive Summary This report details an active Emotet malspam campaign (September 2020) that distributes malicious Office documents prompting users to enable macros; those macros invoke PowerShell to retrieve a packed Emotet payload which persists under %AppData% and communicates with remote C2 servers. The document provides infection-chain TTPs and extensive IOCs including file hashes, malicious URLs, domains and IP addresses to aid detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
