ATT&CKReferencesMalwarebytes Emotet Dec 2017

Malwarebytes Emotet Dec 2017

Smith, A.. (2017, December 22). Protect your network from Emotet Trojan with Malwarebytes Endpoint Security. Retrieved January 17, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
MalwareEmotet

Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement.

T1078.003
Local Accounts
MalwareEmotet

Emotet can brute force a local admin password, then use it to facilitate lateral movement.

T1110.001
Password Guessing
MalwareEmotet

Emotet has been observed using a hard coded list of passwords to brute force user accounts.

T1566.001
Spearphishing Attachment
MalwareEmotet

Emotet has been delivered by phishing emails containing attachments.

T1566.002
Spearphishing Link
MalwareEmotet

Emotet has been delivered by phishing emails containing links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.