ATT&CKReferencesCarbon Black Emotet Apr 2019

Carbon Black Emotet Apr 2019

Lee, S.. (2019, April 24). Emotet Using WMI to Launch PowerShell Encoded Code. Retrieved May 24, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareEmotet

Emotet has used WMI to execute powershell.exe.

T1059.001
PowerShell
MalwareEmotet

Emotet has used Powershell to retrieve the malicious payload and download additional resources like Mimikatz.

T1059.005
Visual Basic
MalwareEmotet

Emotet has sent Microsoft Word documents with embedded macros that will invoke scripts to download additional payloads.

T1204.001
Malicious Link
MalwareEmotet

Emotet has relied upon users clicking on a malicious link delivered through spearphishing.

T1204.002
Malicious File
MalwareEmotet

Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1566.001
Spearphishing Attachment
MalwareEmotet

Emotet has been delivered by phishing emails containing attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.