ATT&CKReferencesemotet_trendmicro_mar2023

emotet_trendmicro_mar2023

Kenefick, I. (2023, March 13). Emotet Returns, Now Adopts Binary Padding for Evasion. Retrieved June 19, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1027.001
Binary Padding
MalwareEmotet

Emotet inflates malicious files and malware as an evasion technique.

T1027.013
Encrypted/Encoded File
MalwareEmotet

Emotet uses obfuscated URLs to download a ZIP file.

T1055.012
Process Hollowing
MalwareEmotet

Emotet uses a copy of `certutil.exe` stored in a temporary directory for process hollowing, starting the program in a suspended state before loading malicious code.

T1218.010
Regsvr32
MalwareEmotet

Emotet uses RegSvr32 to execute the DLL payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.