Kenefick, I. (2023, March 13). Emotet Returns, Now Adopts Binary Padding for Evasion. Retrieved June 19, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.001 Binary Padding |
MalwareEmotet | Emotet inflates malicious files and malware as an evasion technique. |
| T1027.013 Encrypted/Encoded File |
MalwareEmotet | Emotet uses obfuscated URLs to download a ZIP file. |
| T1055.012 Process Hollowing |
MalwareEmotet | Emotet uses a copy of `certutil.exe` stored in a temporary directory for process hollowing, starting the program in a suspended state before loading malicious code. |
| T1218.010 Regsvr32 |
MalwareEmotet | Emotet uses RegSvr32 to execute the DLL payload. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.