ATT&CKReferencesPincus Emotet 2020

Pincus Emotet 2020

Süleyman Özarslan, PhD; Pincus Security Inc.. (2020, July 14). An Analysis of Emotet Malware: PowerShell Unobfuscation. Retrieved November 25, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareEmotet

Emotet can download follow-on payloads and items via malicious `url` parameters in obfuscated PowerShell code.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.