TF-MAL-js.unidentified_003
📛 Threat Title
Malware family: Unidentified JS 003 (Emotet Downloader)
Description
ThreatFox malware family `js.unidentified_003`. Printable name: Unidentified JS 003 (Emotet Downloader).
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Emotet is a modular malware variant which is primarily used as a downloader for other malware variants such as TrickBot and IcedID. Emotet first emerged in June 2014, initially targeting the financial sector, and has expanded to multiple verticals over time.
-
web:github.com
Emotet Loader helps execute Emotet modules in isolation. Emotet is one of the most active botnets, that delivers its modules, such as credit card stealer or SMB spreader, to the user machines. Emotet Loader allows to run the modules separately from the core component and help analyzing their behavior.
-
web:malpedia.caad.fkie.fraunhofer.de
Unidentified JS 003 (Emotet Downloader) Propose Change Actor (s): MUMMY SPIDER According to Max Kersten, Emotet is dropped by a procedure spanned over multiple stages. The first stage is an office file that contains a macro. This macro then loads the second stage, which is either a PowerShell script or a piece of JavaScript, which is this ...
-
web:redcanary.com
Emotet is an advanced, modular trojan that primarily functions as a downloader or dropper of other malware . It's disseminated through malicious email links or attachments that use branding familiar to the recipient.
-
web:research.splunk.com
Description Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment. Why it matters The trojan downloader known as Emotet first surfaced in 2014, when it was discovered targeting the banking ...
-
web:www.bsi.bund.de
Emotet also has the ability to download other malware once it has infected a computer. These malware programs enable the attackers to obtain access data and full remote access to the system.
-
web:www.cisa.gov
Emotet—a sophisticated Trojan commonly functioning as a downloader or dropper of other malware—resurged in July 2020, after a dormant period that began in February. Since August, CISA and MS-ISAC have seen a significant increase in malicious cyber actors targeting state and local governments with Emotet phishing emails.
-
web:www.huntress.com
Emotet is a powerful malware that started as a banking trojan but evolved into a platform capable of distributing ransomware and stealing sensitive data. It infiltrates systems primarily through phishing emails and operates via injecting malicious code into legitimate processes while avoiding detection.
-
web:www.justice.gov
The law enforcement file prevented the administrators of the Emotet botnet from further communicating with infected computers. The law enforcement file did not remediate other malware that was already installed on infected computers; instead, it was designed to prevent additional malware from being installed on the infected computer by ...
-
web:www.malwarebytes.com
Short bio Trojan. Emotet is Malwarebytes' detection name for a banking Trojan that can steal data, such as user credentials stored on the browser, by eavesdropping on network traffic. Due to its effective combination of persistence and network propagation, Trojan. Emotet is often used as a downloader for other malware , and is an especially popular delivery mechanism for banking Trojans, such ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.