2021-11-30 (TUESDAY) - EMOTET EPOCH4 USES APPINSTALLER FOR INFECTION
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2021-11-30-IOCs-for-Emotet-epoch4-from-appinstaller.txt.zip   1.1 kB   (1,086 bytes)
- 2021-11-30-Emotet-epoch4-malspam-for-appinstaller.eml.zip   1.6 kB   (1,577 bytes)
- 2021-11-30-Emotet-epoch4-infection-from-appinstaller.pcap.zip   9.0 MB   (8,963,772 bytes)
- 2021-11-30-malware-and-artifacts-for-Emotet-epoch4-from-appinstaller.zip   1.5 MB   (1,478,955 bytes)
IMAGES
Shown above: Screenshot of the email.
Shown above: Downloading the appinstaller using link from the email.
Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.