Emotet Downloader Document Uses Regsvr32 for Execution

Obfuscated Excel macros are used to download and run the Emotet loader. The Emotet loader is executed using regsvr32.exe. A Windows service is used for Emotet payload persistence.

Emotet Downloader Document Uses Regsvr32 for Execution
Obfuscated Excel macros are used to download and run the Emotet loader. The Emotet loader is executed using regsvr32.exe. A Windows service is used for Emotet payload persistence.