I decided to re-visit the Emotet analysis after receiving some indications that the infection had made its way to my labs Domain Controller.
Emotet Makes Its Way to the Domain Controller

tsrvinnie@gmail.com
I decided to re-visit the Emotet analysis after receiving some indications that the infection had made its way to my labs Domain Controller.
Analysis of malicious VBA code from Emotet Maldoc containing PowerShell downloader.
Review of recent Emotet Maldoc obfuscation & evasion techniques
The Emotet Malware Delivery Botnet is utilizing a combination of obfuscated VBA scripts, macros, and powershell instructions to evade antivirus defenses while relying on social engineering in order to successfully exploit target systems as user intervention is mandatory in the