Exploring Emotet, an Elaborate Everyday Enigma

No ratings

Presented at Elbsides 2019 by

Based on Sophos detection numbers the Emotet Trojan is the most widespread malware family in the wild. It has been, and is still, the most notorious and costly malware since its appearance more than five years ago. Emotet owes its reputation to its constant state of evolution and change. The malware’s rapid advancement helps support its highly sophisticated operation. This presentation will discuss the reverse engineering of its component, the capabilities and features of Emotet: a detailed overview of its multilayered operation, starting with the spam lure, the malicious attachments (and their evolution); and the malware executable itself, from its highly sophisticated packer, to its C2 server communications.Emotet is well-known for its modular architecture, worm-like propagation, and highly skilled persistence techniques. The recent versions spread rapidly using multiple methods. Besides its capability to spread by brute forcing using its own password lists, it can harvest email addresses and email contents from victims, then spread through spam. Its diverse module list hides different malicious intentions, such as information stealing including credentials from web browsers or email clients, spreading capabilities, or delivering other malwares as well as ransomware or other banking Trojans. Finally, I will dissect the background operations of the payload modules. I will also present statistics from Sophos about its global reach.