Included domain list to PowerShell script...
-
Updated
Jan 8, 2021
Included domain list to PowerShell script...
Emotet Loader helps execute Emotet modules in isolation. Emotet is one of the most active botnets, that delivers its modules, such as credit card stealer or SMB spreader, to the user machines. Emotet Loader allows to run the modules separately from the core component and help analyzing their behavior.
EmoKill is an Emotet process detection and killing tool for Windows OS. It avoids wasting time after detection of Emotet. Any process that matches the pattern of Emotet based on the logic of EmoCheck by JPCERT/CC will be detected by EmoKill and killed as soon as possible.
a State-Machine reversing exercise
Links to malware-related YARA rules
Collection of various files from infected hosts
Control-flow-flattening and string deobfuscator
A repository full of malware samples.
Malware samples, analysis exercises and other interesting resources.
Add a description, image, and links to the emotet topic page so that developers can more easily learn about it.
To associate your repository with the emotet topic, visit your repo's landing page and select "manage topics."