dashboardmodule-10
HIGHEmotet / TrickBot
Emotet is typically delivered via phishing emails containing macro-enabled Word documents. When a user is tricked into 'Enabling Content', a hidden VBScript spawns PowerShell.
INVOICE_89432.doc [Protected View] - Word
SECURITY WARNING Macros have been disabled.
DOCUMENT PROTECTED BY RSA SECURE ID
Click "Enable Content" to decrypt and view this document.
Click "Enable Content" to decrypt and view this document.
Phase 1 of 3
Malicious Delivery (Macro)