Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ EmoCheck - Emotet Detection Tool For Windows OS

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š EmoCheck - Emotet Detection Tool For Windows OS


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: kitploit.com


Emotet detection tool for Windows OS.

How to use

  1. Download EmoCheck from the Releases page.
  2. Run EmoCheck on the host.
  3. Check the exported report.

Download

Please download from the Releases page.

Command options

(since v0.0.2)

  • Specify output directory for the report (default: current directory)
    • /output [your output directory] or -output [your output directory]
  • No console output
    • /quiet or -quiet
  • Export the report in JSON style
    • /json or -json
  • Debug mode (no report)
    • /debug or -debug
  • Show help
    • /help or -help

How EmoCheck detects Emotet

(v0.0.1)
Emotet generates their process name from a specific word dictionary and C drive serial number. EmoCheck scans the running process on the host, and find Emotet process from their process name.

(added in v0.0.2)
Emotet keeps their encoded process name in a specific registry key. EmoCheck looks up and decode the registry value, and find it from the process list. Code Signing with Microsoft Authenticode.

(added in v1.0)
Support the April 2020 updated of Emotet.
Obfuscated code.

(added in v2.0)
Support the December 2020 updated of Emotet.
French language support. (Thanks to CERT-FR)

Sample Report

Text stlye:

[Emocheck v0.0.2]
Scan time: 2020-02-10 13:06:20
____________________________________________________

[Result]
Detected Emotet process.

[Emotet Process]
Process Name : mstask.exe
Process ID : 716
Image Path : C:\Users\[username]\AppData\Local\mstask.exe
____________________________________________________

Please remove or isolate the suspicious execution file.

JSON style (added in v0.0.2):

{
"scan_time":"2020-02-10 13:06:20",
"hostname":"[your hostname]",
"emocheck_version":"0.0.2",
"is_infected":"yes",
"emotet_processes":[
{
"process_name":"mstask.exe",
"process_id":"716",
"image_path":"C:\\Users\\[username]\\AppData\\Local\\mstask.exe"
}
]
}

The report will be exported to the following path.

(v0.0.1)
[current directory]\yyyymmddhhmmss_emocheck.txt

(since v0.0.2)
[output path]\[computer name]_yyyymmddhhmmss_emocheck.txt
[output path]\[computer name]_yyyymmddhhmmss_emocheck.json

Screenshot

(v0.0.1)

Releases

  • (Feb. 3, 2020) v0.0.1
    • Initial release
  • (Feb. 10, 2020) v0.0.2
    • update detecting method
    • add options
  • (Aug. 11, 2020) v1.0.0
    • update detecting method
  • (Jan. 27, 2021) v2.0.0
    • update detecting method
    • Added French language support
  • (Mar. 4, 2022) v2.1.0
    • update detecting method
  • (Mar. 14, 2022) v2.1.1
    • Fixed a crash bug when executing with SYSTEM privileges
  • (Apr. 22, 2022) v2.2.0
    • update detecting method
  • (May. 20, 2022) v2.3.0
    • update detecting method
  • (May. 24, 2022) v2.3.1
    • fixed a detection pattern
  • (May. 27, 2022) v2.3.2
    • fixed a detection pattern

License

Please read the LICENSE page.

Notes

Tested environments

  • Windows 11 21H2 64bit Japanese Edition
  • Windows 10 21H2 64bit Japanese Edition
  • Windows 8.1 64bit Japanese Edition
  • Windows 7 SP1 32bit Japanese Edition
  • Windows 7 SP1 64bit Japanese Edition

Windows 7 does not support UTF-8 output in the Command Prompt.

Build

  • Windows 10 1809 64bit Japanese Edition
  • Microsoft Visual Studio Community 2017

Source code

Not published from v2.1.



...



๐Ÿ“Œ EmoCheck 0.0.1 Englisch


๐Ÿ“ˆ 25.99 Punkte

๐Ÿ“Œ Download der Woche: EmoCheck


๐Ÿ“ˆ 25.99 Punkte

๐Ÿ“Œ Download der Woche: EmoCheck


๐Ÿ“ˆ 25.99 Punkte

๐Ÿ“Œ Braintrace Expands Network Detection and Response Capabilities & Is Named in the 2020 Gartner Network Detection and Response Market Guide


๐Ÿ“ˆ 17.64 Punkte

๐Ÿ“Œ Intrusion Detection Honeypots: Detection Through Deception - Chris Sanders - PSW #668


๐Ÿ“ˆ 17.64 Punkte

๐Ÿ“Œ How to integrate Linux Malware Detection and ClamAV for automated malware detection on Linux servers


๐Ÿ“ˆ 17.64 Punkte

๐Ÿ“Œ [papers] - Art of Anti Detection - Introduction To AV & Detection Techniques


๐Ÿ“ˆ 17.64 Punkte

๐Ÿ“Œ [papers] - Art of Anti Detection - Introduction To AV & Detection Techniques


๐Ÿ“ˆ 17.64 Punkte

๐Ÿ“Œ Threat Detection: Sophos erweitert Security-Portfolio um Extended Detection and Response


๐Ÿ“ˆ 17.64 Punkte

๐Ÿ“Œ Endpoint Detection & Response (EDR) benรถtigt Network Detection and Response (NDR) fรผr ...


๐Ÿ“ˆ 17.64 Punkte

๐Ÿ“Œ Vectra Unifies AI-Driven Behavior-Based Detection and Signature-Based Detection


๐Ÿ“ˆ 17.64 Punkte

๐Ÿ“Œ DefakeHop: A deepfake detection method that tackles adversarial threat detection and recognition


๐Ÿ“ˆ 17.64 Punkte

๐Ÿ“Œ Network Detection and Response (NDR) vs. Endpoint Detection and Response (EDR): A Comparison


๐Ÿ“ˆ 17.64 Punkte

๐Ÿ“Œ Facebook Debuts Open Source Detection Tool for Windows


๐Ÿ“ˆ 16.06 Punkte

๐Ÿ“Œ Facebook Debuts Open Source Detection Tool for Windows


๐Ÿ“ˆ 16.06 Punkte

๐Ÿ“Œ FIN7 Hackers Added New Hacking Tool BIOLOAD to Evade AV Detection โ€“ Attacks Windows 64-bit OS


๐Ÿ“ˆ 16.06 Punkte

๐Ÿ“Œ Canadian spooks release their own malware detection tool


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ Facebook's Phishing Detection Tool Now Recognizes Homograph Attacks


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ Fake Detection: Tool GPU-Z 2.12.0 erkennt gefรคlschte Grafikkarten


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ Researcher releases Free Ransomware Detection Tool for Mac OS X Users


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ Nchop - A TCP Session Splicing Tool Used to Rvade Intrusion Detection Systems


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ IoT-Home-Guard - A Tool For Malicious Behavior Detection In IoT Devices


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ Flerken - Obfuscated Command Detection Tool


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ Netscape Browser 7.x Client Detection Tool Plugin memory corruption


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ Google Chrome is ditching its XSS detection tool


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ CMSeeK | An Open Source Content Management System Detection and Exploitation Tool


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ Dr.Semu - Malware Detection and Classification Tool Based on Dynamic Behavior


๐Ÿ“ˆ 14.19 Punkte

๐Ÿ“Œ ESET BlueKeep (CVEโ€‘2019โ€‘0708) Detectionโ€‘Tool


๐Ÿ“ˆ 14.19 Punkte











matomo