EmoCheck v2.3.2 releases: Emotet detection tool for Windows OS
Emotet detection tool for Windows OS.
How EmoCheck detects Emotet
Emotet generates their process name from a specific word dictionary and C drive serial number. EmoCheck scans the running process on the host, and find Emotet process from their process name.
(added in v0.0.2)
Emotet keeps their encoded process name in a specific registry key. EmoCheck looks up and decode the registry value, and find it from the process list.
(added in v1.0)
Support the April 2020 updated of Emotet.
(added in v2.0)
Support the December 2020 updated of Emotet.
French language support. (Thanks to CERT-FR)
- fixed a detection pattern
How to use
- Download EmoCheck from the Releases page.
- Run EmoCheck on the host.
- Check the exported report.
The report will be exported to the following path.
- [path of emocheck.exe]\yyyymmddhhmmss_emocheck.txt
Copyright (C) 2020 JPCERT Coordination Center. All Rights Reserved.