{"schema":"aeternae-malware-metadata/v1","generated_at":"2026-10-08T07:55:20+00:00","total_matching":1,"page":1,"page_size":200,"records":[{"id":"82ca61859958f34c553b142c6253e7112afc2459baf245e8b6f02aeab2e81cff","kind":"reference","title":"Emotet - S0367","family":"Emotet - S0367","category":"Malware intelligence","summary":"Name of ATT&CK software | [Emotet](https://attack.mitre.org/software/S0367) is a modular malware variant which is primarily used as a downloader for other malware variants such as [TrickBot](https://attack.mitre.org/software/S0266) and [IcedID](https://attack.mitre.org/software/S0483). Emotet first emerged in June 2014 and has been primarily used to target the banking sector. (Citation: Trend Micr","first_seen":1679512050,"last_seen":1679512050,"created_at":1791434197,"updated_at":1791434197,"source_count":1,"data":{"context":"2023/03/emotet-switches-to-onenote.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"Emotet - S0367\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2023/03/emotet-switches-to-onenote.json"],"filenames":[],"features":[],"related_cves":[],"labels":["Emotet - S0367"]},"observations":[{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2023/03/emotet-switches-to-onenote.json","source_label":"Emotet - S0367","evidence_class":"provider_reported","confidence":null,"observed_at":1679512050,"fetched_at":1791434197,"data":{"context":"2023/03/emotet-switches-to-onenote.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"Emotet - S0367\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2023/03/emotet-switches-to-onenote.json"],"family":"Emotet - S0367"}}],"indicators":[]}]}