Unidentified JS 003 (Emotet Downloader)

First seen
2014-06-01 00:00:00
Malware type
downloader, dropper
Family
Malware family
Profile updated
2026-07-07 14:34:46

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical education-and-nonprofits

Context

According to Max Kersten, Emotet is dropped by a procedure spanned over multiple stages. The first stage is an office file that contains a macro. This macro then loads the second stage, which is either a PowerShell script or a piece of JavaScript, which is this family entry.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Js.Unidentified 003 (report)
  • maxkersten.nl — Emotet Javascript Downloader (report)

External references