
Emotet DLL Poses as Chinese AV, Beacons to Five-ASN C2 Pool
A 572-kilobyte unsigned Windows DLL masquerading as a Chinese-language antivirus product is actively targeting healthcare networks in Panama. The sample combines PE version-info spoofing, a Dridex-lineage JA3 TLS fingerprint, and a five-node command-and-control pool spread across Indonesian, Korean, German, and Polish autonomous systems to defeat signature, heuristic, and perimeter detection simultaneously.
A 572-kilobyte Windows DLL is circulating across healthcare networks in Panama wearing the identity of a Chinese-language antivirus product — its PE version-info fields stamped with the product name "MJAntiVirus.EXE," an internal name of "MJAntiVirus," and a copyright string reading "版权所有 (C) 2009." The file is unsigned, packed with PEiD, and carries a .rsrc section registering entropy at 7.75. It is, by unanimous verdict of six independent sandboxes, Emotet.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read