APT_CyberCriminal_Campagin_.../2023/2023.01.09.Emotet_return/INTRINSEC_MLW_EMOTET_IOCs_09_01_2023.csv
2024-01-12 17:20:43 +08:00

28 KiB

1TypeIndicatorDescriptionAttributionTLP
2urlhttps[:]//cs.com.sg/Backup/Bk778kXNKMiH5vH/oxnv1.ooccxxHardcoded URL hidden in XLS file sheet 6 pointing at a dropper. The host is a compromised server with a CMS wordpress.EmotetGREEN
3urlhttps[:]//j2ccamionmagasin.fr/css/1Mp8y/oxnv2.ooccxxHardcoded URL hidden in XLS file sheet 6 pointing at a dropper. The host is a compromised server with a CMS wordpress.EmotetGREEN
4urlhttp[:]//atici.net/old/PkZI74DD/oxnv3.ooccxxHardcoded URL hidden in XLS file sheet 6 pointing at a dropper. The host is a compromised server with a CMS wordpress.EmotetGREEN
5urlhttp[:]//clanbaker.org/css/khhl7kT2n69n/oxnv4.ooccxxHardcoded URL hidden in XLS file sheet 6 pointing at a dropper. The host is a compromised server with a CMS wordpress.EmotetGREEN
6domainspkdeutshnewsupp[.]com We observed several IcedID samples dropped by Emotet communicating with this domain. The latter resolves 87.251.67[.]168EmotetGREEN
7sha256910731579a78d2da6452bede7dfce8e1f89c285c22d8a7d40db2eafc2fcc45afHijacked thread email sent by Emotet botnet with a malicious XLS attachmentEmotetGREEN
8sha25691E19D7AEFDD6717A1F79167281E78B95AFB84195BA7525F5EFB6E0A3665AC6BXLS maldoc downloading DLLs on remote compromised server via macros 4.0EmotetGREEN
9sha256199a2e0e1bb46a5dd8eb3a58aa55de157f6005c65b70245e71cecec4905cc2c0 Excel file with malicious macro for Emotet dropped IcedID and BumbleBeeEmotetGREEN
10sha256e59c11ed62c813d1c19e02277e14bbeff0312440b4fdc235d3bcbfe1938743b6 dll downloaded from the URLs integrated in Emotet macros EmotetGREEN
11sha25609931bd43b6b1d5f664d4ea3b7d3b78a2e4a2e67a958032ea92640835d7b9f8fdll downloaded from the URLs integrated in Emotet macros EmotetGREEN
12sha256ce2f3dddfce26433d18f020c8a3337d39d6d2af1eba61967db9be8359bf19fb1dll downloaded from the URLs integrated in Emotet macros EmotetGREEN
13sha25636a2e445f25b38c95129260794ec0973b44f52ec69e8b819cf799fdab76319b5dll downloaded from the URLs integrated in Emotet macros EmotetGREEN
14sha1a7e30946af32f0087bbee19dcb908fce2d9e6814Hijacked thread email sent by Emotet botnet with a malicious XLS attachmentEmotetGREEN
15sha164AF6F0E006D740601A92816D4EEF1F7B6007B89XLS maldoc downloading DLLs on remote compromised server via macros 4.0EmotetGREEN
16sha1a6e306f8841ff6fbd50188c738469143a6934df0Excel file with malicious macro for Emotet dropped IcedID and BumbleBeeEmotetGREEN
17sha1ac5ad5ff7434c1ecbc3c96fcfc530a9f98f64a5e dll downloaded from the URLs integrated in Emotet macros EmotetGREEN
18sha1f8a58b9737cef1223e6cab7839f0921ab791317edll downloaded from the URLs integrated in Emotet macros EmotetGREEN
19sha191f1cabf131ca0dccd8180b6faed2fea24ffcddddll downloaded from the URLs integrated in Emotet macros EmotetGREEN
20sha1d7412689e7f0df8f3425ffaf2a0ac5176202b9c3dll downloaded from the URLs integrated in Emotet macros EmotetGREEN
21md5154014e2aec1638d8feb1c3900752a60Hijacked thread email sent by Emotet botnet with a malicious XLS attachmentEmotetGREEN
22md59DDFCFE774CBFA02FB31E36B819D7D91XLS maldoc downloading DLLs on remote compromised server via macros 4.0EmotetGREEN
23md56493581b246b731e4937fbee64a68803Excel file with malicious macro for Emotet dropped IcedID and BumbleBeeEmotetGREEN
24md5a856da67745c9910bb6efd1a63755f3b dll downloaded from the URLs integrated in Emotet macros EmotetGREEN
25md55240ba05dc7e3179ab47487be788910edll downloaded from the URLs integrated in Emotet macros EmotetGREEN
26md5ef0229e461dd8e1475537a44e3bfe3f6dll downloaded from the URLs integrated in Emotet macros EmotetGREEN
27md56886babbe16ed7b5a8c84d54d2f9ca3edll downloaded from the URLs integrated in Emotet macros EmotetGREEN
28ip202.28.34.99web server with associated IP address 202.28.34.99 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
29ip80.211.107.116web server with associated IP address 80.211.107.116 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
30ip175.126.176.79web server with associated IP address 175.126.176.79 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
31ip218.38.121.17web server with associated IP address 218.38.121.17 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
32ip139.196.72.155web server with associated IP address 139.196.72.155 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
33ip103.71.99.57web server with associated IP address 103.71.99.57 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
34ip87.106.97.83web server with associated IP address 87.106.97.83 used as a proxy listening on port 7080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
35ip178.62.112.199web server with associated IP address 178.62.112.199 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
36ip64.227.55.231web server with associated IP address 64.227.55.231 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
37ip46.101.98.60web server with associated IP address 46.101.98.60 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
38ip54.37.228.122web server with associated IP address 54.37.228.122 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
39ip128.199.217.206web server with associated IP address 128.199.217.206 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
40ip190.145.8.4web server with associated IP address 190.145.8.4 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
41ip209.239.112.82web server with associated IP address 209.239.112.82 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
42ip85.214.67.203web server with associated IP address 85.214.67.203 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
43ip198.199.70.22web server with associated IP address 198.199.70.22 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
44ip128.199.242.164web server with associated IP address 128.199.242.164 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
45ip178.238.225.252web server with associated IP address 178.238.225.252 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
46ip103.85.95.4web server with associated IP address 103.85.95.4 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
47ip103.126.216.86web server with associated IP address 103.126.216.86 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
48ip104.244.79.94web server with associated IP address 104.244.79.94 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
49ip36.67.23.59web server with associated IP address 36.67.23.59 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
50ip37.44.244.177web server with associated IP address 37.44.244.177 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
51ip160.16.143.191web server with associated IP address 160.16.143.191 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
52ip85.25.120.45web server with associated IP address 85.25.120.45 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
53ip103.56.149.105web server with associated IP address 103.56.149.105 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
54ip210.57.209.142web server with associated IP address 210.57.209.142 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
55ip195.77.239.39web server with associated IP address 195.77.239.39 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
56ip62.171.178.147web server with associated IP address 62.171.178.147 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
57ip118.98.72.86web server with associated IP address 118.98.72.86 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
58ip103.224.241.74web server with associated IP address 103.224.241.74 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
59ip185.148.169.10web server with associated IP address 185.148.169.10 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
60ip103.41.204.169web server with associated IP address 103.41.204.169 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
61ip186.250.48.5web server with associated IP address 186.250.48.5 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
62ip165.22.254.236web server with associated IP address 165.22.254.236 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
63ip93.104.209.107web server with associated IP address 93.104.209.107 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
64ip139.59.80.108web server with associated IP address 139.59.80.108 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
65ip196.44.98.190web server with associated IP address 196.44.98.190 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
66ip114.79.130.68web server with associated IP address 114.79.130.68 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
67ip115.178.55.22web server with associated IP address 115.178.55.22 used as a proxy listening on port 80 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
68ip103.254.12.236web server with associated IP address 103.254.12.236 used as a proxy listening on port 7080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
69ip172.105.115.71web server with associated IP address 172.105.115.71 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
70ip174.138.33.49web server with associated IP address 174.138.33.49 used as a proxy listening on port 7080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
71ip51.75.33.122web server with associated IP address 51.75.33.122 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
72ip83.229.80.93web server with associated IP address 83.229.80.93 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
73ip78.47.204.80web server with associated IP address 78.47.204.80 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
74ip188.165.79.151web server with associated IP address 188.165.79.151 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
75ip202.134.4.210web server with associated IP address 202.134.4.210 used as a proxy listening on port 7080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
76ip82.98.180.154web server with associated IP address 82.98.180.154 used as a proxy listening on port 7080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
77ip185.4.135.165web server with associated IP address 185.4.135.165 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
78ip159.89.202.34web server with associated IP address 159.89.202.34 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
79ip82.223.21.224web server with associated IP address 82.223.21.224 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
80ip187.63.160.88web server with associated IP address 187.63.160.88 used as a proxy listening on port 80 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
81ip188.44.20.25web server with associated IP address 188.44.20.25 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
82ip91.187.140.35web server with associated IP address 91.187.140.35 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
83ip110.232.117.186web server with associated IP address 110.232.117.186 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
84ip197.242.150.244web server with associated IP address 197.242.150.244 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
85ip119.59.103.152web server with associated IP address 119.59.103.152 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
86ip182.162.143.56web server with associated IP address 182.162.143.56 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
87ip72.15.201.15web server with associated IP address 72.15.201.15 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
88ip173.255.211.88web server with associated IP address 173.255.211.88 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
89ip206.189.28.199web server with associated IP address 206.189.28.199 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
90ip94.23.45.86web server with associated IP address 94.23.45.86 used as a proxy listening on port 4143 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
91ip45.63.99.23web server with associated IP address 45.63.99.23 used as a proxy listening on port 7080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
92ip153.126.146.25web server with associated IP address 153.126.146.25 used as a proxy listening on port 7080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
93ip45.118.115.99web server with associated IP address 45.118.115.99 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
94ip115.68.227.76web server with associated IP address 115.68.227.76 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
95ip163.44.196.120web server with associated IP address 163.44.196.120 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
96ip159.65.140.115web server with associated IP address 159.65.140.115 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
97ip169.57.156.166web server with associated IP address 169.57.156.166 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
98ip139.59.56.73web server with associated IP address 139.59.56.73 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
99ip183.111.227.137web server with associated IP address 183.111.227.137 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
100ip202.129.205.3web server with associated IP address 202.129.205.3 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
101ip103.43.75.120web server with associated IP address 103.43.75.120 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
102ip45.176.232.124web server with associated IP address 45.176.232.124 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
103ip186.194.240.217web server with associated IP address 186.194.240.217 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
104ip173.212.193.249web server with associated IP address 173.212.193.249 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
105ip139.59.126.41web server with associated IP address 139.59.126.41 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
106ip149.56.131.28web server with associated IP address 149.56.131.28 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
107ip159.65.88.10web server with associated IP address 159.65.88.10 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
108ip201.94.166.162web server with associated IP address 201.94.166.162 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
109ip107.170.39.149web server with associated IP address 107.170.39.149 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
110ip103.75.201.2web server with associated IP address 103.75.201.2 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
111ip103.132.242.26web server with associated IP address 103.132.242.26 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
112ip209.97.163.214web server with associated IP address 209.97.163.214 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
113ip129.232.188.93web server with associated IP address 129.232.188.93 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
114ip79.137.35.198web server with associated IP address 79.137.35.198 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
115ip101.50.0.91web server with associated IP address 101.50.0.91 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
116ip147.139.166.154web server with associated IP address 147.139.166.154 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
117ip160.16.142.56web server with associated IP address 160.16.142.56 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
118ip153.92.5.27web server with associated IP address 153.92.5.27 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
119ip167.172.199.165web server with associated IP address 167.172.199.165 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
120ip95.217.221.146web server with associated IP address 95.217.221.146 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
121ip167.172.253.162web server with associated IP address 167.172.253.162 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
122ip164.90.222.65web server with associated IP address 164.90.222.65 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
123ip172.105.226.75web server with associated IP address 172.105.226.75 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
124ip164.68.99.3web server with associated IP address 164.68.99.3 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
125ip213.239.212.5web server with associated IP address 213.239.212.5 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
126ip91.207.28.33web server with associated IP address 91.207.28.33 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
127ip45.235.8.30web server with associated IP address 45.235.8.30 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
128ip172.104.251.154web server with associated IP address 172.104.251.154 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
129ip5.135.159.50web server with associated IP address 5.135.159.50 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
130ip212.24.98.99web server with associated IP address 212.24.98.99 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
131ip104.168.155.143web server with associated IP address 104.168.155.143 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
132ip1.234.2.232web server with associated IP address 1.234.2.232 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
133ip169.60.181.70web server with associated IP address 169.60.181.70 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
134ip149.28.143.92web server with associated IP address 149.28.143.92 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
135ip51.161.73.194web server with associated IP address 51.161.73.194 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch4EmotetGREEN
136ip172.105.115.71web server with associated IP address 172.105.115.71 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
137ip185.184.25.78web server with associated IP address 185.184.25.78 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
138ip191.252.103.16web server with associated IP address 191.252.103.16 used as a proxy listening on port 80 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
139ip207.148.81.119web server with associated IP address 207.148.81.119 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
140ip37.59.209.141web server with associated IP address 37.59.209.141 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
141ip59.148.253.194web server with associated IP address 59.148.253.194 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
142ip159.69.237.188web server with associated IP address 159.69.237.188 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
143ip195.154.146.35web server with associated IP address 195.154.146.35 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
144ip203.153.216.46web server with associated IP address 203.153.216.46 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
145ip104.131.62.48web server with associated IP address 104.131.62.48 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
146ip173.203.78.138web server with associated IP address 173.203.78.138 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
147ip217.182.143.207web server with associated IP address 217.182.143.207 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
148ip54.38.242.185web server with associated IP address 54.38.242.185 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
149ip116.124.128.206web server with associated IP address 116.124.128.206 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
150ip54.37.106.167web server with associated IP address 54.37.106.167 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
151ip198.199.98.78web server with associated IP address 198.199.98.78 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
152ip190.90.233.66web server with associated IP address 190.90.233.66 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
153ip185.148.168.15web server with associated IP address 185.148.168.15 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
154ip185.148.168.220web server with associated IP address 185.148.168.220 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
155ip142.4.219.173web server with associated IP address 142.4.219.173 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
156ip168.197.250.14web server with associated IP address 168.197.250.14 used as a proxy listening on port 80 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
157ip128.199.192.135web server with associated IP address 128.199.192.135 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
158ip78.46.73.125web server with associated IP address 78.46.73.125 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
159ip66.42.57.149web server with associated IP address 66.42.57.149 used as a proxy listening on port 443 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN
160ip194.9.172.107web server with associated IP address 194.9.172.107 used as a proxy listening on port 8080 hidding network traffic towards genuine C2 linked to botnet Epoch5EmotetGREEN