cyber_threat_intelligence/actors/Emotet
2022-04-01 12:05:45 +02:00
..
README.md Update 2022-04-01 12:05:45 +02:00

Emotet - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Emotet. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.emotet

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Emotet:

There are 2 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Emotet.

ID IP address Hostname Campaign Confidence
1 1.186.249.82 1.186.249.82.dvois.com - High
2 1.226.84.243 - - High
3 1.234.2.232 - - High
4 1.234.21.73 - - High
5 2.47.112.152 net-2-47-112-152.cust.vodafonedsl.it - High
6 2.58.16.86 - - High
7 2.58.16.89 - - High
8 2.82.75.215 bl21-75-215.dsl.telepac.pt - High
9 5.2.84.232 momos.alastyr.com - High
10 5.2.136.90 static-5-2-136-90.rdsnet.ro - High
11 5.2.182.7 static-5-2-182-7.rdsnet.ro - High
12 5.2.212.254 static-5-2-212-254.rdsnet.ro - High
13 5.9.116.246 static.246.116.9.5.clients.your-server.de - High
14 5.9.128.163 static.163.128.9.5.clients.your-server.de - High
15 5.9.189.24 static.24.189.9.5.clients.your-server.de - High
16 5.12.246.155 5-12-246-155.residential.rdsnet.ro - High
17 5.35.249.46 rs250366.rs.hosteurope.de - High
18 5.39.84.48 ns3126815.ip-5-39-84.eu - High
19 5.39.91.110 ns3278366.ip-5-39-91.eu - High
20 5.79.70.250 - - High
21 5.89.33.136 net-5-89-33-136.cust.vodafonedsl.it - High
22 5.101.138.188 uk.mthservers.com - High
23 5.159.57.195 www-riedle.transfermarkt.de - High
24 5.196.35.138 vps10.open-techno.net - High
25 5.196.73.150 ns3000085.ip-5-196-73.eu - High
26 5.230.193.41 casagarcia-web.sys.netzfabrik.eu - High
27 8.4.9.137 onlinehorizons.net - High
28 8.247.6.134 - - High
29 12.6.183.21 - - High
30 12.32.68.154 mail.sealscoinc.com - High
31 12.149.72.170 - - High
32 12.162.84.2 - - High
33 12.163.208.58 - - High
34 12.182.146.226 - - High
35 12.184.217.101 - - High
36 12.222.134.10 - - High
37 12.238.114.130 - - High
38 23.6.65.194 a23-6-65-194.deploy.static.akamaitechnologies.com - High
39 23.36.85.183 a23-36-85-183.deploy.static.akamaitechnologies.com - High
40 23.199.63.11 a23-199-63-11.deploy.static.akamaitechnologies.com - High
41 23.199.71.185 a23-199-71-185.deploy.static.akamaitechnologies.com - High
42 23.239.2.11 li683-11.members.linode.com - High
43 23.254.203.51 hwsrv-779084.hostwindsdns.com - High
44 24.40.239.62 24-40-239-62.fidnet.com - High
45 24.43.99.75 rrcs-24-43-99-75.west.biz.rr.com - High
46 24.101.229.82 dynamic-acs-24-101-229-82.zoominternet.net - High
47 24.119.116.230 24-119-116-230.cpe.sparklight.net - High
48 24.121.176.48 24-121-176-48.prkrcmtc01.com.sta.suddenlink.net - High
49 24.137.76.62 host-24-137-76-62.public.eastlink.ca - High
50 24.178.90.49 024-178-090-049.res.spectrum.com - High
51 24.179.13.119 024-179-013-119.res.spectrum.com - High
52 24.201.79.34 modemcable034.79-201-24.mc.videotron.ca - High
53 24.217.117.217 024-217-117-217.res.spectrum.com - High
54 24.232.228.233 OL233-228.fibertel.com.ar - High
55 24.244.177.40 - - High
56 27.50.89.209 27-50-89-209.as45671.net - High
57 27.78.27.110 localhost - High
58 27.82.13.10 KD027082013010.ppp-bb.dion.ne.jp - High
59 27.109.24.214 - - High
60 27.114.9.93 i27-114-9-93.s41.a011.ap.plala.or.jp - High
61 31.24.158.56 bm.servidoresdedicados.com - High
62 31.167.248.50 - - High
63 35.190.87.116 116.87.190.35.bc.googleusercontent.com - Medium
64 36.91.44.183 - - High
65 37.46.129.215 we-too.ru - High
66 37.97.135.82 37-97-135-82.colo.transip.net - High
67 37.120.175.15 v220220112692175454.nicesrv.de - High
68 37.139.21.175 37.139.21.175-e2-8080-keep-up - High
69 37.179.204.33 - - High
70 37.187.4.178 ks2.kku.io - High
71 37.187.57.57 ns3357940.ovh.net - High
72 37.187.72.193 ns3362285.ip-37-187-72.eu - High
73 37.187.161.206 toolbox.alabs.io - High
74 37.205.9.252 s1.ithelp24.eu - High
75 37.221.70.250 b2b-customer.inftele.net - High
76 41.76.108.46 - - High
77 41.169.36.237 - - High
78 41.185.28.84 brf01-nix01.wadns.net - High
79 41.185.29.128 abp79-nix01.wadns.net - High
80 41.231.225.139 - - High
81 42.62.40.103 - - High
82 45.16.226.117 45-16-226-117.lightspeed.sndgca.sbcglobal.net - High
83 45.33.77.42 li1023-42.members.linode.com - High
84 45.46.37.97 cpe-45-46-37-97.maine.res.rr.com - High
85 45.55.36.51 - - High
86 45.55.219.163 - - High
87 45.79.95.107 li1194-107.members.linode.com - High
88 45.80.148.200 - - High
89 45.118.115.99 - - High
90 45.118.135.203 45-118-135-203.ip.linodeusercontent.com - High
91 45.142.114.231 mail.dounutmail.de - High
92 45.176.232.124 - - High
93 45.230.45.171 - - High
94 46.4.100.178 support.wizard-shopservice.de - High
95 46.4.192.185 static.185.192.4.46.clients.your-server.de - High
96 46.28.111.142 enkindu.jsuchy.net - High
97 46.32.229.152 094882.vps-10.com - High
98 46.32.233.226 yetitoolusa.com - High
99 46.38.238.8 v2202109122001163131.happysrv.de - High
100 46.43.2.95 chris.default.cjenkinson.uk0.bigv.io - High
101 46.55.222.11 - - High
102 46.101.58.37 46.101.58.37-e1-8080 - High
103 46.105.81.76 myu0.cylipo.sbs - High
104 46.105.114.137 ns3188253.ip-46-105-114.eu - High
105 46.105.131.68 http.adven.fr - High
106 46.105.131.69 epouventaille.adven.fr - High
107 46.105.131.79 relay.adven.fr - High
108 46.105.131.87 pop.adven.fr - High
109 46.105.236.18 - - High
110 46.165.212.76 - - High
111 46.165.254.206 - - High
112 46.214.107.142 46-214-107-142.next-gen.ro - High
113 47.36.140.164 047-036-140-164.res.spectrum.com - High
114 47.146.39.147 - - High
115 47.150.11.161 - - High
116 47.188.131.94 - - High
117 47.201.208.154 - - High
118 47.246.24.225 - - High
119 47.246.24.226 - - High
120 47.246.24.230 - - High
121 47.246.24.232 - - High
122 49.12.121.47 filezilla-project.org - High
123 49.50.209.131 131.host-49-50-209.euba.megatel.co.nz - High
124 49.212.135.76 os3-321-50322.vs.sakura.ne.jp - High
125 49.212.155.94 os3-325-52340.vs.sakura.ne.jp - High
126 50.28.51.143 - - High
127 50.30.40.196 usve255301.serverprofi24.com - High
128 50.31.146.101 mail.brillinjurylaw.com - High
129 50.56.135.44 - - High
130 50.62.194.30 ip-50-62-194-30.ip.secureserver.net - High
131 50.78.167.65 millcreek.cc - High
132 50.91.114.38 050-091-114-038.res.spectrum.com - High
133 50.92.101.60 d50-92-101-60.bchsia.telus.net - High
134 50.116.54.215 li440-215.members.linode.com - High
135 50.116.78.109 intersearchmedia.com - High
136 50.245.107.73 50-245-107-73-static.hfc.comcastbusiness.net - High
137 51.15.4.22 51-15-4-22.rev.poneytelecom.eu - High
138 51.15.7.145 51-15-7-145.rev.poneytelecom.eu - High
139 51.38.201.19 ip19.ip-51-38-201.eu - High
140 51.75.33.120 ip120.ip-51-75-33.eu - High
141 51.75.33.127 ip127.ip-51-75-33.eu - High
142 51.89.36.180 ip180.ip-51-89-36.eu - High
143 51.89.199.141 ip141.ip-51-89-199.eu - High
144 51.91.7.5 ns3147667.ip-51-91-7.eu - High
145 51.91.76.89 89.ip-51-91-76.eu - High
146 51.159.35.157 51-159-35-157.rev.poneytelecom.eu - High
147 51.254.140.238 238.ip-51-254-140.eu - High
148 51.255.50.164 vps-b6cfe010.vps.ovh.net - High
149 51.255.165.160 160.ip-51-255-165.eu - High
150 52.66.202.63 ec2-52-66-202-63.ap-south-1.compute.amazonaws.com - Medium
151 54.38.143.245 tools.inovato.me - High
152 58.27.215.3 58-27-215-3.wateen.net - High
153 58.94.58.13 i58-94-58-13.s41.a014.ap.plala.or.jp - High
154 58.216.16.130 - - High
155 58.227.42.236 - - High
156 59.148.253.194 059148253194.ctinets.com - High
157 59.152.93.46 46.93.152.59.zipnetltd.com - High
158 60.93.23.51 softbank060093023051.bbtec.net - High
159 60.108.128.186 softbank060108128186.bbtec.net - High
160 60.125.114.64 softbank060125114064.bbtec.net - High
161 60.249.78.226 60-249-78-226.hinet-ip.hinet.net - High
162 61.19.246.238 - - High
163 62.30.7.67 67.7-30-62.static.virginmediabusiness.co.uk - High
164 62.75.141.82 static-ip-62-75-141-82.inaddr.ip-pool.com - High
165 62.84.75.50 mail.saadegrp.com.lb - High
166 62.171.142.179 vmi499457.contaboserver.net - High
167 62.212.34.102 - - High
168 64.71.36.11 - - High
169 64.190.63.136 - - High
170 64.207.182.168 - - High
171 66.23.200.58 - - High
172 66.50.57.73 66-50-57-73.prtc.net - High
173 66.54.51.172 - - High
174 66.76.26.33 66-76-26-33.hdsncmta01.com.sta.suddenlink.net - High
175 66.209.69.165 - - High
176 66.228.32.31 li282-31.members.linode.com - High
177 66.228.61.248 li318-248.members.linode.com - High
178 67.19.105.107 ns2.datatrust.com.br - High
179 67.170.250.203 c-67-170-250-203.hsd1.ca.comcast.net - High
180 67.225.218.50 lb01.parklogic.com - High
181 68.2.97.91 ip68-2-97-91.ph.ph.cox.net - High
182 68.183.170.114 68.183.170.114-e1-8080-keep-up - High
183 68.183.190.199 68.183.190.199-e1-8080-keep-up - High
184 69.17.170.58 unallocated-static.rogers.com - High
185 69.43.168.200 ns0.imunplugged.com - High
186 69.43.168.232 - - High
187 69.45.19.251 coastinet.com - High
188 69.163.33.82 - - High
189 69.167.152.111 - - High
190 69.198.17.20 69-198-17-20.customerip.birch.net - High
191 69.198.17.49 69-198-17-49.customerip.birch.net - High
192 70.32.84.74 - - High
193 70.32.89.105 parties-at-sea.com - High
194 70.32.92.133 popdesigngroup.com - High
195 70.32.115.157 harpotripofalifetime.com - High
196 70.36.102.35 - - High
197 70.45.30.28 dynamic.libertypr.net - High
198 70.168.7.6 wsip-70-168-7-6.ri.ri.cox.net - High
199 70.182.77.184 wsip-70-182-77-184.ok.ok.cox.net - High
200 70.183.113.54 wsip-70-183-113-54.no.no.cox.net - High
201 70.184.125.132 wsip-70-184-125-132.ph.ph.cox.net - High
202 71.8.1.188 071-008-001-188.res.spectrum.com - High
203 71.15.245.148 071-015-245-148.res.spectrum.com - High
204 71.40.213.82 rrcs-71-40-213-82.sw.biz.rr.com - High
205 71.58.165.119 c-71-58-165-119.hsd1.pa.comcast.net - High
206 71.71.3.84 - - High
207 71.163.171.106 static-71-163-171-106.washdc.fios.verizon.net - High
208 71.165.252.144 static-71-165-252-144.lsanca.fios.frontiernet.net - High
209 71.177.184.128 static-71-177-184-128.lsanca.fios.frontiernet.net - High
210 71.197.211.156 c-71-197-211-156.hsd1.wa.comcast.net - High
211 71.214.17.130 71-214-17-130.orlf.qwest.net - High
212 ... ... ... ...

There are 843 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Emotet. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1008 CWE-757 Algorithm Downgrade High
2 T1040 CWE-294 Authentication Bypass by Capture-replay High
3 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
4 ... ... ... ...

There are 8 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Emotet. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File /admin.php/admin/plog/index.html High
2 File /admin.php/admin/ulog/index.html High
3 File /admin.php/admin/vod/data.html High
4 File /admin.php/admin/website/data.html High
5 File /admin/login.php High
6 File /admin/show.php High
7 File /api/fetch Medium
8 File /cgi-bin/uploadAccessCodePic High
9 File /cgi-bin/uploadWeiXinPic High
10 File /config/list Medium
11 File /data/sqldata High
12 File /goform/delAd High
13 File /goform/exeCommand High
14 File /goform/setAdInfoDetail High
15 File /goform/setFixTools High
16 File /goform/SetInternetLanInfo High
17 File /goform/SetLanInfo High
18 File /goform/setPicListItem High
19 File /goform/setWorkmode High
20 File /goform/WriteFacMac High
21 File /index.php?act=api&tag=8 High
22 ... ... ...

There are 186 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2022 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!