Emotet - Indicators of Compromise
Last updated: 2026-05-10
C2 IP Addresses (100)
62.84.75.50 60.93.23.51 45.46.37.97 85.25.106.204 80.241.255.202 69.206.132.149 5.196.108.189 169.50.76.149 130.0.132.242 96.245.227.43 94.230.70.6 91.146.156.228 89.121.205.18 88.153.35.32 86.123.55.0 85.246.78.192 78.188.106.53 76.18.16.210 76.175.162.101 75.143.247.51 74.214.230.200 72.186.136.247 72.143.73.234 71.15.245.148 68.115.186.26 67.163.161.107 66.76.12.94 61.76.222.210 61.33.119.226 59.125.219.109 5.2.246.108 5.189.168.53 49.50.209.131 49.3.224.99 47.36.140.164 41.40.125.237 37.179.204.33 27.114.9.93 24.230.141.169 24.133.106.23 218.147.193.146 217.123.207.149 209.54.13.14 209.141.54.221 202.188.218.82 200.243.153.66 200.120.241.238 2.85.9.41 2.144.244.204 197.245.25.228 191.97.154.2 190.164.104.62 190.162.215.233 190.12.119.180 190.108.228.27 190.101.48.116 188.80.27.54 186.70.56.94 185.63.32.149 184.180.181.202 182.208.30.18 181.59.59.54 181.56.32.36 180.26.62.115 177.130.51.198 176.113.52.6 173.68.199.157 173.63.222.65 173.212.214.235 173.212.197.71 172.193.79.237 162.241.140.129 154.91.33.137 123.142.37.166 117.247.235.44 107.170.146.252 104.156.59.7 103.48.68.173 102.182.93.220 96.249.236.156 94.124.59.22 94.1.108.190 85.96.199.93 78.187.156.31 75.80.124.4 74.219.172.26 74.135.120.91 74.134.41.124 68.252.26.78 67.10.155.92 66.65.136.14 24.43.32.186 216.139.123.119 200.127.14.97 195.7.12.8 192.175.111.214 191.191.23.135 186.222.250.115 181.169.235.7 175.143.12.123
Malicious URLs (50)
http://101.43.204.194:8080/g64.exe http://62.60.226.97:5553/onetwo.exe https://7070-ppxcx-a1-3gg5ufwp666ee644-1300076834.tcb.qcloud.la/test/zcgo/go.exe http://103.96.75.2:17705/good.cc http://103.96.75.2:17705/good.exe http://84.21.189.158:5554/st.exe http://52.230.23.114/secur32.dll https://raw.githubusercontent.com/C5Hackr/Phantom/main/Phantom/Resources/UAC64.dll https://raw.githubusercontent.com/C5Hackr/Phantom/main/Phantom/Resources/UAC.dll http://66.63.187.190/work/addon.exe http://185.156.72.2/newdef/random.exe https://coadymarine.com/Admin/6c3YBqOLiPE1SyTMf/ https://dhnconstrucciones.com.ar/wp-admin/Sm02ZsVDYWdoTb7rqL/ http://20.151.75.185/Invoice_Final.exe http://20.151.75.185/svchost.exe https://jobcity.com/img/RM0XpX/ https://exilum.com/homegrownorlando.com/closed-section/additional-area/740331365-R4cXbyqTk/ https://www.reifenquick.de/Scripts/statement/ul397wfyb/ https://reifenquick.de/Scripts/hl8-8w4cs-6325/ https://www.reifenquick.de/Scripts/closed_957176_mxqSdoJ6a4IZ/close_warehouse/ql55hnq09iyn6lm_334stxvw03wyv/ https://p20.zdusercontent.com/attachment/453903/WQC7f5S8Lhm8Mu0clzHwbl3Lp?token=eyJhbGciOiJkaXIiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0..kOK-C08tg1sb0RKWxYURVg.7Ptb2bEY9eTQRwRFE3gvZgP-gDCtW-nOKzBIRROWi-iwJtdMjfnTorAttitqoM-5EQrbhZPurovCMmMjXKs4knJpXBAhy0BahdWiDWtu6cUUCpoIGdW4L9jV2px7wSngjQoQp_dY8FpL_1z6J2No0Z_RRAwi5G3dj3VggkR-wCTHkNcZ5a8O6febbFfJIyC7Oij5oKn6O4jAnIS5qD7BtXoqQitdsIc5s2BdUud6OZSFSdjsc54sZpt2gg4zgz8iUAg3pv4APWyt_eO-Owc_8Q.o9d2OWTJtv0VOYQxIS2afQ http://hunter.freshworx.com/et8_webservice/mail/attach/61EB0719-3A26-D60D-7630-B0A2084EEB02/684538_Rechnung_74700680333.doc http://20.151.75.185/Invoice.exe http://194.90.142.157/xlsx/xlsx008.xlsx http://194.90.142.157/xlsx/xlsx006.xlsx http://194.90.142.157/xlsx/xlsx010.xlsx http://194.90.142.157/xlsx/xlsx003.xlsx http://194.90.142.157/xlsx/xlsx009.xlsx http://194.90.142.157/xlsx/xlsx007.xlsx http://194.90.142.157/xlsx/xlsx005.xlsx http://194.90.142.157/xlsx/xlsx002.xlsx http://194.90.142.157/exe/exe009.exe http://bitbucket.org/o1lov/repo1lov/downloads/KIDI.rar https://giantowl.flywheelsites.com/wn1a0/build.exe http://175.178.73.162/K346De4eeCaec750/update.exe https://raw.githubusercontent.com/Ryan2159/Stuff/main/Discord.exe http://147.45.44.104/prog/66c9d78d43c01_valensu.exe http://147.45.44.104/prog/66c9d78d43c01_valensu.exe#space https://asepridwan.net/vidar.exe http://77.91.77.81/lend/ComeDraft.exe https://bitbucket.org/o1lov/repo1lov/downloads/KIDI.rar https://bitbucket.org/o1lov/repo1lov/downloads/KID.rar http://54.90.216.100/icochange2.exe http://gons14fc.top/build.exe http://gobo13fc.top/build.exe http://gons13fc.top/build.exe http://gobo11fc.top/build.exe http://gons12fc.top/build.exe http://gons11fc.top/build.exe https://www.dropbox.com/e/scl/fi/46jyvsv3hn2k974s5idwc/winscp_ver_6.1.1.msi?rlkey=twfq797tlx5xjlnc9tipnd24x&dl=1
SHA256 Hashes (1)
80553effec12cfea2d6f7bf8648e98a6b45635ac92906ebd2346a7f4ef9ac3a0
Data Sources
MalwareBazaar (abuse.ch) • ThreatFox (abuse.ch) • URLhaus (abuse.ch)