Emotet - Indicators of Compromise

Last updated: 2026-05-10

C2 IP Addresses (100)

62.84.75.50
60.93.23.51
45.46.37.97
85.25.106.204
80.241.255.202
69.206.132.149
5.196.108.189
169.50.76.149
130.0.132.242
96.245.227.43
94.230.70.6
91.146.156.228
89.121.205.18
88.153.35.32
86.123.55.0
85.246.78.192
78.188.106.53
76.18.16.210
76.175.162.101
75.143.247.51
74.214.230.200
72.186.136.247
72.143.73.234
71.15.245.148
68.115.186.26
67.163.161.107
66.76.12.94
61.76.222.210
61.33.119.226
59.125.219.109
5.2.246.108
5.189.168.53
49.50.209.131
49.3.224.99
47.36.140.164
41.40.125.237
37.179.204.33
27.114.9.93
24.230.141.169
24.133.106.23
218.147.193.146
217.123.207.149
209.54.13.14
209.141.54.221
202.188.218.82
200.243.153.66
200.120.241.238
2.85.9.41
2.144.244.204
197.245.25.228
191.97.154.2
190.164.104.62
190.162.215.233
190.12.119.180
190.108.228.27
190.101.48.116
188.80.27.54
186.70.56.94
185.63.32.149
184.180.181.202
182.208.30.18
181.59.59.54
181.56.32.36
180.26.62.115
177.130.51.198
176.113.52.6
173.68.199.157
173.63.222.65
173.212.214.235
173.212.197.71
172.193.79.237
162.241.140.129
154.91.33.137
123.142.37.166
117.247.235.44
107.170.146.252
104.156.59.7
103.48.68.173
102.182.93.220
96.249.236.156
94.124.59.22
94.1.108.190
85.96.199.93
78.187.156.31
75.80.124.4
74.219.172.26
74.135.120.91
74.134.41.124
68.252.26.78
67.10.155.92
66.65.136.14
24.43.32.186
216.139.123.119
200.127.14.97
195.7.12.8
192.175.111.214
191.191.23.135
186.222.250.115
181.169.235.7
175.143.12.123

Malicious URLs (50)

http://101.43.204.194:8080/g64.exe
http://62.60.226.97:5553/onetwo.exe
https://7070-ppxcx-a1-3gg5ufwp666ee644-1300076834.tcb.qcloud.la/test/zcgo/go.exe
http://103.96.75.2:17705/good.cc
http://103.96.75.2:17705/good.exe
http://84.21.189.158:5554/st.exe
http://52.230.23.114/secur32.dll
https://raw.githubusercontent.com/C5Hackr/Phantom/main/Phantom/Resources/UAC64.dll
https://raw.githubusercontent.com/C5Hackr/Phantom/main/Phantom/Resources/UAC.dll
http://66.63.187.190/work/addon.exe
http://185.156.72.2/newdef/random.exe
https://coadymarine.com/Admin/6c3YBqOLiPE1SyTMf/
https://dhnconstrucciones.com.ar/wp-admin/Sm02ZsVDYWdoTb7rqL/
http://20.151.75.185/Invoice_Final.exe
http://20.151.75.185/svchost.exe
https://jobcity.com/img/RM0XpX/
https://exilum.com/homegrownorlando.com/closed-section/additional-area/740331365-R4cXbyqTk/
https://www.reifenquick.de/Scripts/statement/ul397wfyb/
https://reifenquick.de/Scripts/hl8-8w4cs-6325/
https://www.reifenquick.de/Scripts/closed_957176_mxqSdoJ6a4IZ/close_warehouse/ql55hnq09iyn6lm_334stxvw03wyv/
https://p20.zdusercontent.com/attachment/453903/WQC7f5S8Lhm8Mu0clzHwbl3Lp?token=eyJhbGciOiJkaXIiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0..kOK-C08tg1sb0RKWxYURVg.7Ptb2bEY9eTQRwRFE3gvZgP-gDCtW-nOKzBIRROWi-iwJtdMjfnTorAttitqoM-5EQrbhZPurovCMmMjXKs4knJpXBAhy0BahdWiDWtu6cUUCpoIGdW4L9jV2px7wSngjQoQp_dY8FpL_1z6J2No0Z_RRAwi5G3dj3VggkR-wCTHkNcZ5a8O6febbFfJIyC7Oij5oKn6O4jAnIS5qD7BtXoqQitdsIc5s2BdUud6OZSFSdjsc54sZpt2gg4zgz8iUAg3pv4APWyt_eO-Owc_8Q.o9d2OWTJtv0VOYQxIS2afQ
http://hunter.freshworx.com/et8_webservice/mail/attach/61EB0719-3A26-D60D-7630-B0A2084EEB02/684538_Rechnung_74700680333.doc
http://20.151.75.185/Invoice.exe
http://194.90.142.157/xlsx/xlsx008.xlsx
http://194.90.142.157/xlsx/xlsx006.xlsx
http://194.90.142.157/xlsx/xlsx010.xlsx
http://194.90.142.157/xlsx/xlsx003.xlsx
http://194.90.142.157/xlsx/xlsx009.xlsx
http://194.90.142.157/xlsx/xlsx007.xlsx
http://194.90.142.157/xlsx/xlsx005.xlsx
http://194.90.142.157/xlsx/xlsx002.xlsx
http://194.90.142.157/exe/exe009.exe
http://bitbucket.org/o1lov/repo1lov/downloads/KIDI.rar
https://giantowl.flywheelsites.com/wn1a0/build.exe
http://175.178.73.162/K346De4eeCaec750/update.exe
https://raw.githubusercontent.com/Ryan2159/Stuff/main/Discord.exe
http://147.45.44.104/prog/66c9d78d43c01_valensu.exe
http://147.45.44.104/prog/66c9d78d43c01_valensu.exe#space
https://asepridwan.net/vidar.exe
http://77.91.77.81/lend/ComeDraft.exe
https://bitbucket.org/o1lov/repo1lov/downloads/KIDI.rar
https://bitbucket.org/o1lov/repo1lov/downloads/KID.rar
http://54.90.216.100/icochange2.exe
http://gons14fc.top/build.exe
http://gobo13fc.top/build.exe
http://gons13fc.top/build.exe
http://gobo11fc.top/build.exe
http://gons12fc.top/build.exe
http://gons11fc.top/build.exe
https://www.dropbox.com/e/scl/fi/46jyvsv3hn2k974s5idwc/winscp_ver_6.1.1.msi?rlkey=twfq797tlx5xjlnc9tipnd24x&dl=1

SHA256 Hashes (1)

80553effec12cfea2d6f7bf8648e98a6b45635ac92906ebd2346a7f4ef9ac3a0

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)