Emotet - один из самых опасных троянов, когда-либо созданных. За время своего существования он был усовершенствован и превратился в очень разрушительную вредоносную программу. Его жертвами становятся в основном корпоративные пользователи, но даже частные пользователи заражаются в ходе массовых спам-рассылок.
Emotet Botnet
Indicators of Compromise
Domains
- aacl.co.in
- balibuli.hu
- baykusoglu.com.tr
- napolni.me
- sigratech.de
- tlaxcala.gob.mx
- webbandi.huzonainformatica.es
URLs
- http://1.234.2.232:8080
- http://101.50.0.91:8080
- http://103.132.242.26:8080
- http://103.43.75.120:443
- http://103.70.28.102:8080
- http://103.75.201.2:443
- http://104.168.155.143:8080
- http://107.170.39.149:8080
- http://110.232.117.186:8080
- http://115.68.227.76:8080
- http://119.193.124.41:7080
- http://129.232.188.93:443
- http://131.100.24.231:80
- http://134.122.66.193:8080
- http://139.59.126.41:443
- http://144.202.108.116:8080
- http://146.59.226.45:443
- http://147.139.166.154:8080
- http://149.56.131.28:8080
- http://150.95.66.124:8080
- http://151.106.112.196:8080
- http://153.126.146.25:7080
- http://158.69.222.101:443
- http://159.65.140.115:443
- http://159.65.88.10:8080
- http://159.89.202.34:443
- http://160.16.142.56:8080
- http://163.44.196.120:8080
- http://164.68.99.3:8080
- http://164.90.222.65:443
- http://167.172.253.162:8080
- http://172.104.251.154:8080
- http://172.105.226.75:8080
- http://173.212.193.249:8080
- http://183.111.227.137:8080
- http://185.4.135.165:8080
- http://186.194.240.217:443
- http://188.44.20.25:443
- http://196.218.30.83:443
- http://197.242.150.244:8080
- http://201.94.166.162:443
- http://206.189.28.199:8080
- http://207.148.79.14:8080
- http://209.126.98.206:8080
- http://209.97.163.214:443
- http://212.24.98.99:8080
- http://213.239.212.5:443
- http://213.241.20.155:443
- http://37.187.115.122:8080
- http://45.118.115.99:8080
- http://45.176.232.124:443
- http://45.235.8.30:8080
- http://5.9.116.246:8080
- http://51.161.73.194:443
- http://51.254.140.238:7080
- http://51.91.76.89:8080
- http://64.227.100.222:8080
- http://72.15.201.15:8080
- http://79.137.35.198:8080
- http://82.165.152.127:8080
- http://82.223.21.224:8080
- http://91.207.28.33:8080
- http://94.23.45.86:4143
- http://aacl.co.in/images/zZMVn05EJDpTcQ/
- http://balibuli.hu/galeria/ArPQKNsnvuW/
- http://baykusoglu.com.tr/wp-admin/0o
- http://induvit.tlaxcala.gob.mx/components/CFZUmiQTd367H4nH/
- http://sigratech.de/career/sRpMMHief7H/
- http://webbandi.hu/image/Ifm98UCtROXr/
- http://zonainformatica.es/aspnet_client/n0ULlfoAHHQh9tagckL/
- https://napolni.me/3r/ILq7TqCUS/
Emails
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
MD5
- 0a553775cc4d25bd8448baf913057efc
- 18907eebc1c95764ed9ca8a85f8fae13
- 1cbaa77b6c2c91fdc6f2f20ea8b14c05
- 2a21978635ab1827c7bb05f62d422537
- 5f885d862679351abde14c5e6e837644
- 6a2657048199ec48a46ec00fe3236f0e
- 74ef5e3aabefe58a018e7c5d1a532bd7
- 7501b0d6080bfba92cd33e43edd61277
- a6f8a8aec6ddc869693f3ffbaa80b8a7
- afc776b02c9cdf0716d1d01c511ab870
- b2cd142cb4b9b15953245f2f050f4ee7
- c3d71f860c941fb9a4a16f5b1ebf0c34