2018-03-01 - EMOTET ACTIVITY

NOTICE:

ASSOCIATED FILES:

NOTES:


Shown above:  Screenshot of the spreadsheet tracker.

 

WEB TRAFFIC BLOCK LIST

Indicators are not a block list.  If you feel the need to block web traffic, I suggest the following URLs:

 

EMAILS


Shown above:  Screenshot from one of the emails (1 of 3).

 


Shown above:  Screenshot from one of the emails (2 of 3).

 


Shown above:  Screenshot from one of the emails (3 of 3).

 

EMAIL HEADERS:

 


Shown above:  Example of a Word document downloaded from one of the email links.

 

TRAFFIC


Shown above:  Infection traffic filtered in Wireshark.

 

TRAFFIC FROM AN INFECTED WINDOWS HOST:

 

FILE HASHES

MALWARE FROM AN INFECTED WINDOWS HOST:

 

IMAGES


Shown above:  Emotet binary persistent on the infected Windows host.

 


Shown above:  Follow-up malware seen during an Emotet infection.

 

Click here to return to the main page.