s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

AI-IOC-995c55a82271 medium

📛 Threat Title

Emotet Botnet Infrastructure IP

Category: ai-validated First seen: Last updated:

Description

The IPv4 address 70.127.107.162 is known to be associated with the Emotet botnet, a notorious malware campaign used for distributing banking Trojans and other malicious activities.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 70.127.107.162 VT 0 / 91

IOC database

Type
ipv4
Value
70.127.107.162
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AI-validated IOC. The IPv4 address 70.127.107.162 is known to be associated with the Emotet botnet, a notorious malware campaign used for distributing banking Trojans and other malicious activities.

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
Network70.126.0.0/15
CountryUS
AS ownerCharter Communications, Inc
ASN33363
Regional registryARIN
History
Last analysis2024-05-12 15:52 UTC
Last modified on VirusTotal2024-05-12 15:53 UTC
WHOIS record date2024-05-12 15:53 UTC

References (0)

No references collected yet.

Remediations (11)

  • web:feodotracker.abuse.ch

    Block botnet communication to known Emotet C&Cs Even if everything fails and users in your network get infected with Emotet , you can prevent that infected machins talk to the attackers by blocking IP addresses that are active Emotet botnet C&C servers.

  • web:sites.cs.ucsb.edu

    To track the evolution of Emotet's command-and-control infrastructure , we developed techniques and tools to extract the configuration files used by the samples [10].

  • web:www.cisa.gov

    This increase has rendered Emotet one of the most prevalent ongoing threats. To secure against Emotet , CISA and MS-ISAC recommend implementing the mitigation measures described in this Alert, which include applying protocols that block suspicious attachments, using antivirus software, and blocking suspicious IPs .

  • web:www.cisecurity.org

    This increase has rendered Emotet one of the most prevalent ongoing threats. To secure against Emotet , CISA and MS-ISAC recommend implementing the mitigation measures described in this Alert, which include applying protocols that block suspicious attachments, using antivirus software, and blocking suspicious IPs .

  • web:www.fortinet.com

    The primary initial access vector observed by the FortiGuard Responder team for Emotet -based intrusions is phishing. Phishing campaigns involving Emotet differ in complexity; some are sent as replies from legitimate emails from compromised mailboxes. Others copy legitimate-sounding emails to decrease the chances of being flagged as malware.

  • web:www.hhs.gov

    13 Image courtesy of Proofpoint The beginning of Emotet's operational rhythm: Attack campaign followed by a pause for updates and improvements. Emotet Disruption in 2021 International efforts to take down Emotet's global botnet infrastructure in January 2021 included the United States, Canada, and several European countries. 14

  • web:www.huntress.com

    Emotet is a powerful malware that started as a banking trojan but evolved into a platform capable of distributing ransomware and stealing sensitive data. It infiltrates systems primarily through phishing emails and operates via injecting malicious code into legitimate processes while avoiding detection.

  • web:www.quorumcyber.com

    The botnet malware variant has been notorious for its previous distribution methods via Microsoft Word and Microsoft Excel attachments containing malicious macros. As noted in March 2023, The Emotet threat actor took an unexpected break from malicious activity for four months, between 13th July and 2nd November 2022.

  • web:www.radware.com

    Its modular design allows attackers to update its capabilities dynamically, turning compromised machines into parts of a larger botnet infrastructure used for further attacks. Infection by Emotet often results in significant disruptions.

  • web:dl.acm.org

    Ukraine's law enforcement apprehended two individuals who were responsible for deploying and managing Emotet's network infrastructure . In addition, the take-down team hijacked the controlling hosts and pushed a new update that would uninstall Emotet on a specific date.

  • web:www.spamhaus.org

    In January 2021, Europol announced a coordinated international group of law enforcement authorities had taken control of the Emotet malware infrastructure . To assist in the mitigation of this threat, the Spamhaus Project provided remediation data directly to end-users, networks, and national CERTs. All parties contacted with Emotet remediation data have responded; therefore, Spamhaus will no ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…