AI-IOC-995c55a82271
medium
📛 Threat Title
Emotet Botnet Infrastructure IP
Description
The IPv4 address 70.127.107.162 is known to be associated with the Emotet botnet, a notorious malware campaign used for distributing banking Trojans and other malicious activities.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
70.127.107.162
VT 0 / 91
IOC database
- Type
- ipv4
- Value
70.127.107.162- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- AI-validated IOC. The IPv4 address 70.127.107.162 is known to be associated with the Emotet botnet, a notorious malware campaign used for distributing banking Trojans and other malicious activities.
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Network | 70.126.0.0/15 |
| Country | US |
| AS owner | Charter Communications, Inc |
| ASN | 33363 |
| Regional registry | ARIN |
History
| Last analysis | 2024-05-12 15:52 UTC |
| Last modified on VirusTotal | 2024-05-12 15:53 UTC |
| WHOIS record date | 2024-05-12 15:53 UTC |
References (0)
No references collected yet.
Remediations (11)
-
web:feodotracker.abuse.ch
Block botnet communication to known Emotet C&Cs Even if everything fails and users in your network get infected with Emotet , you can prevent that infected machins talk to the attackers by blocking IP addresses that are active Emotet botnet C&C servers.
-
web:sites.cs.ucsb.edu
To track the evolution of Emotet's command-and-control infrastructure , we developed techniques and tools to extract the configuration files used by the samples [10].
-
web:www.cisa.gov
This increase has rendered Emotet one of the most prevalent ongoing threats. To secure against Emotet , CISA and MS-ISAC recommend implementing the mitigation measures described in this Alert, which include applying protocols that block suspicious attachments, using antivirus software, and blocking suspicious IPs .
-
web:www.cisecurity.org
This increase has rendered Emotet one of the most prevalent ongoing threats. To secure against Emotet , CISA and MS-ISAC recommend implementing the mitigation measures described in this Alert, which include applying protocols that block suspicious attachments, using antivirus software, and blocking suspicious IPs .
-
web:www.fortinet.com
The primary initial access vector observed by the FortiGuard Responder team for Emotet -based intrusions is phishing. Phishing campaigns involving Emotet differ in complexity; some are sent as replies from legitimate emails from compromised mailboxes. Others copy legitimate-sounding emails to decrease the chances of being flagged as malware.
-
web:www.hhs.gov
13 Image courtesy of Proofpoint The beginning of Emotet's operational rhythm: Attack campaign followed by a pause for updates and improvements. Emotet Disruption in 2021 International efforts to take down Emotet's global botnet infrastructure in January 2021 included the United States, Canada, and several European countries. 14
-
web:www.huntress.com
Emotet is a powerful malware that started as a banking trojan but evolved into a platform capable of distributing ransomware and stealing sensitive data. It infiltrates systems primarily through phishing emails and operates via injecting malicious code into legitimate processes while avoiding detection.
-
web:www.quorumcyber.com
The botnet malware variant has been notorious for its previous distribution methods via Microsoft Word and Microsoft Excel attachments containing malicious macros. As noted in March 2023, The Emotet threat actor took an unexpected break from malicious activity for four months, between 13th July and 2nd November 2022.
-
web:www.radware.com
Its modular design allows attackers to update its capabilities dynamically, turning compromised machines into parts of a larger botnet infrastructure used for further attacks. Infection by Emotet often results in significant disruptions.
-
web:dl.acm.org
Ukraine's law enforcement apprehended two individuals who were responsible for deploying and managing Emotet's network infrastructure . In addition, the take-down team hijacked the controlling hosts and pushed a new update that would uninstall Emotet on a specific date.
-
web:www.spamhaus.org
In January 2021, Europol announced a coordinated international group of law enforcement authorities had taken control of the Emotet malware infrastructure . To assist in the mitigation of this threat, the Spamhaus Project provided remediation data directly to end-users, networks, and national CERTs. All parties contacted with Emotet remediation data have responded; therefore, Spamhaus will no ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.