Skip to content

Instantly share code, notes, and snippets.

@Blevene
Created September 4, 2018 16:35
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Blevene/937968152aad4eaaf62134eb32aa8bf6 to your computer and use it in GitHub Desktop.
Save Blevene/937968152aad4eaaf62134eb32aa8bf6 to your computer and use it in GitHub Desktop.
Emotet 9/3/2018 Indicators Courtesy of VirusTotal
1.22.155.6,
104.236.24.85,
133.242.208.183,
159.192.247.138,
160.226.162.79,
178.63.118.195,
181.29.82.117,
187.193.97.96,
189.161.67.1,
189.190.154.29,
189.207.123.105,
189.219.205.50,
190.144.78.74,
190.180.108.38,
198.199.185.25,
1c1e2db21c30fe50d3dcb4b4f756bc154d319cf1365afb3962631941b9513859,
200.56.104.44,
200.68.112.41,
201.102.224.23,
201.145.118.199,
201.146.211.106,
203.198.129.4,
209.204.201.18,
210.2.86.94,
217.13.106.203,
37.120.175.15,
39.53.38.131,
41.79.155.118,
45.33.14.245,
49.212.135.76,
81.21.85.89,
http://1.22.155.6,
http://104.236.24.85:8080,
http://133.242.208.183:8080,
http://178.63.118.195:8080,
http://189.190.154.29:50000,
http://198.199.185.25:443,
http://200.68.112.41,
http://201.102.224.23:443,
http://203.198.129.4:8080,
http://209.204.201.18,
http://210.2.86.94:8080,
http://217.13.106.203:4143,
http://37.120.175.15,
http://45.33.14.245:8080,
http://49.212.135.76:443,
http://81.21.85.89:7080,
http://acsgroup-usa.com/Payments-09-2018/,
http://atgmail.net/payment-09-18/,
http://bin-bang.com/Documents-09-2018/,
http://blog.v217.5pa.cn/Invoice,
http://blog.v217.5pa.cn/Invoice/,
http://bujiandanxd.club/Corrections,
http://collateralproduccions.com/Receipts/,
http://geotermicapilosur.com/INVOICE-09-2018,
http://geotermicapilosur.com/INVOICE-09-2018/,
http://gutshaus-hugoldsdorf.de/Invoice-09-18/,
http://harryliwen.net/INVOICES,
http://harryliwen.net/INVOICES/,
http://investmentsofpassion.biz/Corrections,
http://investmentsofpassion.biz/Corrections/,
http://islamforall.tv/Documents-09-18,
http://islamforall.tv/Documents-09-18/,
http://keraradio.com/Corrections-09-18,
http://laschuk.com.br/Payments,
http://laschuk.com.br/Payments/,
http://leodruker.com/wp-content/cache/Payments-09-2018,
http://michiganbusiness.us/Documents,
http://michiganbusiness.us/Documents/,
http://peekaboorevue.com/Documents,
http://peekaboorevue.com/Documents/,
http://vivafascino.com/INVOICES/,
http://writerbliss.com/Payments/,
http://yuanjie.me/INVOICE-09-2018,
@Blevene
Copy link
Author

Blevene commented Sep 4, 2018

Source graph (I know not everyone has VTI so I parsed the data out): https://www.virustotal.com/graph/#/selected/n81z21z85z89/drawer/graph-details

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment