Return of Emotet malware | Zscaler
Emotet, a prolific banking-trojan-turned-initial-access-broker, returned to the threat landscape on November 14, 2021 following a law enforcement disruption and arrests in January 2021. The revived variant is being distributed via the TrickBot botnet and direct spam campaigns using reply-chain phishing emails with malicious macro-enabled Office documents and password-protected archives, and now communicates with C2 infrastructure over HTTPS with updated encryption compared to prior versions.
- filenameFILE_24561806179825605525.docmMalicious macro-enabled Word attachment used in Emotet reply-chain phishing email
- filenameINF_4069641746481110.zipPassword-protected zip attachment used to deliver Emotet payload, evading email scanning
- ip103[.]75[.]201[.]2Configured Emotet C2 server (port 443)
- ip103[.]8[.]26[.]102Configured Emotet C2 server (port 8080)
- ip103[.]8[.]26[.]103Configured Emotet C2 server (port 8080)
- ip104[.]251[.]214[.]46Configured Emotet C2 server (port 8080)
- ip138[.]185[.]72[.]26Configured Emotet C2 server (port 8080)
- ip142[.]4[.]219[.]173Configured Emotet C2 server (port 8080)
- ip168[.]197[.]250[.]14Configured Emotet C2 server (port 80)
- ip177[.]72[.]80[.]14Configured Emotet C2 server (port 7080)
- ip178[.]79[.]147[.]66Configured Emotet C2 server (port 8080)
- ip185[.]148[.]169[.]10Configured Emotet C2 server (port 8080)
- ip185[.]184[.]25[.]237Configured Emotet C2 server (port 8080)
- ip188[.]93[.]125[.]116Configured Emotet C2 server (port 8080)
- ip191[.]252[.]103[.]16Configured Emotet C2 server (port 80)
- ip195[.]154[.]133[.]20Configured Emotet C2 server (port 443)
- ip195[.]154[.]146[.]35Configured Emotet C2 server (port 443)
- ip195[.]77[.]239[.]39Configured Emotet C2 server (port 8080)
- ip196[.]44[.]98[.]190Configured Emotet C2 server (port 8080)
- ip207[.]148[.]81[.]119Configured Emotet C2 server (port 8080)
- ip207[.]38[.]84[.]195Configured Emotet C2 server (port 8080)
- ip210[.]57[.]217[.]132Configured Emotet C2 server (port 8080)
- ip212[.]237[.]5[.]209Configured Emotet C2 server (port 443)
- ip37[.]44[.]244[.]177Configured Emotet C2 server (port 8080)
- ip37[.]59[.]209[.]141Configured Emotet C2 server (port 8080)
- ip45[.]118[.]135[.]203Configured Emotet C2 server (port 7080)
- ip45[.]142[.]114[.]231Configured Emotet C2 server (port 8080)
- ip45[.]76[.]176[.]10Configured Emotet C2 server (port 8080)
- ip45[.]79[.]33[.]48Configured Emotet C2 server (port 8080)
- ip51[.]178[.]61[.]60Configured Emotet C2 server (port 443)
- ip51[.]210[.]242[.]234Configured Emotet C2 server (port 8080)
- ip51[.]68[.]175[.]8Configured Emotet C2 server (port 8080)
- ip54[.]37[.]228[.]122Configured Emotet C2 server (port 443)
- ip54[.]38[.]242[.]185Configured Emotet C2 server (port 443)
- ip58[.]227[.]42[.]236Configured Emotet C2 server (port 80)
- ip66[.]42[.]55[.]5Configured Emotet C2 server (port 7080)
- ip66[.]42[.]57[.]149Configured Emotet C2 server (port 443)
- ip78[.]46[.]73[.]125Configured Emotet C2 server (port 443)
- ip78[.]47[.]204[.]80Configured Emotet C2 server (port 443)
- ip81[.]0[.]236[.]93Configured Emotet C2 server (port 443)
- ip85[.]214[.]67[.]203Configured Emotet C2 server (port 8080)
- ip94[.]177[.]248[.]64Configured Emotet C2 server (port 443)
- md5bc3532085a0b4febd9eed51aac2180d0MD5 of Emotet DLL payload flagged in Zscaler cloud sandbox analysis (Threat Score 88)
- sha256015a96c0567c86af8c15b3fe4e19098ae9d0ea583e6bc0bb71c344fc993a26cfSpam campaign malicious attachment hash used to deliver Emotet
- sha256c7574aac7583a5bdc446f813b8e347a768a9f4af858404371eae82ad2d136a01Reference sample hash for the returned Emotet malware payload
- urlhxxp://crownadvertising[.]ca/wp-includes/OxiAACCoic/Malicious URL embedded in spam campaign document (compromised WordPress site)
- urlhxxp://immoinvest[.]com[.]br/blog_old/wp-admin/luoT/Malicious URL embedded in spam campaign document (compromised WordPress site)
- urlhxxps://cars-taxonomy[.]mywebartist[.]eu/-/BPCahsAFjwF/Malicious URL embedded in spam campaign document (compromised site)
- urlhxxps://evgeniys[.]ru/sap-logs/D6/Malicious URL embedded in spam campaign document used to fetch/deliver Emotet payload
- urlhxxps://www[.]168801[.]xyz/wp-content/6J3CV4meLxvZP/Malicious URL embedded in spam campaign document
- urlhxxps://www[.]pasionportufuturo[.]pe/wp-content/XUBS/Malicious URL embedded in spam campaign document
- urlhxxps://yoho[.]love/wp-content/e4laFBDXIvYT6O/Malicious URL embedded in spam campaign document
Detection / HunterAnthropic
What Happened
A well-known and dangerous piece of malware called Emotet, which had been shut down by law enforcement in early 2021, has come back online. It is being spread through fake 'reply' emails that trick people into opening infected Word or Excel file attachments or password-protected zip files. This matters because Emotet has historically been used as a doorway for ransomware gangs to break into organizations' networks, so its return could lead to more serious follow-on attacks. Anyone who uses email and Microsoft Office documents could be affected, especially if macros are enabled. Organizations should remind employees to be cautious about unexpected email replies and attachments, and consider blocking known malicious infrastructure listed in this report.
Key Takeaways
- Emotet malware resurfaced on November 14, 2021 after a ~10-month hiatus following a January 2021 law enforcement takedown and arrests.
- The new Emotet variant was initially distributed via the TrickBot botnet, with later reporting confirming distribution via direct email spam campaigns as well.
- Emotet now uses HTTPS instead of plain HTTP for command and control (C2) communication, along with changes to C2 data and encryption compared to earlier variants.
- Spam campaigns leverage 'reply-chain' email hijacking with malicious .docm, .xlsm, and password-protected .zip attachments to deliver the payload.
- Emotet functions as an initial access broker, historically providing footholds to ransomware operators, suggesting downstream ransomware risk for infected organizations.
Affected Systems
- Microsoft Windows endpoints
- Users running Microsoft Word/Excel with macros enabled
- Email users receiving spoofed reply-chain messages
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Victim receives a reply-chain phishing email (hijacked legitimate thread) with a malicious .docm, .xlsm, or password-protected .zip attachment
- Execution: Victim opens the attachment and enables macros, or extracts and runs the archived file, triggering the embedded malicious macro
- Delivery: Macro reaches out to an attacker-controlled/compromised URL to download the Emotet DLL payload
- Installation: Emotet DLL is loaded via process injection and establishes persistence and masquerading on the host
- Command and Control: Emotet beacons to a configured C2 server over HTTPS using updated encryption
- Follow-on Access: Emotet provides initial access to ransomware operators or downloads additional malware (e.g., TrickBot) for further compromise
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Zscaler Cloud Sandbox
The article does not provide YARA, Sigma, Snort/Suricata, or query-language detection logic. Detection evidence is limited to a Zscaler Cloud Sandbox behavioral report screenshot showing a malicious threat score and behavioral indicators for the sample.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | Behaviors like process injection, masquerading, and disabling security tools are typically observable by EDR, but the article provides no specific process names, command lines, or file paths beyond attachment names, limiting precise detection engineering. |
| Network Visibility | Medium | C2 traffic now uses HTTPS, reducing visibility for network tools without TLS inspection; however, a list of C2 IP:port pairs is provided which can be used for network-layer blocking and monitoring. |
| Detection Difficulty | Moderate | The reply-chain phishing lure and use of HTTPS for C2 evade simple signature-based email and network detection, but known malicious macro behaviors, process injection, and the provided C2 IOC list support moderate detection via layered controls. |
Required Log Sources
- Email gateway/attachment logs
- Proxy/web gateway logs (URL and TLS SNI)
- Endpoint process creation and injection telemetry (e.g., Sysmon Event ID 1, 7, 8, 10)
- DNS query logs
- Sandbox detonation logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Look for Office applications (Word/Excel) spawning unusual child processes shortly after opening an email attachment, consistent with macro execution and payload staging. | Endpoint process creation logs, parent-child process relationships | Execution (T1055, T1218) | Medium - legitimate macro-enabled business documents can trigger similar parent-child relationships |
| Hunt for outbound HTTPS connections from endpoints to non-standard high ports (e.g., 7080, 8080) that are uncommon for normal user traffic. | Network/proxy logs, firewall connection logs | Command and Control | Medium - some legitimate applications also use non-standard ports |
| Search email gateway logs for inbound messages that appear to be replies to existing threads but originate from unexpected or spoofed senders with attached .docm, .xlsm, or password-protected .zip files. | Email gateway/mail flow logs, attachment metadata | Initial Access (Phishing) | Low to Medium - password-protected zips and reply-style subjects are less common in legitimate high-volume traffic but do occur |
| Investigate hosts exhibiting process injection into legitimate processes combined with disabling of AV/security tool processes shortly after document activity. | EDR behavioral alerts, Sysmon Event ID 8/10, security product tamper logs | Defense Evasion (T1055, T1562) | Low - this combination of behaviors is uncommon in benign activity |
| Check for enumeration activity (registry queries, file/directory listing, security software discovery) occurring immediately following a suspicious document open event. | Endpoint registry access logs, file system access logs, EDR discovery-technique alerts | Discovery (T1012, T1083, T1518) | Medium - some legitimate software performs similar discovery actions |
Control Gaps
- Email filters relying solely on content/signature detection may miss reply-chain phishing that abuses legitimate hijacked email threads
- Network security tools without TLS/SSL inspection capability will have reduced visibility into C2 traffic now that Emotet uses HTTPS
- Password-protected zip archives can bypass attachment scanning and sandboxing that cannot open encrypted content without the password
Key Behavioral Indicators
- Office application spawning script interpreters or loader processes after opening an attachment
- DLL being mapped/injected into another process's memory space shortly after document execution
- Processes launched in debugging mode or exhibiting anti-analysis sleep loops
- Suppression of application error messages or evidence of hiding mark-of-the-web/download origin
- Outbound connections to multiple distinct IP:port combinations over HTTPS shortly after document macro execution
False Positive Assessment
Medium - Behavioral indicators (process injection, discovery activity) can overlap with legitimate software, and network indicators (non-standard ports, HTTPS to varied IPs) require correlation with additional context to avoid false positives; the provided C2 IP list, however, offers relatively high-confidence blocking opportunities if current.
Recommendations
Immediate Mitigation
- Consider blocking the listed C2 IP addresses and malicious URLs at the perimeter firewall/proxy where feasible; verify against your organization's incident response runbook and team escalation paths before acting.
- Consider disabling macros by default in Microsoft Office applications organization-wide, or restrict macro execution to signed/trusted macros only.
- Evaluate blocking or flagging inbound emails containing .docm, .xlsm, or password-protected .zip attachments, particularly where reply-chain (RE:) subject lines are combined with unexpected senders.
- Consider isolating and investigating any endpoint that has opened one of the identified malicious attachments if your EDR supports host isolation.
Infrastructure Hardening
- Evaluate deploying or tuning TLS/SSL inspection on network security tools to regain visibility into HTTPS-based C2 traffic.
- Consider implementing DNS-layer filtering or sinkholing for known malicious domains/URLs associated with this campaign.
- Review and harden email gateway rules to detect password-protected archive attachments and flag them for additional scrutiny or sandboxing with credential harvesting.
- Evaluate network segmentation to limit lateral movement potential if an endpoint is compromised by Emotet, given its history as an initial access broker for ransomware.
User Protection
- Ensure endpoint protection/EDR signatures and behavioral detections are updated to cover known Emotet TTPs (process injection, masquerading, security tool tampering).
- Consider enabling application allow-listing or script execution controls to limit macro-driven payload execution.
- Evaluate deploying attachment detonation/sandboxing for all inbound Office documents and archive files before delivery to end users.
Security Awareness
- Update phishing awareness training to specifically cover reply-chain (thread hijacking) phishing tactics, where attackers reply to legitimate existing email conversations.
- Remind employees to verify unexpected attachments even when they appear to come from known contacts or ongoing conversations, and to report suspicious password-protected archives.
- Reinforce guidance around not enabling macros in documents received via email unless independently verified as legitimate.
MITRE ATT&CK Mapping
Persistence
Privilege Escalation
Stealth
Additional IOCs
- Ips:
94[.]177[.]248[.]64- Configured Emotet C2 server (port 443)103[.]8[.]26[.]103- Configured Emotet C2 server (port 8080)185[.]184[.]25[.]237- Configured Emotet C2 server (port 8080)45[.]76[.]176[.]10- Configured Emotet C2 server (port 8080)188[.]93[.]125[.]116- Configured Emotet C2 server (port 8080)103[.]8[.]26[.]102- Configured Emotet C2 server (port 8080)178[.]79[.]147[.]66- Configured Emotet C2 server (port 8080)58[.]227[.]42[.]236- Configured Emotet C2 server (port 80)45[.]118[.]135[.]203- Configured Emotet C2 server (port 7080)103[.]75[.]201[.]2- Configured Emotet C2 server (port 443)195[.]154[.]133[.]20- Configured Emotet C2 server (port 443)45[.]142[.]114[.]231- Configured Emotet C2 server (port 8080)212[.]237[.]5[.]209- Configured Emotet C2 server (port 443)207[.]38[.]84[.]195- Configured Emotet C2 server (port 8080)104[.]251[.]214[.]46- Configured Emotet C2 server (port 8080)138[.]185[.]72[.]26- Configured Emotet C2 server (port 8080)51[.]68[.]175[.]8- Configured Emotet C2 server (port 8080)210[.]57[.]217[.]132- Configured Emotet C2 server (port 8080)51[.]178[.]61[.]60- Configured Emotet C2 server (port 443)168[.]197[.]250[.]14- Configured Emotet C2 server (port 80)45[.]79[.]33[.]48- Configured Emotet C2 server (port 8080)196[.]44[.]98[.]190- Configured Emotet C2 server (port 8080)177[.]72[.]80[.]14- Configured Emotet C2 server (port 7080)51[.]210[.]242[.]234- Configured Emotet C2 server (port 8080)185[.]148[.]169[.]10- Configured Emotet C2 server (port 8080)142[.]4[.]219[.]173- Configured Emotet C2 server (port 8080)78[.]47[.]204[.]80- Configured Emotet C2 server (port 443)78[.]46[.]73[.]125- Configured Emotet C2 server (port 443)37[.]44[.]244[.]177- Configured Emotet C2 server (port 8080)37[.]59[.]209[.]141- Configured Emotet C2 server (port 8080)191[.]252[.]103[.]16- Configured Emotet C2 server (port 80)54[.]38[.]242[.]185- Configured Emotet C2 server (port 443)85[.]214[.]67[.]203- Configured Emotet C2 server (port 8080)54[.]37[.]228[.]122- Configured Emotet C2 server (port 443)207[.]148[.]81[.]119- Configured Emotet C2 server (port 8080)195[.]77[.]239[.]39- Configured Emotet C2 server (port 8080)66[.]42[.]57[.]149- Configured Emotet C2 server (port 443)195[.]154[.]146[.]35- Configured Emotet C2 server (port 443)
- Urls:
hxxps://cars-taxonomy[.]mywebartist[.]eu/-/BPCahsAFjwF/- Malicious URL embedded in spam campaign document (compromised site)hxxp://immoinvest[.]com[.]br/blog_old/wp-admin/luoT/- Malicious URL embedded in spam campaign document (compromised WordPress site)hxxps://yoho[.]love/wp-content/e4laFBDXIvYT6O/- Malicious URL embedded in spam campaign documenthxxps://www[.]168801[.]xyz/wp-content/6J3CV4meLxvZP/- Malicious URL embedded in spam campaign documenthxxps://www[.]pasionportufuturo[.]pe/wp-content/XUBS/- Malicious URL embedded in spam campaign document