Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
26
Global rank
24 infographic chevron month
Month rank
25 infographic chevron week
Week rank

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Trojan
Type
ex-USSR
Origin
1 June, 2014
First seen
7 October, 2026
Last seen
Also known as
Heodo
Geodo

How to analyze Emotet with ANY.RUN

Type
ex-USSR
Origin
1 June, 2014
First seen
7 October, 2026
Last seen

IOCs

IP addresses
23.194.190.167
165.154.1.133
184.31.95.119
52.110.17.48
23.213.161.106
40.126.31.69
52.110.17.54
52.168.117.175
52.110.17.42
208.91.197.27
2.21.239.12
52.123.243.87
199.232.214.172
95.101.9.135
2.18.66.37
195.210.46.42
52.111.236.4
2.21.20.138
52.110.17.45
52.110.17.71
Hashes
93fa329ba9ef75af1d19df29a2b933bc1eb83336703bbdd3cbc60946a9f668b9
044aa7e93ec81b297b53aaebad9bbac1a9d754219b001aaf5d4261665af30bc7
057e3d39cd6e6b882c9cebfb56920db712f49cd628b35bf58e1fd544c0bea20b
0dfa017a86a8dd9c7b2f8a07af89f6e5a2dbacea8e0d2699b6176e055a8a1a15
438a487d96c184aafaf90bf796dfb7b551fbaec22e8b9ef432eb3675b8c814cf
b452ba00f4971736a7eadcf2187b7c008a145e84fb43b046594807625c065640
8a2cedeec7ca8ac2691f024af0f453170e8b6647a9de382a9a82c9ac8ef73025
66f47b2ef0d2b4c0fefecb0374412d59142cdc44d50c35b85bbb90b470b40fa6
ba19e9a6a3cc91582dc1005ce0239620208e2e8795086eef9ec94b9c75fe4ccc
c0b296e47062d9088be55e80bf9d99de03e3154daeea19e9c236f2d4d1c8faea
ff03f069281de852c003cf93e40247a03e3402c734ee2c6c9961e3f55965817f
b19162cec9afcb0ff202ccc366d23fd745aebf4e5dd9f23bfaaabc7ac4b2f240
198a134cff22c87dd3164ae1e82ada5ae6c5e49caefe2819bb8a607adf2ac2e0
14a73223fc963ee73477f64edb92dc03e9ef5c0044c56d9aa22a6dcb29c5bde2
ee66db98d5158e7e3107700632403cbeb7290b5c6fd5384f41d98f5585182ef6
c8c96c37ff8427467fc0b2c685ae6f231dfe841332f0783c785729c4451f976c
481e0734223e3bd2bc152e3e61b06e0462b193883e46004025bc7b0aba09c39c
32796f324e8a232310b9a81ddd576db25af78216117ba8d69cf3ad4d2f0c51d2
82f6db23e32b0b8ccec1c83ac426628fc38bc8c5884fbab0f20df068eee9f587
bada2719f2e86a81f7d330eaa38168b9418e35f09b4e971af421012d9be20659
Domains
dns.msftncsi.com
ecs.office.com
okcupidating.com
52550750-56-20180826151453.webstarterz.com
metadata.templates.cdn.office.net
officeclient.microsoft.com
oubaina.com
odc.officeapps.live.com
login.live.com
omex.cdn.office.net
licensing.m365.svc.cloud.microsoft
messaging.engagement.office.com
fs.microsoft.com
binaries.templates.cdn.office.net
google.com
self.events.data.microsoft.com
www.msbc.kz
ctldl.windowsupdate.com
bike-nomad.com
roaming.svc.cloud.microsoft
URLs
https://officeclient.microsoft.com/config16/?lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16626&crev=3
https://fs.microsoft.com/fs/windows/config.json
https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
https://roaming.svc.cloud.microsoft/rs/roamingsoapservice.svc
https://ecs.office.com/config/v2/office/word/16.0.16626.20134/production/cc?&clientid=%7b72fa513c-1434-461c-bfdf-dcc1864a73f3%7d&application=word&platform=win32&version=16.0.16626.20134&msoversion=16.0.16626.20086&sdx=fa000000069.1.0.2211.2001&sdx=fa000000070.1.0.2211.4002&officefirstrunsdxversion=1.0.2211.2001&processname=winword.exe&audience=production&build=ship&architecture=x64&language=en-us&subscriptionlicense=false&perpetuallicense=2021&licensecategory=13&licensesku=homebusiness2021retail&osversion=10.0&osbuild=22000&channel=cc&installtype=c2r&providerid=9fcc1350af7dd254&sessionid=%7bef9972e0-e113-4fd3-98d5-d8450d98149c%7d&labmachine=false
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?b44e84c0e1ebfda9
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7046a599b1fe1993
https://odc.officeapps.live.com/odc/servicemanager/catalog?lcid=1033&syslcid=1033&uilcid=1033&app=0&ver=16&schema=8
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?d6ca38c5c156c45f
https://messaging.engagement.office.com/campaignmetadataaggregator?app=0&platform=10&ofc_channel=cc&ofc_audience=production&ofc_flights=ofsh6c2b1tla1a31%3bofcrui4yvdulbf31%3bofhpex3jznepoo31%3bofjhlwlmoc1pz531&ver=16.0.16626.20086&hwid=cww_ea36965c-3b04-488f-872d-9ea1a33fd23d_ea36965c-3b04-488f-872d-9ea1a33fd23d_cad00ed2804b4459ac7100a9078c786b%3a04d2511d56021f46e0&osversion=10.0.22000&country=vn&locale=en-us&ofc_licensecategory=13&ofc_licensesku=homebusiness2021retail&contenttype=campaigncontent
https://licensing.m365.svc.cloud.microsoft/licensing/user/renewperpetuallicense?api-version=5
https://login.live.com/rst2.srf
https://www.msbc.kz/data/k527_5_cbdvv5bi19/
http://oubaina.com/wp-includes/lqkz_nvr_1avf4/
http://bike-nomad.com/cgi-bin/7n_0x0_62mnzyh9q/
https://self.events.data.microsoft.com/onecollector/1.0/
https://metadata.templates.cdn.office.net/client/templates/gallery?lcid=1033&syslcid=1033&uilcid=1033&app=0&ver=16&tl=2&build=16.0.16626&gtype=0%2c1%2c2%2c5%2c
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02835233.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851223.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851220.cab
Last Seen at
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1648
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 3378
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10879
comments 0

What is Emotet Trojan?

Emotet is a highly sophisticated and destructive Trojan used to download and install other malware. First recorded in 2014, it was classified as a banking trojan, but Emotet has gained advanced capabilities throughout its lifetime and evolved into an entire malware distribution service.

So what makes the Emotet virus so dangerous? Based on the analysis, Emotet can act like a worm and spread using local networks, which makes it extremely hard to clean up. In addition to this, the trojan has advanced persistence and anti-evasion mechanics, such as detecting sandboxes and virtual machines with an option to generate false indicators to throw research off.

On top of that, the trojan has a polymorphic design – meaning that it can change its code to bypass signature-based detection, making this cyber defense strategy useless against its' attacks. Besides that, Emotet receives updates from the control server, performing this operation as if an operating system update is being installed. This allows the trojan to drop additional malware onto the infected machine stealthily.

It should also be noted that the Emotet trojan has a modular design which makes it possible to adapt this malware to various tasks and customize it for every particular campaign, giving the attackers maximum flexibility. Emotet's main targets are governments, corporations, small businesses, and individuals, focusing on Europe, America, and Canada.

General description of Emotet virus

The first version of Emotet malware which was spotted in the wild back in 2014, was designed to steal banking credentials by intercepting internet traffic and was much more basic than the beast of a Trojan which we know today. When Emotet was first spotted in the wild, the malware targeted mainly banks from Germany and Austria using only its native information stealing toolset.

Version two followed shortly after, this time carrying several additional modules such as a money transfer, mail spam, DDoS, and address book stealing modules. The third iteration of Emotet was released in 2015. This time attackers focused on upgrading the anti-evasion functionality of the malware and introducing banks from Switzerland into the list of potential victims.

The next overhaul of the Emotet malware followed in December 2016, changing the attack vector of the virus. At the beginning of its lifetime, Version 4 of the virus heavily relied on the RIG 4.0 exploit kit to make its way into the victims' computers, later switching primarily to mail spam. The same iteration of the malware also marked the moment when the primary use case of the malware started shifting from using its own banking module to dropping other Trojans onto infected machines.

Speaking of modules, Emotet malware can perform a large number of malicious activities that vary depending on the modules used in a particular campaign. Most versions of the virus included a spam module that can be used to continue the spread of the malware by sending out a series of malicious emails from the infected machine. Another typically included module is the one used for credential stealing, allowing Emotet to steal sensitive information from web browsers and mail clients.

In 2017, Emotet trojan was equipped with a spreader module, allowing the malware to infect all machines connected via a local network. The virus also gained the address book stealer module – this one is interesting. It analyzes the relationship between email senders and receivers and uses the collected information to enhance the effectiveness of subsequent campaigns originating from the users' PC, targeting friends, family members, and colleagues of the victim with personalized spam emails.

Not only does Emotet malware provide flexible functionality through the use of modules and has several anti-evasion functions, but it also puts a heavy emphasis on persistence. To ensure that the malware stays in the infected machine, it injects into running processes, downloads additional payloads, often targeting the Explorer.exe. In addition to that, the malware uses Scheduled Tasks and makes registry key changes.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

In January 2021, the Emotet botnet was taken down by law enforcement. The global effort, known as Operation Ladybird, located the malware infrastructure around the globe. They arrested at least two of the cybercriminal gang members in Ukraine. Their attackers' names were not uncovered.

Security experts teamed up and simultaneously hijacked hundreds of Emotet command-and-control servers and disrupted its backups, too. Researchers placed their own machines at the IP addresses of crooks' computers and made the payload inactive to prevent connection with the botnet.

These actions led to the fact that Emotet's C2 servers didn't work for almost ten months.

On November 14, 2021, Emotet came back with a new version. The botnet started to spread numerous maldocs. Moreover, it changed its tactics. The Emotet virus used to drop Trickbot or Qbot. But right now, the malware is also dealing with Cobalt Strike. It means that the time between the initial infection and a ransomware attack shortens significantly.

Also, researchers noticed that Emotet brings up more and more C2 servers to life. The botnet's new version acquired ECC encryption, modified communication protocols - ​​ new initial check-in, etc.

It should be noted that the mentioned Trojan versions are extremely destructive, and their attacks can have several consequences. For example, malware can cause loss of private data, inability to operate the infected PC up to its total disability, and financial losses associated with restoring the damaged infrastructure. In fact, one company was forced to spend an excess of one million dollars in order to deal with the aftermath of an Emotet attack.

Emotet malware analysis

A video recorded in the ANY.RUN malware hunting service, displays the execution process of Emotet, allowing to perform the analysis of the malware behavior in a lot of detail. You can also investigate other malware like FlawedAmmyy or Agent Tesla.

emotet execution process tree

Figure 1: Displays the processes list generated by the ANY.RUN malware hunting service

text report of the Emotet analysis

Figure 2: Even more information about the execution of Emotet can be found in customizable text reports generated by ANY.RUN

Emotet execution process

The Emotet trojan's primary distribution is through malicious email spam campaigns. The first step in the chain of infection involves tricking the potential victim into opening an attached Microsoft Office file using social engineering. After the file has been opened and macros enabled, there is no need for additional user actions.

Downloaded files contain malicious VBA code that runs after a document has been opened. One of the possible options of the infection process is when the VBA code utilizes WMI to launch a Powershell code which downloads the payload – a malicious executable file from the webserver. Notably, the Powershell script is encoded.

Emotet makes steps to maintain a presence in the infected system - it copies itself into %AppData% subfolders and changes the autorun value in the registry. Besides that, the malware allows its attackers to download additional payloads. The malware sends information to and from a server through all infection processes. As the last execution step, Emotet waits for commands from command-and-control servers.

Prevention of Emotet attacks

To minimize the risk of Emotet virus infection and potential destruction if such infection does occur, users are advised to follow a set of standard best practices, such as not downloading files from suspicious emails and keeping an updated version of antivirus on the machine at all times.

For organizations, it is advised to restrict inbound SMB communication between client systems to prevent Emotet from spreading from one machine to another within the local network, provide security training for personnel and instruct employees about the danger of mail spam as well as take all possible precautions to filter out potentially malicious emails at the firewall.

How does Emotet spread?

According to the analysis, the main distribution method of Emotet malware is malicious email campaigns. The trojan uses its address book stealer module in order to pull the contacts from the email account of its victim and send its payloads to the contacts found from the hijacked account.

Bearing in mind that potential victims are receiving an email from somebody they know and trust, Emotet has a very high chance of a successful attack. The received email usually contains a link to a malicious URL that downloads the malware and launches the payload when clicked.

However, email spam is not the only distribution Method that this malware utilizes. It may also take advantage of certain Windows vulnerabilities, thus the malware can make its way into a machine completely "silently," without the user ever knowing about it.

How to collect Emotet's IOCs using ANY.RUN?

For your detailed Emotet malware analysis ANY. RUN's "Fake Net" feature will be very useful. It intercepts HTTP requests and returns a 404 error, forcing malware to reveal its command-and-control server links.

fake net emotet Figure 3: Run Emotet sample with turn on "Fake net" feature

To turn it on in the "Advanced mode" of the "New task" window, check the box next to the "Fake net" in the "Network" section.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Conclusion

Emotet malware is one of the most sophisticated and destructive trojans. Since its first introduction back in 2014, the malware has underground a substantial evolution gaining a lot of anti-evasion features, obtaining worm-like functionality, and even changing the main focus from information-stealing to installing other trojans onto infected machines. With the ability to spread to adjacent systems, Emotet can easily infect all machines in a single network, making dealing with the consequences of an attack a true nightmare.

The situation is further worsened by the fact that the malware is equipped with a series of anti-evasion tricks that make analyzing it quite tricky. As a result, the process of developing countermeasures is much more complicated in comparison to more straightforward trojans.

Thankfully, modern online hunting services like ANY.RUN are equipped with equally advanced research functions and allow professionals to study cyber threats with maximum efficiency, helping researchers battle evasive malware like Emotet.

Create your free ANY.RUN account to analyze malware and phishing without limits!

HAVE A LOOK AT

PureCrypter screenshot
PureCrypter
purecrypter
First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.
Read More
Kamasers screenshot
Kamasers
kamasers
Kamasers is a multi-functional DDoS botnet malware that transforms infected machines into remotely controlled attack nodes. It combines network-layer flooding capabilities, resilient command-and-control (C2), and payload delivery, making it not just a disruption tool but a gateway to broader compromise.
Read More
Qilin Ransomware screenshot
Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.
Read More
Trojan screenshot
Trojan
trojan trojan horse
Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.
Read More
BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More
Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More