logo

Emotet’s Uncommon Approach of Masking IP Addresses

ID: 42b6c4a2-5a72-5862-b06c-1e39cc6801fb

STIX ID: report--42b6c4a2-5a72-5862-b06c-1e39cc6801fb

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2022-02-04

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee researchers analyzed an Emotet maldoc campaign that uses hexadecimal and octal representations of IP addresses to obfuscate URLs and evade detection; the infection chain is phishing Excel attachment → mshta executing obfuscated JavaScript → PowerShell downloading a DLL (saved as C:\Users\Public\Documents\ssd.dll) → DLL executed by rundll32 establishing C2. The report includes sample command lines, file and URL IOCs, hashes for the XLS and DLL, and MITRE ATT&CK technique mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.