C&CMembers
C&C

Old Emotet Loader's TLS Fingerprint Still Trips Dridex C2 Rules

A 494KB Emotet DLL cataloged in April 2022 still generates IDS hits — including two signatures explicitly flagged for Dridex — because its live TLS handshake matches infrastructure tracked under a different banking-trojan family's name. Fifty-four of 76 engines and a unanimous three-sandbox verdict confirm the file itself, even as the four IPs attached to its C2 label remain weakly corroborated.

Oct 2, 2026, 06:40 (UTC+9)Last seenOct 2, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC11MITRE24

A 494-kilobyte Emotet loader DLL first catalogued in April 2022 is still showing up in intrusion-detection logs today — not because the file is new, but because the TLS handshake it performs when it calls home still matches signatures built to track an entirely different banking trojan. Six IDS rule hits fire on this binary (hash 6bdac750fd1885696ffaf5dd38806c8f7bff2c8bc706421c9b4f0c2b0a9d8520, popularly tagged "mint" and "zard" alongside its Emotet label): three separate "ET CNC Feodo Tracker…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence