C&CMembers
C&C

Emotet-Labeled Loader's TLS Handshake Trips Dridex IDS Rules

A Win32 loader DLL flagged by 65 of 77 engines and unanimously sandboxed as Emotet triggers two separate JA3 fingerprint rules built for Dridex infrastructure. The narrow crossover sits atop an otherwise ordinary cluster: a hidden-macrosheet Excel dropper, the loader it likely feeds, and three IPs scattered across three unrelated hosting providers.

Jun 14, 2026, 02:41 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC16RegionsRO

A Win32 loader DLL tracked in this cluster — 65 of 77 engines flag it, and Zenbox, VMRay, and C2AE all name it Emotet in a unanimous 3/3 sandbox verdict — trips two independent intrusion-detection rules built for an entirely different crimeware family. The DLL's outbound TLS handshake fires "ET JA3 Hash - [Abuse.ch] Possible Dridex" from Proofpoint's Emerging Threats Open ruleset and a second hit from Abuse.ch's SSLBL malicious JA3 fingerprint list, also tagged Dridex.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence