WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships FBI FLASH: Increased Number of Emotet Command and Control IP Addresses Identified
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

FBI FLASH: Increased Number of Emotet Command and Control IP Addresses Identified

Author: Charles Egli

Created: Tuesday, September 10, 2019 - 13:08

Categories: Cybersecurity

The FBI has released a FLASH message on Emotet, providing new internet protocol (IP) addresses that have been associated with modular banking Trojan since it recently resumed operations after a hiatus that began in early June (for more on Emotet’s revival, read an article WaterISAC discussed in the August 27, 2019 Security and Resilience Update). The FBI recommends system administrators immediately block these IP addresses to prevent Emotet from exploiting their systems.

Please note the IP addresses are included in the second document listed below, the Excel document.

WaterISAC also encourages members to review the FLASH message and use the information to detect and block Emotet activity, especially given that this malware has been observed in attacks, some successful, against the water and wastewater sector. These include incidents involving the Onslow Water and Sewer Authority (originally discussed in the October 16, 2018 Security and Resilience Update) and the Brick Township Municipal Utilities Authority (discussed during the March 2019 Cyber Threat Briefing).

Attached Files:

Emotet_FLASH_MC-000106-MW Emotet_FLASH_C2_Ports_MC-000106-MW

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar