General

  • Target

    2024-04-11_3a01d211af30633181f9cea70010347a_icedid

  • Size

    8KB

  • Sample

    240411-nm1vnadf8x

  • MD5

    3a01d211af30633181f9cea70010347a

  • SHA1

    f69cf1177ff1215e0b7d68f112c5bf57d0ab1867

  • SHA256

    85d0eb64e7f7eb20cb2c468823db94b1c97292a821ecf8510aa6b39a7611c1d7

  • SHA512

    161f8152b487b32d2aaff64d9d787aa8bb5a3b3a02228d83c94205172265dcbd1e03f63bc6cbbf5c68e3f7aef4359b51a5bdd5e3796f00679d00c260a8f61b0c

  • SSDEEP

    192:/G6OThBwj6k8TqLUh5wCb3py+g2O9CdY/B:/G9hNxh5Zp1i9Cde

Malware Config

Extracted

Family

icedid

Targets

    • Target

      2024-04-11_3a01d211af30633181f9cea70010347a_icedid

    • Size

      8KB

    • MD5

      3a01d211af30633181f9cea70010347a

    • SHA1

      f69cf1177ff1215e0b7d68f112c5bf57d0ab1867

    • SHA256

      85d0eb64e7f7eb20cb2c468823db94b1c97292a821ecf8510aa6b39a7611c1d7

    • SHA512

      161f8152b487b32d2aaff64d9d787aa8bb5a3b3a02228d83c94205172265dcbd1e03f63bc6cbbf5c68e3f7aef4359b51a5bdd5e3796f00679d00c260a8f61b0c

    • SSDEEP

      192:/G6OThBwj6k8TqLUh5wCb3py+g2O9CdY/B:/G9hNxh5Zp1i9Cde

    Score
    10/10
    • IcedID, BokBot

      IcedID is a banking trojan capable of stealing credentials.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Tasks