General

  • Target

    2024-06-28_89de3a110c0bffb2bc3e073089135f2c_icedid

  • Size

    10.8MB

  • Sample

    240628-2n9e3sxcpk

  • MD5

    89de3a110c0bffb2bc3e073089135f2c

  • SHA1

    474df726bd9cc40699dad025c43f753e77eff1c1

  • SHA256

    27b3660ab08b007bb1a32d76a50de3c4ddb39d6427acbfff31a4ba4352aebfcd

  • SHA512

    6863522c6f03cf08847736e2d72ec8b74e0e7445ae4f221860ee74254977f4bb56b02ca51122b9ac16aa81eac72e7f2ed62c8df73c2f38c59adf6b0eaa878476

  • SSDEEP

    196608:4vA5UWb5RyputVARx2E9ONxxm2oadqvolbm/TBw00WxDtJ/YRZ8ZS4R0:/nRXtVw2E9cxzxViGWxDr/IGSB

Malware Config

Targets

    • Target

      2024-06-28_89de3a110c0bffb2bc3e073089135f2c_icedid

    • Size

      10.8MB

    • MD5

      89de3a110c0bffb2bc3e073089135f2c

    • SHA1

      474df726bd9cc40699dad025c43f753e77eff1c1

    • SHA256

      27b3660ab08b007bb1a32d76a50de3c4ddb39d6427acbfff31a4ba4352aebfcd

    • SHA512

      6863522c6f03cf08847736e2d72ec8b74e0e7445ae4f221860ee74254977f4bb56b02ca51122b9ac16aa81eac72e7f2ed62c8df73c2f38c59adf6b0eaa878476

    • SSDEEP

      196608:4vA5UWb5RyputVARx2E9ONxxm2oadqvolbm/TBw00WxDtJ/YRZ8ZS4R0:/nRXtVw2E9cxzxViGWxDr/IGSB

    • Modifies firewall policy service

    • Drops file in Drivers directory

    • Sets service image path in registry

    • Executes dropped EXE

    • Impair Defenses: Safe Mode Boot

    • Loads dropped DLL

    • Adds Run key to start application

    • Installs/modifies Browser Helper Object

      BHOs are DLL modules which act as plugins for Internet Explorer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

2
T1547.001

Browser Extensions

1
T1176

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

2
T1547.001

Defense Evasion

Modify Registry

5
T1112

Impair Defenses

2
T1562

Disable or Modify System Firewall

1
T1562.004

Safe Mode Boot

1
T1562.009

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Tasks