IcedID Malware Analizi
Dosya Ozellikleri
SHA256: f1f61b0e96c172a24fba71806829c486b43e141493c78ec4bb895de760134316
MD5: 25add83261efe6a0a348b9a432060085
Dosya Tipi: exe
Boyut: 153,600 byte
Ilk Gorulme: 2022-11-14
AV Imzasi: IcedID
Imphash: d057690aaef589b45e702be655691a5a
Raporlayan: k3dg3
Etiketler: 3310689666, exe, IcedID, trolspeaksunt
Statik analiz: metadata tabanli (ornek indirilmedi)
IcedID — 악성코드 프로필
IcedID banking trojan. info_IR MSI invoice lure. ConnectNamedPipe named pipe IPC. IsDebuggerPresent double anti-debug.
기술 세부 정보
IcedID (BazarLoader) is a banking trojan and loader first observed 2017. Man-in-the-browser attacks targeting banking credentials via web injections. BazarLoader component: delivers Ryuk, Conti, and other ransomware payloads. Uses HTTPS with TLS for C2, custom binary protocol. Delivered via malspam (Office macros, password-protected archives). Notable for forked distribution: Standard IcedID vs. Lite variant (reduced banking features). Lite/BackConnect IcedID evolved to focus solely on ransomware delivery. C2 uses high entropy DGA-like domains with .com TLD.
귀속 / 위협 행위자
TA551 (Shathak), TA578
기능 및 동작
IOC 목록 (1 개 지표)
# FILEPATH
f1f61b0e96c172a24fba71806829c486b43e141493c78ec4bb895de760134316
| 유형 | 값 | 메모 |
|---|---|---|
| filepath | f1f61b0e96c172a24fba71806829c486b43e141493c78ec4bb895de760134316 | PDB |
C2 서버 (이 패밀리에 대해 5개의 서버 기록)
| 주소 | 유형 | 포트 | 프로토콜 | 상태 | 국가 |
|---|---|---|---|---|---|
| 162.33.177.167 | ip | 443 | HTTPS | inactive | US |
| topfiveaccounting.com | domain | 443 | HTTPS | inactive | US |
| 185.220.100.240 | ip | 443 | HTTPS | inactive | DE |
| nsabx.gg | domain | 443 | HTTPS | inactive | — |
| 5.8.88.226 | ip | 443 | HTTPS | sinkholed | RU |
C2 주소는 KEYDAL 팀이 수동으로 검증한 악성코드 샘플에서만 제공됩니다. 상업적 사용은 금지됩니다.