Kessem, L., et al. (2017, November 13). New Banking Trojan IcedID Discovered by IBM X-Force Research. Retrieved July 14, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.004 Asynchronous Procedure Call |
MalwareIcedID | IcedID has used |
| T1069 Permission Groups Discovery |
MalwareIcedID | IcedID has the ability to identify Workgroup membership. |
| T1082 System Information Discovery |
MalwareIcedID | IcedID has the ability to identify the computer name and OS version on a compromised host. |
| T1087.002 Domain Account |
MalwareIcedID | IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect. |
| T1087.003 Email Account |
MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| T1105 Ingress Tool Transfer |
MalwareIcedID | IcedID has the ability to download additional modules and a configuration file from C2. |
| T1114 Email Collection |
MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| T1185 Browser Session Hijacking |
MalwareIcedID | IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser. |
| T1204.002 Malicious File |
MalwareEmotet | Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareIcedID | IcedID has established persistence by creating a Registry run key. |
| T1555.003 Credentials from Web Browsers |
MalwareEmotet | Emotet has been observed dropping browser password grabber modules. |
| T1566.001 Spearphishing Attachment |
MalwareEmotet | Emotet has been delivered by phishing emails containing attachments. |
| T1573.002 Asymmetric Cryptography |
MalwareIcedID | IcedID has used SSL and TLS in communications with C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.