Kenefick , I. (2022, December 23). IcedID Botnet Distributors Abuse Google PPC to Distribute Malware. Retrieved July 24, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.009 Embedded Payloads |
MalwareIcedID | IcedID has embedded malicious functionality in a legitimate DLL file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIcedID | IcedID has modified legitimate .dll files to include malicious code. |
| T1189 Drive-by Compromise |
MalwareIcedID | IcedID has cloned legitimate websites/applications to distribute the malware. |
| T1218.007 Msiexec |
MalwareIcedID | IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader. |
| T1218.011 Rundll32 |
MalwareIcedID | |
| T1497 Virtualization/Sandbox Evasion |
MalwareIcedID | IcedID has manipulated Keitaro Traffic Direction System to filter researcher and sandbox traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.