ATT&CKReferencesTrendmicro_IcedID

Trendmicro_IcedID

Kenefick , I. (2022, December 23). IcedID Botnet Distributors Abuse Google PPC to Distribute Malware. Retrieved July 24, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027.009
Embedded Payloads
MalwareIcedID

IcedID has embedded malicious functionality in a legitimate DLL file.

T1036.005
Match Legitimate Resource Name or Location
MalwareIcedID

IcedID has modified legitimate .dll files to include malicious code.

T1189
Drive-by Compromise
MalwareIcedID

IcedID has cloned legitimate websites/applications to distribute the malware.

T1218.007
Msiexec
MalwareIcedID

IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader.

T1218.011
Rundll32
MalwareIcedID

IcedID has used rundll32.exe to execute the IcedID loader.

T1497
Virtualization/Sandbox Evasion
MalwareIcedID

IcedID has manipulated Keitaro Traffic Direction System to filter researcher and sandbox traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.