DFIR. (2022, April 25). Quantum Ransomware. Retrieved July 26, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareIcedID | IcedID used the `ipconfig /all` command and a batch script to gather network information. |
| T1053.005 Scheduled Task |
MalwareIcedID | IcedID has created a scheduled task to establish persistence. |
| T1055.012 Process Hollowing |
MalwareIcedID | IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing. |
| T1071.001 Web Protocols |
MalwareIcedID | IcedID has used HTTPS in communications with C2. |
| T1082 System Information Discovery |
MalwareIcedID | IcedID has the ability to identify the computer name and OS version on a compromised host. |
| T1087.002 Domain Account |
MalwareIcedID | IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect. |
| T1105 Ingress Tool Transfer |
MalwareIcedID | IcedID has the ability to download additional modules and a configuration file from C2. |
| T1135 Network Share Discovery |
MalwareIcedID | IcedID has used the `net view /all` command to show available shares. |
| T1204.002 Malicious File |
MalwareIcedID | IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL. |
| T1218.011 Rundll32 |
MalwareIcedID | |
| T1482 Domain Trust Discovery |
MalwareIcedID | |
| T1518.001 Security Software Discovery |
MalwareIcedID | IcedID can identify AV products on an infected host using the following command: |
| T1614.001 System Language Discovery |
MalwareIcedID | IcedID used the following command to check the country/language of the active console: |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.