Dosya Kimligi
| SHA256 | c7441ea5c8a42ce0a3afa24991c8a7f328434d2eba9c3d2a2fc26543c9288f9a |
|---|---|
| Boyut | 405.504 byte |
| String Sayisi | 2.067 |
Analiz Bulgulari
Bu IcedID ornegi agir sekilde paketlenmistir. Cleartext C2 adresi, URL veya email IOC bulunamadi. IcedID, C2 IP listesini sifrelenmis blob icerisinde saklar ve runtime'da cozumler.
IcedID Mimarisi
- Birinci Asama: Paketli loader — anti-analiz ve sandbox kacis teknikleri
- Ikinci Asama: IcedID core DLL — bellekte sifresiz, diskte sifrelenmis
- C2 Haberlesme: HTTPS, encrypted C2 list
- Kalicilik: Zamanlanmis gorev veya COM hijacking
IcedID Downstream Payload'lar
| Payload | Amac |
|---|---|
| Cobalt Strike Beacon | Lateral movement, enterprise penetrasyonu |
| Ransomware | Conti, REvil, Quantum yayilimi |
| Credential Harvester | Domain credential theft |
| Network Reconnaissance | AD enumeration |
IcedID Hakkinda
IcedID (Bokbot), 2017 yilinda ortaya cikan banking trojan'dan gelismis enterprise loader'a donusen bir malware ailesidir. Emotet, Qakbot ve TrickBot ile birlikte calisarak buyuk ransomware operasyonlari icin ilk erisim ve lateral movement saglar. Conti ve Quantum ransomware operasyonlarinda yaygin kullanilmistir.
IOC
| SHA256 | c7441ea5c8a42ce0a3afa24991c8a7f328434d2eba9c3d2a2fc26543c9288f9a |
|---|---|
| C2 | Runtime decrypt (paketli) |
IcedID — Malware Profile
IcedID banking trojan. info_IR MSI invoice lure. ConnectNamedPipe named pipe IPC. IsDebuggerPresent double anti-debug.
Technical Details
IcedID (BazarLoader) is a banking trojan and loader first observed 2017. Man-in-the-browser attacks targeting banking credentials via web injections. BazarLoader component: delivers Ryuk, Conti, and other ransomware payloads. Uses HTTPS with TLS for C2, custom binary protocol. Delivered via malspam (Office macros, password-protected archives). Notable for forked distribution: Standard IcedID vs. Lite variant (reduced banking features). Lite/BackConnect IcedID evolved to focus solely on ransomware delivery. C2 uses high entropy DGA-like domains with .com TLD.
Attribution / Threat Actor
TA551 (Shathak), TA578
Capabilities & Behavior
IOC List (1 indicators)
# SHA256
c7441ea5c8a42ce0a3afa24991c8a7f328434d2eba9c3d2a2fc26543c9288f9a
| Type | Value | Note |
|---|---|---|
| sha256 | c7441ea5c8a42ce0a3afa24991c8a7f328434d2eba9c3d2a2fc26543c9288f9a |
C2 Servers (5 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| 162.33.177.167 | ip | 443 | HTTPS | active | US |
| topfiveaccounting.com | domain | 443 | HTTPS | inactive | US |
| 185.220.100.240 | ip | 443 | HTTPS | inactive | DE |
| nsabx.gg | domain | 443 | HTTPS | inactive | — |
| 5.8.88.226 | ip | 443 | HTTPS | sinkholed | RU |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.