IcedID Banking Trojan returns with new TTPS – Detection & Response - Security Investigation
Common Information
Type Value
UUID ac1d3633-5173-45e0-9129-04e33f14ee8a
Fingerprint 40270176afb2499b
Analysis status DONE
Considered CTI value 0
Text language
Published June 24, 2022, 8 p.m.
Added to db Sept. 26, 2022, 9:33 a.m.
Last updated Nov. 17, 2024, 10:40 p.m.
Headline IcedID Banking Trojan returns with new TTPS – Detection & Response
Title IcedID Banking Trojan returns with new TTPS – Detection & Response - Security Investigation
Detected Hints/Tags/Attributes 27/2/29
Attributes
Details Type #Events CTI Value
Details Domain 1
bredofenction.com
Details Domain 48
storage.googleapis.com
Details Domain 1
rj66f513.appspot.com
Details Domain 1
aniogarphianeo.com
Details Domain 1
carbrownleger.com
Details File 409
c:\windows\system32\cmd.exe
Details File 1
c:\users\admin\appdata\local\temp\document 2.iso
Details File 2
isoburn.exe
Details File 1
c:\windows\system32\isoburn.exe
Details File 1
c:\users\admin\downloads\poweriso8.exe
Details File 1
poweris08.exe
Details File 1
bx9pomc.htm
Details File 16
document.zip
Details File 2
'%.iso
Details File 2126
cmd.exe
Details File 459
regsvr32.exe
Details File 1
'%poweriso8.exe
Details File 1
poweriso8.exe
Details File 49
process.exe
Details File 7
commandline.key
Details File 6
image.key
Details File 2
'.iso
Details File 1
'poweriso8.exe
Details File 1
'isoburn.exe
Details File 10
'regsvr32.exe
Details sha256 1
7354552c28ad25c6c83e84f1ef7da0a8a53dc9ba8177416c1f4be229130505b5
Details Url 1
https://www.virustotal.com/gui/file/7354552c28ad25c6c83e84f1ef7da0a8a53dc9ba8177416c1f4be229130505b5
Details Url 1
https://storage.googleapis.com/rj66f513.appspot.com/o/bx9pomc.htm#
Details Url 1
https://firebasestorage.googleapis.com/v0/b/causal-tracker-354112.appspot.com/o/q4dlc3kw3k/document.zip?alt=media&token=70ade0dd