2020-03-20 - ICEDID FROM INFO_03_20.DOC
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
 
ASSOCIATED FILES:
- 2020-03-20-IcedID-IOCs.txt.zip 2.0 kB (1,969 bytes)
 - 2020-03-20-IcedID-traffic.pcap.zip 3.3 MB (3,308,199 bytes)
 - 2020-03-20-IcedID-malware-and-artifacts.zip 1.7 MB (1,657,249 bytes)
 
IMAGES

Shown above:  Screenshot of the Word doc.

Shown above:  Traffic from an infection filtered in Wireshark.

Shown above:  Initial artifacts seen for a successful infection (I had to use MSHTA.EXE saved here as "microsoft.com" for this to work).

Shown above:  Follow-up artifacts seen after a successful infection.

Shown above:  Scheduled task to keep IcedID persistent on my infected lab host.
Click here to return to the main page.
