2021-03-19 - ICEDID (BOKBOT) INFECTION
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2021-03-19-IOCs-for-IcedID-infection.txt.zip 1.5 kB (1,518 bytes)
- 2021-03-19-IcedID-infection-traffic-carved.pcap.zip 3.4 MB (3,396,800 bytes)
- 2021-03-19-IcedID-malware-and-artiacts.zip 998 kB (997,744 bytes)
IMAGES
Shown above: Screenshot of spreadsheet used to kick off this infection.
Shown above: Traffic from an infection filtered in Wireshark.
Shown above: Malware/artifacts from the infected Windows host.
Shown above: Scheduled task to keep IcedID infection persistent.
Click here to return to the main page.