mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
20 lines
1.2 KiB
YAML
20 lines
1.2 KiB
YAML
name: IcedID
|
|
id: 1d2cc747-63d7-49a9-abb8-93aa36305603
|
|
version: 2
|
|
creation_date: '2021-07-29'
|
|
modification_date: '2026-05-13'
|
|
author: Teoderick Contreras, Splunk
|
|
status: production
|
|
description: Leverage searches that allow you to detect and investigate unusual activities that might relate to the IcedID banking trojan, including looking for file writes associated with its payload, process injection, shellcode execution and data collection.
|
|
narrative: IcedId banking trojan campaigns targeting banks and other vertical sectors.This malware is known in Microsoft Windows OS targetting browser such as firefox and chrom to steal banking information. It is also known to its unique payload downloaded in C2 where it can be a .png file that hides the core shellcode bot using steganography technique or gzip dat file that contains "license.dat" which is the actual core icedid bot.
|
|
references:
|
|
- https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/
|
|
- https://app.any.run/tasks/48414a33-3d66-4a46-afe5-c2003bb55ccf/
|
|
category:
|
|
- Malware
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|