Files
splunk-security_content/docs/_stories/icedid.md
2022-03-09 11:36:28 +01:00

4.5 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
IcedID 2021-07-29 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint
Actions on Objectives
Exploitation
Reconnaissance

Try in Splunk Security Cloud{: .btn .btn--success}

Description

Leverage searches that allow you to detect and investigate unusual activities that might relate to the IcedID banking trojan, including looking for file writes associated with its payload, process injection, shellcode execution and data collection.

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2021-07-29
  • Author: Teoderick Contreras, Splunk
  • ID: 1d2cc747-63d7-49a9-abb8-93aa36305603

Narrative

IcedId banking trojan campaigns targeting banks and other vertical sectors.This malware is known in Microsoft Windows OS targetting browser such as firefox and chrom to steal banking information. It is also known to its unique payload downloaded in C2 where it can be a .png file that hides the core shellcode bot using steganography technique or gzip dat file that contains "license.dat" which is the actual core icedid bot.

Detections

Name Technique Type
Account Discovery With Net App None TTP
CHCP Command Execution None TTP
CMD Carry Out String Command Parameter None Hunting
Create Remote Thread In Shell Application None TTP
Disable Schedule Task None TTP
Drop IcedID License dat None Hunting
Eventvwr UAC Bypass None TTP
FodHelper UAC Bypass None TTP
IcedID Exfiltrated Archived File Creation None Hunting
Mshta spawning Rundll32 OR Regsvr32 Process None TTP
NLTest Domain Trust Discovery None TTP
Office Application Spawn Regsvr32 process None TTP
Office Application Spawn rundll32 process None TTP
Office Document Executing Macro Code None TTP
Office Product Spawning MSHTA None TTP
Registry Keys Used For Persistence None TTP
Regsvr32 with Known Silent Switch Cmdline None Anomaly
Rundll32 Create Remote Thread To A Process None TTP
Rundll32 CreateRemoteThread In Browser None TTP
Rundll32 DNSQuery None TTP
Rundll32 Process Creating Exe Dll Files None TTP
Schedule Task with Rundll32 Command Trigger None TTP
Sqlite Module In Temp Folder None TTP
Suspicious IcedID Rundll32 Cmdline None TTP
Suspicious Rundll32 PluginInit None TTP
WinEvent Scheduled Task Created Within Public Path None TTP
WinEvent Windows Task Scheduler Event Action Started None Hunting

Reference

source | version: 1