Kimayong, P. (2020, June 18). COVID-19 and FMLA Campaigns used to install new IcedID banking malware. Retrieved July 14, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareIcedID | IcedID has packed and encrypted its loader module. |
| T1027.003 Steganography |
MalwareIcedID | IcedID has embedded binaries within RC4 encrypted .png files. |
| T1027.013 Encrypted/Encoded File |
MalwareIcedID | IcedID has utilzed encrypted binaries and base64 encoded strings. |
| T1047 Windows Management Instrumentation |
MalwareIcedID | IcedID has used WMI to execute binaries. |
| T1053.005 Scheduled Task |
MalwareIcedID | IcedID has created a scheduled task to establish persistence. |
| T1059.005 Visual Basic |
MalwareIcedID | IcedID has used obfuscated VBA string expressions. |
| T1071.001 Web Protocols |
MalwareIcedID | IcedID has used HTTPS in communications with C2. |
| T1105 Ingress Tool Transfer |
MalwareIcedID | IcedID has the ability to download additional modules and a configuration file from C2. |
| T1106 Native API |
MalwareIcedID | IcedID has called |
| T1185 Browser Session Hijacking |
MalwareIcedID | IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser. |
| T1204.002 Malicious File |
MalwareIcedID | IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL. |
| T1218.007 Msiexec |
MalwareIcedID | IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader. |
| T1566.001 Spearphishing Attachment |
MalwareIcedID | IcedID has been delivered via phishing e-mails with malicious attachments. |
| T1573.002 Asymmetric Cryptography |
MalwareIcedID | IcedID has used SSL and TLS in communications with C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.