ATT&CKReferencesJuniper IcedID June 2020

Juniper IcedID June 2020

Kimayong, P. (2020, June 18). COVID-19 and FMLA Campaigns used to install new IcedID banking malware. Retrieved July 14, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareIcedID

IcedID has packed and encrypted its loader module.

T1027.003
Steganography
MalwareIcedID

IcedID has embedded binaries within RC4 encrypted .png files.

T1027.013
Encrypted/Encoded File
MalwareIcedID

IcedID has utilzed encrypted binaries and base64 encoded strings.

T1047
Windows Management Instrumentation
MalwareIcedID

IcedID has used WMI to execute binaries.

T1053.005
Scheduled Task
MalwareIcedID

IcedID has created a scheduled task to establish persistence.

T1059.005
Visual Basic
MalwareIcedID

IcedID has used obfuscated VBA string expressions.

T1071.001
Web Protocols
MalwareIcedID

IcedID has used HTTPS in communications with C2.

T1105
Ingress Tool Transfer
MalwareIcedID

IcedID has the ability to download additional modules and a configuration file from C2.

T1106
Native API
MalwareIcedID

IcedID has called ZwWriteVirtualMemory, ZwProtectVirtualMemory, ZwQueueApcThread, and NtResumeThread to inject itself into a remote process.

T1185
Browser Session Hijacking
MalwareIcedID

IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser.

T1204.002
Malicious File
MalwareIcedID

IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL.

T1218.007
Msiexec
MalwareIcedID

IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader.

T1566.001
Spearphishing Attachment
MalwareIcedID

IcedID has been delivered via phishing e-mails with malicious attachments.

T1573.002
Asymmetric Cryptography
MalwareIcedID

IcedID has used SSL and TLS in communications with C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.