Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
IcedID used the `ipconfig /all` command and a batch script to gather network information. |
| T1027.002 Software Packing |
IcedID has packed and encrypted its loader module. |
| T1027.003 Steganography |
IcedID has embedded binaries within RC4 encrypted .png files. |
| T1027.009 Embedded Payloads |
IcedID has embedded malicious functionality in a legitimate DLL file. |
| T1027.013 Encrypted/Encoded File |
IcedID has utilzed encrypted binaries and base64 encoded strings. |
| T1036.005 Match Legitimate Resource Name or Location |
IcedID has modified legitimate .dll files to include malicious code. |
| T1047 Windows Management Instrumentation |
IcedID has used WMI to execute binaries. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
IcedID has exfiltrated collected data via HTTPS. |
| T1053.005 Scheduled Task |
IcedID has created a scheduled task to establish persistence. |
| T1055.004 Asynchronous Procedure Call |
IcedID has used |
| T1055.012 Process Hollowing |
IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing. |
| T1059.005 Visual Basic |
IcedID has used obfuscated VBA string expressions. |
| T1069 Permission Groups Discovery |
IcedID has the ability to identify Workgroup membership. |
| T1071.001 Web Protocols |
IcedID has used HTTPS in communications with C2. |
| T1082 System Information Discovery |
IcedID has the ability to identify the computer name and OS version on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.