Analytics Story: IcedID

Description

Leverage searches that allow you to detect and investigate unusual activities that might relate to the IcedID banking trojan, including looking for file writes associated with its payload, process injection, shellcode execution and data collection.

Why it matters

IcedId banking trojan campaigns targeting banks and other vertical sectors.This malware is known in Microsoft Windows OS targetting browser such as firefox and chrom to steal banking information. It is also known to its unique payload downloaded in C2 where it can be a .png file that hides the core shellcode bot using steganography technique or gzip dat file that contains "license.dat" which is the actual core icedid bot.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼
Rundll32 CreateRemoteThread In Browser Process Injection TTP
Regsvr32 with Known Silent Switch Cmdline Regsvr32 Anomaly
Windows PUA Named Pipe SMB/Windows Admin Shares, Process Injection, Inter-Process Communication Anomaly
Disable Defender Submit Samples Consent Feature Disable or Modify Tools TTP
Registry Keys Used For Persistence Registry Run Keys / Startup Folder TTP
Process Creating LNK file in Suspicious Location Spearphishing Link Anomaly
Disable Schedule Task Disable or Modify Tools Anomaly
Rundll32 DNSQuery Rundll32 TTP
WinEvent Scheduled Task Created Within Public Path Scheduled Task TTP
FodHelper UAC Bypass Modify Registry, Bypass User Account Control TTP
Sqlite Module In Temp Folder Data from Local System TTP
Windows File Download Via PowerShell PowerShell, Ingress Tool Transfer Anomaly
Disable Defender Enhanced Notification Disable or Modify Tools TTP
Windows Sensitive Group Discovery With Net Domain Groups Anomaly
Suspicious Rundll32 PluginInit Rundll32 TTP
Suspicious IcedID Rundll32 Cmdline Rundll32 TTP
Disable Defender MpEngine Registry Disable or Modify Tools TTP
Suspicious Regsvr32 Register Suspicious Path Regsvr32 TTP
Windows ISO LNK File Creation Malicious Link, Spearphishing Attachment Hunting
Disabling Defender Services Disable or Modify Tools TTP
Windows Phishing Recent ISO Exec Registry Spearphishing Attachment Hunting
Windows Office Product Spawned Uncommon Process Spearphishing Attachment TTP
CMD Carry Out String Command Parameter Windows Command Shell Hunting
Suspicious Copy on System32 Rename Legitimate Utilities Anomaly
Executables Or Script Creation In Temp Path Masquerading Anomaly
Disable Defender AntiVirus Registry Disable or Modify Tools TTP
RunDLL Loading DLL By Ordinal Rundll32 TTP
Executable File Written in Administrative SMB Share SMB/Windows Admin Shares TTP
Eventvwr UAC Bypass Bypass User Account Control TTP
Powershell Using memory As Backing Store PowerShell TTP
Wmic NonInteractive App Uninstallation Disable or Modify Tools Hunting
Schedule Task with Rundll32 Command Trigger Scheduled Task/Job TTP
Disable Defender BlockAtFirstSeen Feature Disable or Modify Tools TTP
Rundll32 Process Creating Exe Dll Files Rundll32 TTP
Detect PsExec With accepteula Flag SMB/Windows Admin Shares TTP
Windows AdFind Exe Remote System Discovery TTP
Windows Group Discovery Via Net Local Groups, Domain Groups Hunting
Network Share Discovery Via Dir Command Network Share Discovery Hunting
Windows Office Product Loading VBE7 DLL Spearphishing Attachment Anomaly
Drop IcedID License dat Malicious File Hunting
Powershell Fileless Script Contains Base64 Encoded Content Obfuscated Files or Information, PowerShell TTP
Windows WMI Process Call Create Windows Management Instrumentation Hunting
Create Remote Thread In Shell Application Process Injection TTP
Suspicious Rundll32 dllregisterserver Rundll32 TTP
WinEvent Windows Task Scheduler Event Action Started Scheduled Task Hunting
Windows Curl Download to Suspicious Path Ingress Tool Transfer TTP
Windows Uncommon Remote Thread Creation In Browser Process Dynamic-link Library Injection Anomaly
Network Connection Discovery With Arp System Network Connections Discovery Hunting
Windows Suspicious Process File Path Match Legitimate Resource Name or Location, Create or Modify System Process TTP
Rundll32 Create Remote Thread To A Process Process Injection TTP
NLTest Domain Trust Discovery Domain Trust Discovery TTP
Powershell Processing Stream Of Data PowerShell Anomaly
IcedID Exfiltrated Archived File Creation Archive via Utility Hunting
Mshta spawning Rundll32 OR Regsvr32 Process Mshta TTP
Disable Defender Spynet Reporting Disable or Modify Tools TTP
Executables Or Script Creation In Suspicious Path Masquerading Anomaly
Remote WMI Command Attempt Windows Management Instrumentation TTP

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼
Sysmon EventID 8 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 1 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Windows Event Log Security 4688 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
CrowdStrike ProcessRollup2 Other crowdstrike:events:sensor crowdstrike
Sysmon EventID 17 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 18 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 13 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 11 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 22 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Windows Event Log Security 4698 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Cisco Network Visibility Module Flow Data Network icon Network cisco:nvm:flowdata:v2 not_applicable
Windows Event Log Security 5145 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Powershell Script Block Logging 4104 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
Windows Event Log Security 5140 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Sysmon EventID 7 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Windows Event Log TaskScheduler 200 Windows icon Windows wineventlog WinEventLog:Microsoft-Windows-TaskScheduler/Operational
Windows Event Log TaskScheduler 201 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security

References


Source: GitHub | Version: 2