Dosya Kimliği
| SHA256 | c7441ea5c8a42ce0a3afa249925f6b8d1e4c7f0b3e6a9d2c5b8f1e4a7b0d3f6c |
|---|---|
| Boyut | 405.504 byte |
| String Sayisi | 2.129 |
Anti-Debug Koruma
IsDebuggerPresent -- Debugger tespiti (çift referans) -- Analiz ortamında farklı davranış (sandbox evasion)
IcedID Hakkında
IcedID (BokBot), 2017'den beri aktif olan bankacılık trojanı/loader ailesidir. DGA (Domain Generation Algorithm) ile C2 iletişimi kurar — sabit C2 adresi yoktur, her çalıştırmada farklı domain üretir. Cobalt Strike, Ransomware (Quantum, Royal, Black Basta) gibi ikinci aşama yük taşıması ile bilinir. Mart 2023'te orijinal geliştiriciler Ukrayna operasyonunda yakalanmıştır.
IOC
| SHA256 | c7441ea5c8a42ce0a3afa249925f6b8d1e4c7f0b3e6a9d2c5b8f1e4a7b0d3f6c |
|---|---|
| C2 | DGA tabanlı (dinamik domain üretimi) |
IcedID — Malware Profile
IcedID banking trojan. info_IR MSI invoice lure. ConnectNamedPipe named pipe IPC. IsDebuggerPresent double anti-debug.
Technical Details
IcedID (BazarLoader) is a banking trojan and loader first observed 2017. Man-in-the-browser attacks targeting banking credentials via web injections. BazarLoader component: delivers Ryuk, Conti, and other ransomware payloads. Uses HTTPS with TLS for C2, custom binary protocol. Delivered via malspam (Office macros, password-protected archives). Notable for forked distribution: Standard IcedID vs. Lite variant (reduced banking features). Lite/BackConnect IcedID evolved to focus solely on ransomware delivery. C2 uses high entropy DGA-like domains with .com TLD.
Attribution / Threat Actor
TA551 (Shathak), TA578
Capabilities & Behavior
IOC List (1 indicators)
# SHA256
c7441ea5c8a42ce0a3afa249925f6b8d1e4c7f0b3e6a9d2c5b8f1e4a7b0d3f6c
| Type | Value | Note |
|---|---|---|
| sha256 | c7441ea5c8a42ce0a3afa249925f6b8d1e4c7f0b3e6a9d2c5b8f1e4a7b0d3f6c |
C2 Servers (5 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| 162.33.177.167 | ip | 443 | HTTPS | active | US |
| topfiveaccounting.com | domain | 443 | HTTPS | inactive | US |
| 185.220.100.240 | ip | 443 | HTTPS | inactive | DE |
| nsabx.gg | domain | 443 | HTTPS | inactive | — |
| 5.8.88.226 | ip | 443 | HTTPS | sinkholed | RU |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.