ICEDIDs network infrastructure is alive and well
ID: ffef9393-6130-527b-89aa-9e627575b802
STIX ID: report--ffef9393-6130-527b-89aa-9e627575b802
Feed Name: Elastic Security Labs
Elastic Security Labs presents a technical analysis of the ICEDID (Bokbot) banking trojan, describing its multi-stage infection chain (phishing → ISO/LNK → rundll32 loader), in-memory payload loading, persistence via scheduled tasks or registry run keys, and a rich set of modules for credential theft, proxying, command execution, and shellcode injection. The report emphasizes ICEDID's TLS certificate pinning used to validate C2 servers, details methods to discover and validate C2 infrastructure via Censys and a Check Point script (yielding 103 confirmed ICEDID IPs), and supplies IOCs, a YARA rule for the certificate pinning routine, and scripts to ingest results into Elasticsearch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
