IcedID GZIPLOADER Analysis
ID: 4af89350-dbe2-5153-8276-9d21ac64dd3c
STIX ID: report--4af89350-dbe2-5153-8276-9d21ac64dd3c
Feed Name: Binary Defense Blog
Binary Defense analyzes a new IcedID variant delivered by Qakbot's TR malspam affiliate that replaces the photoloader with a novel 'gziploader' first stage and updated encryption to hide configuration and embedded strings. The report reverse-engineers the loader and main bot, documents payload layout and memory loading, describes post-infection behaviors (credential and cookie theft, browser hooking, DLL injection, Exec/ExecAdmin behavior, and Cobalt Strike staging), provides detection opportunities and IOCs (files, commands, domains, IPs), and releases a decryption tool to assist defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
