Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
102
Global rank
101 infographic chevron month
Month rank
137 infographic chevron week
Week rank

IcedID is a banking trojan-type malware which allows attackers to utilize it to steal banking credentials of the victims. IcedID aka BokBot mainly targets businesses and steals payment information, it also acts as a loader and can deliver another viruses or download additional modules.

Trojan
Type
Unknown
Origin
1 September, 2017
First seen
1 September, 2026
Last seen
Also known as
BokBot

How to analyze IcedID with ANY.RUN

Type
Unknown
Origin
1 September, 2017
First seen
1 September, 2026
Last seen

IOCs

IP addresses
104.18.12.149
57.153.246.3
104.18.94.41
150.171.109.106
74.178.76.128
142.251.154.119
34.246.85.92
94.237.85.247
162.159.207.0
2.19.252.152
142.251.13.138
23.52.181.141
150.171.28.11
142.251.110.94
52.123.243.83
185.227.69.72
150.171.109.194
184.86.103.12
3.65.98.86
48.192.1.65
Hashes
5020a647ccd61a045f2c1fbecbd95d11da38706ea8adea6f7daa44e6fbd57ed3
28042dd4a92a0033b8f1d419b9e989c5b8e32d1d2d881f5c8251d58ce35b9063
0d7240d074ba544c90df72d5e339978aa2edc19f4a02c0a302718d851b11c384
319cd301cf40be03c00cd086560d4e810e0f6d0dbfdc2d28d6af3522c027cf49
60a172e81a2c07e2006465f8625306e385b4fe57fca02ad5da8af91527ed6de9
b22118c3159d96c061e3e6f668cb26f0c679bb96fccd2c788584d3e2a64c4c35
bd2c2cf0631d881ed382817afcce2b093f4e412ffb170a719e2762f250abfea4
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
0ddfb724096ba9094f02ef19b18862b00e1eb11d7e9a636f549b7f679febb93e
349c2840415a317856995fb9de0e69691027b04dc910053d4914b1f78af2d8f5
70211a3f90376bbc61f49c22a63075d1d4ddd53f0aefa976216c46e6ba39a9f4
4259e53d48a3fed947f561ff04c7f94446bedd64c87f52400b2cb47a77666aaa
5ae7c0972fd4e4c4ae14c0103602ca854377fefcbccd86fa68cfc5a6d1f99f60
282696487ea5dc781788d5d8477b977f72b7c70f201c2af0cfe7e1a9fd8d749a
acd49f2aa36d4efb9c4949e2d3cc2bd7aee384c2ced7aa9e66063da4150fcb00
fc9d0d0482c63ab7f238bc157c3c0fed97951ccf2d2e45be45c06c426c72cb52
e2e4d97c20d4478e8e947480c8f6c71a2c795776d405366be70db82e4ea4ba77
8ee48d94f5591c25df70ad41f7f6bc04431a06e3a92f9668007cd0e9efd0c7ae
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
be280e7a371073e313dbb78e08a4499e896916d0baffef5767425d90ff29f20d
Domains
th.bing.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
stun1.l.google.com
edge.microsoft.com
edge-cloud-resource-static.azureedge.net
a.fsdn.com
b.6sc.co
region1.analytics.google.com
ipv6.6sc.co
ml314.com
processhacker.sourceforge.net
fonts.gstatic.com
ps.eyeota.net
idsync.rlcdn.com
stun.cloudflare.com
challenges.cloudflare.com
www.googletagmanager.com
crl3.digicert.com
analytics.slashdotmedia.com
static.edge.microsoftapp.net
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:kjxfvsvh8ypfhfrs8en0av0oiakrw5rwfgyerwnmw08&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://google.com/
https://www.google.com/
https://www.google.com/xjs/_/ss/k=xjs.hd.8znh1jabwai.l.b1.o/am=aaaeaaagaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqaaemaaaaaqcgaqaaaaaaaagbacaaaaeaaaaaaaadcaqaaaamaaaaaaaaaaaaaaaaaaiaaacabaaaaaaaagaacaagaaaaagagaaaaabiaakaaagaaaaaaaaaaaaaiaaaaaaabacagaaaaaaaaaaaaaqaiaaaaaaaaaacawgcaaaacayaaaaaaaaaaaaaaaaaaaaaaaaaaaiaqgaqaqaaaaaaaeaaaaaaceaeiiagabcibgqqaaaaaawaiaaaaaaecjyeaiaaaaaaaaaaaagabaeagbbaaaaaabaabaaeaaqaaaaqqageebajcoaaiaaieaaaaabaaaaaaaaqaaaaaaaaaaaeqaaaaaaaaaaabaagameaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaka/d=1/ed=1/br=1/rs=act90ofyy6a1ssn60iqx_pibawusx0cfhw/m=cdos,hsm,jsa,mb4zub,cet90b,snun3,qddgke,stsdmc,dtl0hd,ehdfl,yv5bee,d,csi?cb=121509378
https://www.google.com/xjs/_/js/k=xjs.hd.de.qts9wvqscfa.2019.o/am=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaeaggaaaaibaaaaaaaaaaaaaaaayaaaaaaaaaaaaaaaaaaaaaaayiaasabaaaaaaaagaacaagagaaagaaaaayabiaakaaaaayaaaaaaaaaaaaaaaaaaabagagaaabcaaaa4a8gwaeaaaaaaaaaqaiagaaaaaaaagabaabacaaaaeaacaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaeaaaaaacgaaaaaaaqaaaaaaaaaaaaaaaaaaaaaaaaaqaaaaaaaaaaaaaaaaaaabacgaaeaaabaaaaaaaaaaaaaaaaaaamaaaaaaaaaaaaaaaaaaaqaaaaaaaaqaaabaahaaaaaaaaaaaaiacaaaaeahqoabhhquaaaaaaaaaaaaaaaaaaaaaaaaaabaaawwc6kgaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaakgnaaaaaaaasbg/d=1/ed=1/dg=4/br=1/rs=act90ohyxzjs8yjgrs1si2ebu7ah2zbsxg/ee=alejib:b8glwd;afeap:tkrajf;bmxagc:e5bfse;bgs6mb:fidj5d;bjwmce:cxx2wb;bujtu:v6yjn;ciztgb:kqhykb;cxxawb:yyrlvc;dqeued:fevhcf;dulqb:rkfg5c;dkk6ge:jzmw9e;dpcr3d:zl72xf;eabsz:mxzt9d;esrpqc:mntjvc;evnhjf:pw70gc;ejxhpb:pshqh;emz2bf:zr1jrb;enlcnd:wehg4;f54iae:zgsfh;f9mqte:uorcbe;fsxmue:fizr8b;fkukfc:i8h2c;fmv9nc:o1tzwc;g0khtb:liaoz;glezl:j1a7od;hmddwe:g8qudb;htpxrd:gx8jab;ibadcc:ryqurb;ioglcf:b5lhvb;isdwvc:qzxzob;jxjsm:ii1rgf;jxs8fb:qj0suc;jqsq7d:y9ephe;jsbnhc:xd8iud;k08hxe:zmbglf;k5nytd:zdzcre;ka3p2:c3jnce;kdb6nb:fe9n2;koxck:ozqgte;kqzwid:zmkkn;kdihef:bwtnj;kpraue:tia57b;lbgrlc:sdcwhb,xvmnvd;lbn8cf:bj9l0c;leikze:byftob,lsjvmc;lxa8b:q7odkd;lsnahb:ucglnb;mnkade:kmcd1d;nj1rfe:qtnobf;npkak:sdcwhb;nseox:lazg7b;njiwef:yvgi7d;np8qkd:dpx6qc;nyt6ic:jn2sgd;oifwub:qfoycd;ogagbe:cnte0;oiqe2c:tfpek;ook5v:sp69o;oohiye:mpeaqb;pjplud:poes9b;pptlxd:pjyjx;q1ow7b:x5csu;q7ij9c:bvlz3d;qe20be:gilto;qfoglf:pq2aoe;qgr0gd:mlhmy;qylf2b:paqyud;qw8feb:jpavue;r4iiib:qwfekf;r9ulx:cr7ufe;rcf5sd:x1kbmd;raf5me:mgvfmc;sltqo:kh1xye;smdl4c:ftfgo;snun3:zwdk9d,xd8kp;snk4je:wwmhg;sci3yc:e7hzgb,e7hzgb;shpf6e:n0pvgc;snahre:mgctob;swcqad:fxbczc;szqq3e:dnhofb;tiuvqd:lwtjwd;troz1d:vvvzjb;u96prd:fsr04;ubkjz:lgdjgb;udry1c:n0f29d,w50nvd,eps46d,wciyue;uvmjed:eesrsb;uvzb9c:ivpz6d;uyrieb:hztaqc;uyg7kb:wqd0g;v2htte:rolty;vgrfx:vfqbr;vmuem:pl7sbc;vn6jic:ddqyuf;vocgde:yquhtb;vha7bd:vamqff;vsaqsb:pgf2re;w9qsqe:yncwwc;wdgyfe:jcvoxd;wxtneb:qu9bmd;wfmdue:g3mjlb;wl55ib:vgbikb;y3c5sd:fgbfle;yizmrd:a1yn5d;yv5bee:ivpz6d;ynhubf:snssob;zsh6tc:qavyle;zweua:afr4cf;zloomb:p0i0ec;a56pne:jefcwb;aaje9c:whw6ef;acj9tf:qkftvc;avzq3e:emevib;az61od:artwj;aci7y:z5tr6c;buikwb:wmwehe;bcpxsc:gszljb;cet90b:ws9tlc;cftwae:gt8qnd;diosbb:zggg9b;dllj2:qqt3gf;dxdzv:a7qtqd;dowigb:ebz3mb,ebz3mb;dtl0hd:llqwfe;ebaesb:ck63tb;ebz5nd:audvde;ehdfl:ofjvkb;ejkchc:atg1be;eo3lse:uefomb;euoxy:ozjbq;g8nkx:u4mzkc;gaub4:tn6bme;gbfhr:qztzib;gtvsi:ekuoyd;h3myod:ws9tlc;hk67qb:qweo5b;hvic1b:kqhykb;hehb1:sfczq;hjro6e:f62sg;hlqgx:fwz1ic;hslsyc:vl118;hwovhd:zw4u8c;ifqykf:qihfr;jjj2g:kf2o2b;k1o0rf:pnould;k2qxcb:xy51pe;kbam9d:mkhygd;loo0vd:ota3ae;lbfkyf:mqgdud;liaz7d:kf2o2b;mmvogb:qdm7k;mwzs9c:fz5ukf;mtkmcc:zg5tfe;nbznze:cverjb;ne6ojf:fi4rsc;nebwnb:mxkx9d;njw4gd:dpfzh;nrdcw:sueode;ogtauc:soxfj;osunyd:ftfgo,ftfgo;oulnpc:ragdlc;oibhre:oumkrd;okuaud:witadb;pkjixd:vcenhc;pnsl2d:j9yuyc;pxdryb:jkokve;pj82le:ww04df;qgv2uc:hhi04c;qqeooc:kum7z,d7ysfd;qzx2fc:j0xre;qas3gd:yilg6e;qafbpd:sgy6zb;qavrxe:i0c9u;qddgke:d7ysfd,x4fyxe;rdexkf:fekkd;rmwaj:pms6sd;ropkz:hjoqoe;stsdmc:jksfdf;szmdvc:rdgefc;th4iie:ymry6;tesrsb:bmlai;toskvd:zcqp3;trzl0b:qy8pfe;uuqky:u2v3ud;veycnb:faqsvd;vrlmvf:iw9xo;vfvwpd:lcrkwe;w3bzcb:zpgaib;w9w86d:xwhueb,dt4g2b,gkd90c,lwvzve;wfpbg:jbgbbc;wqlyve:alufp;wr5frb:o1gjze,ttcote;wv5pjc:l8kgxe;x9n9ie:kh4qof;xbbsrc:new1qc;xparob:avqz9b;yil5ab:mt0zbd;ysnimc:cpibjd;yxtchf:kum7z;z97ygf:oug9te;zaigpb:sl0pxd/m=cdos,hsm,jsa,mb4zub,cet90b,snun3,qddgke,stsdmc,dtl0hd,ehdfl,yv5bee,d,csi?cb=121509378
https://www.google.com/async/hpba?yv=3&cs=0&ei=w9owaremkosy0pepz_dbyq0&async=_basejs:/xjs/_/js/k%3dxjs.hd.de.qts9wvqscfa.2019.o/am%3daaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaeaggaaaaibaaaaaaaaaaaaaaaayaaaaaaaaaaaaaaaaaaaaaaaqiaasabaaaaaaaagaacaagagaaagaaaaayabiaacaaaaayaaaaaaaaaaaaaaaaaaabagagaaabcaaaa4a8gwaeaaaaaaaaaqaiagaaaaaaaagabaabacaaaaeaacaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaeaaaaaacgaaaaaaaqaaaaaaaaaaaaaaaaaaaaaaaaaqaaaaaaaaaaaaaaaaaaabacgaaeaaabaaaaaaaaaaaaaaaaaaamaaaaaaaaaaaaaaaaaaaqaaaaaaaaqaaabaahaaaaaaaaaaaaiacaaaaeahqoabhhquaaaaaaaaaaaaaaaaaaaaaaaaaabaaawwcykgaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaakgnaaaaaaaasbg/dg%3d0/br%3d1/rs%3dact90ofubkimysfrppbuvak9dyvfebc9ea?cb%3d121509378,_basecss:/xjs/_/ss/k%3dxjs.hd.8znh1jabwai.l.b1.o/am%3daaaeaaagaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqaaemaaaaaqcgaqaaaaaaaagbacaaaaeaaaaaaaadcaqaaaamaaaaaaaaaaaaaaaaaaiaaacabaaaaaaaagaacaagaaaaagagaaaaabiaakaaagaaaaaaaaaaaaaiaaaaaaabacagaaaaaaaaaaaaaqaiaaaaaaaaaacawgcaaaacayaaaaaaaaaaaaaaaaaaaaaaaaaaaiaqgaqaqaaaaaaaeaaaaaaceaeiiagabcibgqqaaaaaawaiaaaaaaecjyeaiaaaaaaaaaaaagabaeagbbaaaaaabaabaaeaaqaaaaqqageebajcoaaiaaieaaaaabaaaaaaaaqaaaaaaaaaaaeqaaaaaaaaaaabaagameaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaka/br%3d1/rs%3dact90ofyy6a1ssn60iqx_pibawusx0cfhw?cb%3d121509378,_basecomb:/xjs/_/js/k%3dxjs.hd.de.qts9wvqscfa.2019.o/ck%3dxjs.hd.8znh1jabwai.l.b1.o/am%3daaaeaaagaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqaaemaaaaaqcgaqaaeaggaagbidaaaaeaaaaaaaadcayaaaamaaaaaaaaaaaaaaaaaayiaasabaaaaaaaagaacaagagaaagagaaayabiaakaaagayaaaaaaaaaaaiaaaaaaabaiagaaabcaaaa4a8gwamaaaaaaaaaqciwgcaaaacaygabaabacaaaaeaacaaaaaaaaaaaiaqgaqaqaaaaaaaeaaaaaaceaeiiagabcibgqqaaaqaawaiaaaaaaecjyeaiaaaaaaaqaaaagabaeagbbaaaaaabachaaeaaqbaaaqqageebajcoaaiaameaaaaabaaaaaaaaqaaaqaaaaaaaeqaaabaahaaaabaagameaiacaaaaeahqoabhhquaaaaaaaaaaaaaaaaaaaaaaaaaabaaawwc6kgaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaakgnaaaaaaaasbg/d%3d1/ed%3d1/dg%3d0/br%3d1/ujg%3d1/rs%3dact90of682cjylexef6jhjcqumjmiukfaw?cb%3d121509378,_fmt:prog,_id:_w9owaremkosy0pepz_dbyq0_18&sp_imghp=false&sp_hpep=2&sp_hpte=0&vet=10ahukewj3k5ggv82waxvkddqihu_4ntkqj-0kccy..i
https://www.google.com/gen_204?atyp=i&ct=bxjs&cad=&b=0&ei=w9owaremkosy0pepz_dbyq0&zx=1788269507930&opi=89978449
https://www.google.com/gen_204?ei=w9owaremkosy0pepz_dbyq0&vet=10ahukewj3k5ggv82waxvkddqihu_4ntkqhjahcdk..s&bl=mwmd&s=webhp&gl=de&pc=search_homepage&ismobile=false
https://www.google.com/gen_204?s=async&astyp=hpba&t=all&atyp=csi&ei=w9owatxbo6a3i-gp_4cgsao&rt=ipf.14,ipfr.586,ttfb.586,st.588,ipfrl.590,acrt.590,aaft.590,art.605,ns.-771&twt=4&mwt=3&imn=0&ima=0&sv=&cb=112&ucb=102&folid=_w9owaremkosy0pepz_dbyq0_18
https://www.google.com/gen_204?s=webhp&t=aft&atyp=csi&ei=w9owaremkosy0pepz_dbyq0&rt=wsrt.635,hst.55,prt.748,aft.748&folr=_w9owaremkosy0pepz_dbyq0_18&imn=8&dtc=199&stc=49&ima=0&imad=0&imac=2&wh=650&nt=navigate&dt=&ts=300&nhp=h2&ant=replace&opi=89978449
https://www.google.com/gen_204?atyp=csi&ei=w9owaremkosy0pepz_dbyq0&s=webhp&t=all&folr=_w9owaremkosy0pepz_dbyq0_18&imn=8&dtc=199&stc=49&ima=0&imad=0&imac=2&wh=650&nt=navigate&dt=&ts=300&nhp=h2&ant=replace&tbdba=0&tbdaa=0&thdba=0&thdaa=0&ime=1&imeh=0&imeha=0&imehb=0&imea=0&imeb=0&imel=0&imed=0&imeeb=0&imexb=0&scp=0&cb=87709&ucb=289969&lts=88009&adh=&mem=ujhs.10,tjhs.18,jhsl.2248,dm.4&nv=ne.1,feid.294174f9-1736-41f8-9109-2c8a73122261&net=dl.3550,ect.4g,rtt.50,sd.0&hp=&p=bs.true&rt=hst.55,prt.748,aft.748,xjses.802,xjsee.851,xjs.851,wsrt.635,cst.0,dnst.0,rqst.915,rspt.673,sslt.0,rqstt.393,unt.337,cstt.393,dit.1404&zx=1788269508623&opi=89978449
https://www.google.com/gen_204?atyp=i&ct=psnt&cad=&nt=navigate&ei=w9owaremkosy0pepz_dbyq0&zx=1788269508629&opi=89978449
https://www.google.com/xjs/_/js/k=xjs.hd.de.qts9wvqscfa.2019.o/ck=xjs.hd.8znh1jabwai.l.b1.o/am=aaaeaaagaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqaaemaaaaaqcgaqaaeaggaagbidaaaaeaaaaaaaadcayaaaamaaaaaaaaaaaaaaaaaayiaasabaaaaaaaagaacaagagaaagagaaayabiaakaaagayaaaaaaaaaaaiaaaaaaabaiagaaabcaaaa4a8gwamaaaaaaaaaqciwgcaaaacaygabaabacaaaaeaacaaaaaaaaaaaiaqgaqaqaaaaaaaeaaaaaaceaeiiagabcibgqqaaaqaawaiaaaaaaecjyeaiaaaaaaaqaaaagabaeagbbaaaaaabachaaeaaqbaaaqqageebajcoaaiaameaaaaabaaaaaaaaqaaaqaaaaaaaeqaaabaahaaaabaagameaiacaaaaeahqoabhhquaaaaaaaaaaaaaaaaaaaaaaaaaabaaawwc6kgaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaakgnaaaaaaaasbg/d=0/dg=0/br=1/ujg=1/rs=act90of682cjylexef6jhjcqumjmiukfaw/m=sy10n,hgv0mf,sy24a,zmpthf,ueshwc,sy248,sy19h,yhnubc,sy2eo,sy2el,vtmfj,sy2bj,sysn,sy2bi,sy2bh,n8yo7e,sy2bm,sy1wk,sy1wl,sy1ix,sy1iy,sy1j2,sy1im,sy1ii,sy1df,sy1i2,sy1fp,sy1di,sy1dh,sy9d,sy1dg,sy1de,sy1dc,sycg,syh6,sy1ih,sy1if,sy1ig,sy1i1,sy1ie,sy1i9,sy1fj,sy1i8,sy1i3,sy1ij,sy1i0,sy1id,sy1hx,sy1ia,sy1hw,sy1i7,sy1i5,sy1i4,sy1hz,sy1g6,sy11q,sy1ic,syo0,syl5,syl8,syl6,sy2bl,jywekf,u9eyge,sy14z,lol8vb,sy152,sy151,sy144,sy143,sy13e,sy138,sy13f,sy13z,sydr,syds,sydl,sy142,sy13c,sy13a,sy139,syhi,sy137,sy13y,sy13w,sy13v,sy13u,syiq,syhj,syhh,syeb,sy13x,sy140,sy13d,sy13j,sy130,sy141,sy13l,sy13q,sy13m,sy13i,sy13h,sy13g,sy132,sy12x,sy11s,sy11r,sy133,ms4mzb,sy10e,b2qlpe,sy198,nzu6v,sy19q,sy9m,wlnqgd,sy12w,sy12u,sy12t,dpree,sy19s,sy19r,nabpbb,abd,sy4er,tdfkye?cb=121509378&xjs=s3
https://www.google.com/xjs/_/js/md=2/k=xjs.hd.de.qts9wvqscfa.2019.o/am=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaeaggaaaaibaaaaaaaaaaaaaaaayaaaaaaaaaaaaaaaaaaaaaaayiaasabaaaaaaaagaacaagagaaagaaaaayabiaakaaaaayaaaaaaaaaaaaaaaaaaabagagaaabcaaaa4a8gwaeaaaaaaaaaqaiagaaaaaaaagabaabacaaaaeaacaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaeaaaaaacgaaaaaaaqaaaaaaaaaaaaaaaaaaaaaaaaaqaaaaaaaaaaaaaaaaaaabacgaaeaaabaaaaaaaaaaaaaaaaaaamaaaaaaaaaaaaaaaaaaaqaaaaaaaaqaaabaahaaaaaaaaaaaaiacaaaaeahqoabhhquaaaaaaaaaaaaaaaaaaaaaaaaaabaaawwc6kgaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaakgnaaaaaaaasbg/rs=act90ohyxzjs8yjgrs1si2ebu7ah2zbsxg?cb=121509378
https://www.google.com/client_204?atyp=i&biw=1352&bih=650&dpr=1&ei=w9owaremkosy0pepz_dbyq0&opi=89978449
https://www.google.com/xjs/_/js/k=xjs.hd.de.qts9wvqscfa.2019.o/ck=xjs.hd.8znh1jabwai.l.b1.o/am=aaaeaaagaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqaaemaaaaaqcgaqaaeaggaagbidaaaaeaaaaaaaadcayaaaamaaaaaaaaaaaaaaaaaayiaasabaaaaaaaagaacaagagaaagagaaayabiaakaaagayaaaaaaaaaaaiaaaaaaabaiagaaabcaaaa4a8gwamaaaaaaaaaqciwgcaaaacaygabaabacaaaaeaacaaaaaaaaaaaiaqgaqaqaaaaaaaeaaaaaaceaeiiagabcibgqqaaaqaawaiaaaaaaecjyeaiaaaaaaaqaaaagabaeagbbaaaaaabachaaeaaqbaaaqqageebajcoaaiaameaaaaabaaaaaaaaqaaaqaaaaaaaeqaaabaahaaaabaagameaiacaaaaeahqoabhhquaaaaaaaaaaaaaaaaaaaaaaaaaabaaawwc6kgaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaakgnaaaaaaaasbg/d=0/dg=0/br=1/ujg=1/rs=act90of682cjylexef6jhjcqumjmiukfaw/m=sy2n7,sy1vp,ifl?cb=121509378&xjs=s3
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1991
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 2325
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3981
comments 0

What is IcedID?

IcedID is a banking trojan-type malware that allows attackers to utilize it to steal the banking credentials of the victims. IcedID aka BokBot mainly targets businesses and steals payment information, it also acts as a loader and can deliver other viruses or download additional modules.

Researchers identified IcedID for the first time in Autumn 2017 when the first victims suffered from attacks by this malware. Upon further investigation, researchers revealed that IcedID is a modular virus that carries very advanced functions. In addition, it was initially reported that IcedID does not seem to feature any borrowed or stolen code from other trojans which is atypical for more developed malware samples like the one we are dealing with today.

General description of IcedID malware

It is thought that IcedID is being operated by a group of threat actors with connections to Eastern European cyber-bands. In addition, criminals behind IcedID are known to collaborate with creators or distributors of Emotet and TrickBot.

IcedID attacks are targeted mostly at banks in North America and a few select banking organizations in the United Kingdom. This malware targets mostly corporate bank accounts, payment card providers, mobile services providers, payroll, webmail, and e-commerce sites. We were not able to find any information about attacks directed at private users at this point.

However, this very well might change at some point in the future as evidence suggests that the criminals behind IcedID are preparing new and, possibly, bigger campaigns. There have appeared several removal tools, so it's no wonder hackers try to level the game up. As a matter of fact, network propagation functionality was added to this malware, giving it the ability to move across various endpoints.

Speaking of additions, IcedID is being actively maintained and upgraded by its authors despite several removal tools. For example, the second version of the virus significantly reworked the code and made the IcedID modular, giving it the ability to fetch plugins on-demand after the execution of the base file. This made the virus much harder to detect and defend against. While it is generally believed that this virus relies 100% on code created from scratch, some researchers suggest that the malware does, in fact, reuse code from version 2.0 of Pony malware. Apparently, the borrowed function is in charge of stealing data from email accounts although Pony code may have been used for other applications within the virus.

Unfortunately, constant upgrades are most likely one of the leading factors that contributed to the rising popularity of this trojan. This is bad news especially considering that this trojan is already using extremely advanced techniques as complex web injects.

Once the execution process is complete, IcedID creates a local proxy to intercept and control all web traffic of the infected user.

When the malware detects that a victim is navigating to the bank's website, IcedID can redirect the user to a replica of the webpage located on the server that is controlled by the attackers. Threat actors carefully reconstruct the webpage and make the experience as seamless as possible for the victim by maintaining an active connection with the real website all the time. This allows IcedID to use the correct URL in the address bar and even display a legit SSL certificate.

Of course, from this point on every action of the user is being recorded and social engineering is used to retrieve as many credentials and administrative information as possible.

IcedID malware analysis

A video recorded in the ANY.RUN interactive malware hunting service shows the execution process of IcedID. Users can utilize this information to take a deep dive into how this malware functions under the hood.

icedid execution process graph Figure 1: Shows the graph of processes generated by the ANY.RUN malware hunting service.

text report of the IcedID analysis Figure 2: ANY.RUN allows creating customizable text reports that contain detailed and nicely structured information. This function is perfect for making presentations.

IcedID execution process

IcedID authors constantly make changes to the malware, so its execution process can dramatically vary from one version to another.

Our example was distributed in the form of a malicious Microsoft Office document with macro. Maldocs macro dropped an obfuscated command-line file and started its execution. Wscript.exe was started through the command-line execution process to download the payload which was, in turn, executed by cmd.exe. After the payload started its execution, it injected into the svchost.exe process which, then, activated malicious activities such as stealing personal data, establishing a connection with the C2 server, creating scheduled tasks, and more.

Distribution of IcedID malware

IcedID uses a typical delivery method for banking trojans — attackers distribute it in malicious Microsoft Office documents that prompt the users to enable macros and, once it is done, activate the download of the executable to the victim's machine.

The unique aspect of IcedID distribution campaigns lies in the meticulous approach to email crafting that threat actors employ. While most malware types that use email campaigns as the mains distribution channel tend to target the broadest audience they can, IcedID authors choose to work with much narrower focus groups and craft every email with greater detail than the usual standard in the industry.

While any email with a malicious attachment is designed to lower your guard and make you download and open the file, usually attackers pick very general topics with little to no personalization.

IcedID authors use spear-phishing techniques, meaning that they learn details about their victims and use them to increase the effectiveness of their emails. If a latter carrying IcedID is directed at a car dealer from Arizona, it is likely to contain information about a car dealership in Arizona, references to local companies or even colleagues of the victim.

The creation of such targeted campaigns requires hackers to devote time to investigative work in preparation for each bunch of emails, but it is guaranteed to make messages look less like a scam and more like legit business communication.

It should be noted that in some cases IcedID may infect the system in tandem with other malware samples. It can download and can be downloaded by malware such as Emotet or TrickBot trojans.

How to detect IcedID?

This malware creates files that allow analysts to detect it with a high degree of certainty. To detect IcedID, Open the "Files" tab in the lower part of the task's window and take a look at the created files. If you see folders with names such as "lchej" and "ydmfipkzqfsb" within C:\Users\admin\AppData\Local\ directory and files with names "pczapabclgpba", "mtkdonmlmxelaa", "ozwzefgpkzmzba", and "zcnejolyretaa", as shown on the figure below, be sure that it is IcedID in front of you.

how to detect icedid Figure 3: File created by IcedID malware

Summary

IcedID trojan is one of the examples of the new generation of malware. Although it was built from the ground up by its creators, it uses a lot of unique code and has functions not much inferior to those found in the most advanced older viruses such as Trickbot.

However, what makes IcedID potentially even more dangerous is the evolved mentality of its authors, who use spear-phishing to increase the effectiveness of their distribution campaigns.

Before, we could secure ourselves from a lot of threats by removal tools and raising awareness about the dangers of suspicious emails and infected documents. With IcedID we need to rely more on technological lines of defense since some email templates that authors have used and will use again are indistinguishable from real professional communication.

Here, at ANY.RUN it is our job to provide cybersecurity researchers with all the necessary tools to study and neutralize threats like IcedID and we hope that you will find these tools extremely useful in your line of work!

HAVE A LOOK AT

BQTLock screenshot
BQTLock
bqtlock baqiyatlock
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.
Read More
Lynx screenshot
Lynx
lynx
Lynx is a double extortion ransomware: attackers encrypt important and sensitive data and demand a ransom for decryption simultaneously threatening to publish or sell the data. Active since mid-2024. Among techniques are terminating processes and services, privilege escalation, deleting shadow copies. Distribution by phishing, malvertising, exploiting vulnerabilities.
Read More
Black Basta screenshot
Black Basta
blackbasta
Black Basta is a ransomware-as-a-service operated by Storm-1811. It emerged in 2022 and uses double extortion tactics, encrypting data and stealing it for ransom. The malware often gains access through spear-phishing and uses tools like QakBot and Cobalt Strike. It's known for exploiting system vulnerabilities and using advanced obfuscation techniques.
Read More
Jigsaw screenshot
Jigsaw
jigsaw
The Jigsaw ransomware, initially detected in 2016, encrypts files on compromised systems and requires a ransom payment in Bitcoin. If the ransom is not paid, the malware starts deleting files, increasing the pressure on victims to comply. Its source code is publicly accessible, allowing various threat actors to customize and repurpose the malware for different objectives.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
Mirage2FA screenshot
Mirage2FA
mirage2fa
Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.
Read More