Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
102
Global rank
125 infographic chevron month
Month rank
115 infographic chevron week
Week rank
0
IOCs

IcedID is a banking trojan-type malware which allows attackers to utilize it to steal banking credentials of the victims. IcedID aka BokBot mainly targets businesses and steals payment information, it also acts as a loader and can deliver another viruses or download additional modules.

Trojan
Type
Unknown
Origin
1 September, 2017
First seen
23 August, 2026
Last seen
Also known as
BokBot

How to analyze IcedID with ANY.RUN

Type
Unknown
Origin
1 September, 2017
First seen
23 August, 2026
Last seen

IOCs

IP addresses
2.16.241.201
142.251.110.100
142.251.110.95
142.251.20.139
150.171.27.11
192.178.183.94
142.251.154.119
150.171.22.17
48.192.1.65
48.209.6.48
48.209.138.189
48.192.1.64
142.251.14.102
57.153.246.3
23.200.214.115
142.251.127.84
172.217.119.4
40.126.31.67
142.251.13.113
23.200.213.221
Hashes
3ad2dc318056d0a2024af1804ea741146cfc18cc404649a44610cbf8b2056cf2
d95aed234f932a1c48a2b1b0d98c60ca31f962310c03158e2884ab4ddd3ea1e0
99c61abf41c3aec38cab3ed6270adbca9a247bbf5f9aa9d29ecb0659a5527f48
d4c9d9027326271a89ce51fcaf328ed673f17be33469ff979e8ab8dd501e664f
c9cd5c9609e70005926ae5171726a4142ffbcccc771d307efcd195dafc1e6b4b
f6f2e247226ab06e9b56ae2d10ccd02d9298abccac85c56abfa19e5587446d54
49656c178b17198470ad6906e9ee0865f16f01c1dbbf11c613b55a07246a7918
52360f17c9c70c9cea3316560b40c4d89fd705ed7e6b6088c99fc54d4cc35eb5
69ac56d2fdf3c71b766d3cc49b33b36f1287cc2503310811017467dfcb455926
be704f094c5df6a8fc7e0861e564e137c8729585ce37b7b0225b58c3b1ace070
f5416abd44d13cab9b55b30910c7aed5a342462684372e317951c099a4397d8c
acfd3cd36e0dfcf1dcb67c7f31f2a5b9ba0815528a0c604d4330dfaa9e683e51
53b47c4f3a403686b7c3298cb866c743fcd845e5f52b86540b1ea48341d844d1
e225fe554387ce0ae77076bdda53c6dbbd2d5222c50309a248b0ae53c81a8033
2413de0a5c66078987b1dd515fa6a90f7fabbc9071244d173210029b20fb5dac
6017552e8ce880024ae1a4f31030594857224073161d48f3057b9b1df0bca75f
43017b68a20a5062ec2043e2a84d879e05e5a4e4364de3c5596f6abec0221507
338955bdb88a3b402764c2085292b5b993ed64aa3e6b17b0e4cb25e1e22b776d
9f5d2c72044ad00416c3679a24a480102000745969e19db59e48c632b923caba
7b679812c49cc807100697b4b6b6a37923a85426c09486318c1b22b87baac586
Domains
config.edge.skype.com
ogads-pa.clients6.google.com
www.gstatic.com
google.com
edge.microsoft.com
fonts.gstatic.com
www.google.com
play.google.com
www.bing.com
activation-v2.sls.microsoft.com
settings-win.data.microsoft.com
crl.microsoft.com
clientservices.googleapis.com
ocsp.digicert.com
update.googleapis.com
optimizationguide-pa.googleapis.com
accounts.google.com
go.microsoft.com
login.live.com
client.wns.windows.com
URLs
https://edge.microsoft.com/serviceexperimentation/v2/
https://config.edge.skype.com/config/v1/edge/109.0.1518.115?clientid=-626569875466424637&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfull=0&scpguard=1&scpfre=0&scpver=18&osarch=x86&osver=6.1.7601&wu=0&devicefamily=desktop&uma=1&sessionid=17&mngd=0&installdate=1604373552&edu=0&bphint=0
https://google.com/
https://www.google.com/
https://www.google.com/xjs/_/ss/k=xjs.hd.nsbyjazounw.l.w.o/am=aaaegaaaaaaaaaaaaagaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqdaeaaaaaamabaaaaaaqaaaiaaaaaaeaaaaaaaghaaaadaaaaaaaaaaaaaaaaaaabaaabaaaaaaaaaaabaaaaaaaaaaaigaaaaaqaaigaiaaaaaaaaaaaaaaeaaaaaaaaaaeaicaaaaaaaaaaaaaakaaaaaaaaaaidaycaaaacamaaaaaaaaaaaaaaaaaaaaaaaaaaaigesaaabaaaaabaaaaaageaaiqqbgaafelagaaaaaaabwaiaaaaaaaaaaaacaaaaaaaaaaaaiaaqbeiaaqaaaiaaaaaqabaaeabaqacaerqaaikaeaaacaqaaaagaaaaaaaiaaaaaaaaaaaaaciaaaaaaaaaaacqaaadhaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaaaao/d=1/ed=1/rs=act90oeqp9lrx_3zwqxtl0mxdfq6_7dqga/m=cdos,cr,hsm,jsa,mb4zub,cet90b,snun3,qddgke,stsdmc,dtl0hd,ehdfl,yv5bee,d,csi?cb=121509378
https://www.google.com/xjs/_/js/k=xjs.hd.da.bj42cfm3ac0.2019.o/am=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaqabaaaaqqaaaaaaaaaaaaaaeaaiaaaaaaaaaaaaaaaaaaagqbaaabaaaaaaaaaaabaaaaaaaagaaagaagaaqaaigaiaagaaaaaaaaaaaaaaaaaaaaaaecacaabacaaagd8yyauaaaaaaaaaaakayaaaaaaaalaaaaagagaaabaaagaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaeaaiaaaaaafaaaaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaiaaaaaaaaaaaaaaaaaiaaaaoaabaaaaqaaaaaaaaaaaaaaaaaaayaaaaaaaaaaaaaaaaiaaaaaaaaaaiaaaagaaiaaaaaaaaagaaaaqaaaogacdzakiicaaaaaaaaaaaaaaaaaaaaaaaaaaaewac7kaociaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacd0faaaaaacaxq/d=1/ed=1/dg=4/rs=act90ohnsvy4ay7edvhncjjuopbj2qj49a/ee=alejib:b8glwd;afeap:tkrajf;bmxagc:e5bfse;bgs6mb:fidj5d;bjwmce:cxx2wb;bujtu:v6yjn;ciztgb:kqhykb;cxxawb:yyrlvc;dqeued:fevhcf;dulqb:rkfg5c;dkk6ge:jzmw9e;dpcr3d:zl72xf;eabsz:mxzt9d;esrpqc:mntjvc;evnhjf:pw70gc;ejxhpb:pshqh;emz2bf:zr1jrb;enlcnd:wehg4;f54iae:zgsfh;f9mqte:uorcbe;fsxmue:fizr8b;fkukfc:i8h2c;fmv9nc:o1tzwc;g0khtb:liaoz;glezl:j1a7od;hmddwe:g8qudb;htpxrd:gx8jab;ibadcc:ryqurb;ioglcf:b5lhvb;isdwvc:qzxzob;jxjsm:ii1rgf;jxs8fb:qj0suc;jqsq7d:y9ephe;jsbnhc:xd8iud;k08hxe:zmbglf;k5nytd:zdzcre;ka3p2:c3jnce;kdb6nb:fe9n2;koxck:ozqgte;kqzwid:zmkkn;kdihef:bwtnj;kpraue:tia57b;lbgrlc:sdcwhb,xvmnvd;lbn8cf:bj9l0c;leikze:byftob,lsjvmc;lxa8b:q7odkd;lsnahb:ucglnb;mnkade:kmcd1d;nj1rfe:qtnobf;npkak:sdcwhb;nseox:lazg7b;njiwef:yvgi7d;np8qkd:dpx6qc;nyt6ic:jn2sgd;oifwub:qfoycd;ogagbe:cnte0;oiqe2c:tfpek;ook5v:sp69o;oohiye:mpeaqb;pjplud:poes9b;pptlxd:pjyjx;q1ow7b:x5csu;q7ij9c:bvlz3d;qe20be:gilto;qfoglf:pq2aoe;qgr0gd:mlhmy;qylf2b:paqyud;qw8feb:jpavue;r4iiib:qwfekf;r9ulx:cr7ufe;rcf5sd:x1kbmd;raf5me:mgvfmc;sltqo:kh1xye;smdl4c:ftfgo;snun3:zwdk9d,xd8kp;snk4je:wwmhg;sci3yc:e7hzgb,e7hzgb;shpf6e:n0pvgc;snahre:mgctob;swcqad:fxbczc;szqq3e:dnhofb;tiuvqd:lwtjwd;troz1d:vvvzjb;u96prd:fsr04;ubkjz:lgdjgb;udry1c:n0f29d,w50nvd,eps46d,wciyue;uvmjed:eesrsb;uvzb9c:ivpz6d;uyrieb:hztaqc;uyg7kb:wqd0g;v2htte:rolty;vgrfx:vfqbr;vmuem:pl7sbc;vn6jic:ddqyuf;vocgde:yquhtb;vha7bd:vamqff;vsaqsb:pgf2re;w9qsqe:yncwwc;wdgyfe:jcvoxd;wxtneb:qu9bmd;wfmdue:g3mjlb;wl55ib:vgbikb;y3c5sd:fgbfle;yizmrd:a1yn5d;yv5bee:ivpz6d;ynhubf:snssob;zsh6tc:qavyle;zweua:afr4cf;zloomb:p0i0ec;a56pne:jefcwb;aaje9c:whw6ef;acj9tf:qkftvc;avzq3e:emevib;az61od:artwj;aci7y:z5tr6c;buikwb:wmwehe;bcpxsc:gszljb;cet90b:ws9tlc;cftwae:gt8qnd;diosbb:zggg9b;dllj2:qqt3gf;dxdzv:a7qtqd;dowigb:ebz3mb,ebz3mb;dtl0hd:llqwfe;ebaesb:ck63tb;ebz5nd:audvde;ehdfl:ofjvkb;ejkchc:atg1be;eo3lse:uefomb;euoxy:ozjbq;g8nkx:u4mzkc;gaub4:tn6bme;gbfhr:qztzib;gtvsi:ekuoyd;h3myod:ws9tlc;hk67qb:qweo5b;hvic1b:kqhykb;hehb1:sfczq;hjro6e:f62sg;hlqgx:fwz1ic;hslsyc:vl118;hwovhd:zw4u8c;ifqykf:qihfr;jjj2g:kf2o2b;k1o0rf:pnould;k2qxcb:xy51pe;kbam9d:mkhygd;loo0vd:ota3ae;lbfkyf:mqgdud;liaz7d:kf2o2b;mmvogb:qdm7k;mwzs9c:fz5ukf;mtkmcc:zg5tfe;nbznze:cverjb;ne6ojf:fi4rsc;nebwnb:mxkx9d;njw4gd:dpfzh;nrdcw:sueode;ogtauc:soxfj;osunyd:ftfgo,ftfgo;oulnpc:ragdlc;oibhre:oumkrd;okuaud:witadb;pkjixd:vcenhc;pnsl2d:j9yuyc;pxdryb:jkokve;pj82le:ww04df;qgv2uc:hhi04c;qqeooc:kum7z,d7ysfd;qzx2fc:j0xre;qas3gd:yilg6e;qafbpd:sgy6zb;qavrxe:i0c9u;qddgke:d7ysfd,x4fyxe;rdexkf:fekkd;rmwaj:pms6sd;ropkz:hjoqoe;stsdmc:jksfdf;szmdvc:rdgefc;th4iie:ymry6;tesrsb:bmlai;toskvd:zcqp3;trzl0b:qy8pfe;uuqky:u2v3ud;veycnb:faqsvd;vrlmvf:iw9xo;vfvwpd:lcrkwe;w3bzcb:zpgaib;w9w86d:xwhueb,dt4g2b,gkd90c,lwvzve;wfpbg:jbgbbc;wqlyve:alufp;wr5frb:o1gjze,ttcote;wv5pjc:l8kgxe;x9n9ie:kh4qof;xbbsrc:new1qc;xparob:avqz9b;yil5ab:mt0zbd;ysnimc:cpibjd;yxtchf:kum7z;z97ygf:oug9te;zaigpb:sl0pxd/m=cdos,cr,hsm,jsa,mb4zub,cet90b,snun3,qddgke,stsdmc,dtl0hd,ehdfl,yv5bee,d,csi?cb=121509378
https://www.google.com/tia/tia.png
https://www.google.com/async/hpba?yv=3&cs=0&ei=4pckarvxe_6owpaplj_fsqu&async=_basejs:/xjs/_/js/k%3dxjs.hd.da.bj42cfm3ac0.2019.o/am%3daaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaqabaaaaqqaaaaaaaaaaaaaaeaaiaaaaaaaaaaaaaaaaaaagqaaaabaaaaaaaaaaabaaaaaaaagaaagaagaaqaaigaaaagaaaaaaaaaaaaaaaaaaaaaaecacaabacaaagd8yyauaaaaaaaaaaakayaaaaaaaalaaaaagagaaabaaagaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaeaaiaaaaaafaaaaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaiaaaaaaaaaaaaaaaaaiaaaaoaabaaaaqaaaaaaaaaaaaaaaaaaayaaaaaaaaaaaaaaaaiaaaaaaaaaaiaaaagaaiaaaaaaaaagaaaaqaaaogacdzakiicaaaaaaaaaaaaaaaaaaaaaaaaaaaewac7kaiciaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacd0faaaaaacaxq/dg%3d0/rs%3dact90ohg7pvzqh-rgibldlm2z9d-qrjxew?cb%3d121509378,_basecss:/xjs/_/ss/k%3dxjs.hd.nsbyjazounw.l.w.o/am%3daaaegaaaaaaaaaaaaagaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqdaeaaaaaamabaaaaaaqaaaiaaaaaaeaaaaaaaghaaaadaaaaaaaaaaaaaaaaaaabaaabaaaaaaaaaaabaaaaaaaaaaaigaaaaaqaaigaiaaaaaaaaaaaaaaeaaaaaaaaaaeaicaaaaaaaaaaaaaakaaaaaaaaaaidaycaaaacamaaaaaaaaaaaaaaaaaaaaaaaaaaaigesaaabaaaaabaaaaaageaaiqqbgaafelagaaaaaaabwaiaaaaaaaaaaaacaaaaaaaaaaaaiaaqbeiaaqaaaiaaaaaqabaaeabaqacaerqaaikaeaaacaqaaaagaaaaaaaiaaaaaaaaaaaaaciaaaaaaaaaaacqaaadhaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaaaao/rs%3dact90oeqp9lrx_3zwqxtl0mxdfq6_7dqga?cb%3d121509378,_basecomb:/xjs/_/js/k%3dxjs.hd.da.bj42cfm3ac0.2019.o/ck%3dxjs.hd.nsbyjazounw.l.w.o/am%3daaaegaaaaaaaaaaaaagaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqdaeaaaaaamabcaaqabqaaayqaaaaaeaaaaaaaghaaiadaaaaaaaaaaaaaaaaagqbaaabaaaaaaaaaaabaaaaaaaagaaigaagaaqaaigaiaagaaaaaaaaaaaeaaaaaaaaaaecicaabacaaagd8yya0aaaaaaaaaainaycaaaacamlaaaaagagaaabaaagaaaaaaaaaaigesaaabaaaaabaaaaaageaaiqqbgaafelagaiaaaaabwaiaaaaaaaaaaaacaaaaaaaiaaaaiaaqbeiaaqaaaiaaaaoqabaaearaqacaerqaaikaeaaacayaaaagaaaaaaaiaaaiaaaaaaaaaciaaaagaaiaaacqaaadhaaaaqaaaogacdzakiicaaaaaaaaaaaaaaaaaaaaaaaaaaaewac7kaociaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacd0faaaaaacaxq/d%3d1/ed%3d1/dg%3d0/ujg%3d1/rs%3dact90oeikehr16p8a-bg4lbvfsjozyphzg?cb%3d121509378,_fmt:prog,_id:_4pckarvxe_6owpaplj_fsqu_7&sp_imghp=false&sp_hpep=2&sp_hpte=0&vet=10ahukewi76oxkjbawaxv-fbaihztpn1yqj-0kcbm..i
https://www.google.com/gen_204?s=webhp&t=cap&atyp=csi&ei=4pckarvxe_6owpaplj_fsqu&rt=wsrt.886,hst.220,cbt.1135&folr=_4pckarvxe_6owpaplj_fsqu_7&nt=navigate&ts=83695&nhp=h2&opi=89978449
https://www.google.com/gen_204?atyp=i&ct=bxjs&cad=&b=0&ei=4pckarvxe_6owpaplj_fsqu&zx=1787465955500&opi=89978449
https://www.google.com/gen_204?ei=4pckarvxe_6owpaplj_fsqu&vet=10ahukewi76oxkjbawaxv-fbaihztpn1yqhjahccc..s&bl=9reg&s=webhp&gl=dk&pc=search_homepage&ismobile=false
https://www.google.com/xjs/_/js/k=xjs.hd.da.bj42cfm3ac0.2019.o/ck=xjs.hd.nsbyjazounw.l.w.o/am=aaaegaaaaaaaaaaaaagaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqdaeaaaaaamabcaaqabqaaayqaaaaaeaaaaaaaghaaiadaaaaaaaaaaaaaaaaagqbaaabaaaaaaaaaaabaaaaaaaagaaigaagaaqaaigaiaagaaaaaaaaaaaeaaaaaaaaaaecicaabacaaagd8yya0aaaaaaaaaainaycaaaacamlaaaaagagaaabaaagaaaaaaaaaaigesaaabaaaaabaaaaaageaaiqqbgaafelagaiaaaaabwaiaaaaaaaaaaaacaaaaaaaiaaaaiaaqbeiaaqaaaiaaaaoqabaaearaqacaerqaaikaeaaacayaaaagaaaaaaaiaaaiaaaaaaaaaciaaaagaaiaaacqaaadhaaaaqaaaogacdzakiicaaaaaaaaaaaaaaaaaaaaaaaaaaaewac7kaociaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacd0faaaaaacaxq/d=0/dg=0/ujg=1/rs=act90oeikehr16p8a-bg4lbvfsjozyphzg/m=ueshwc,sy240,sy19k,yhnubc?cb=121509378&xjs=s3
https://www.google.com/xjs/_/js/md=2/k=xjs.hd.da.bj42cfm3ac0.2019.o/am=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaqabaaaaqqaaaaaaaaaaaaaaeaaiaaaaaaaaaaaaaaaaaaagqbaaabaaaaaaaaaaabaaaaaaaagaaagaagaaqaaigaiaagaaaaaaaaaaaaaaaaaaaaaaecacaabacaaagd8yyauaaaaaaaaaaakayaaaaaaaalaaaaagagaaabaaagaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaeaaiaaaaaafaaaaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaaaiaaaaaaaaaaaaaaaaaiaaaaoaabaaaaqaaaaaaaaaaaaaaaaaaayaaaaaaaaaaaaaaaaiaaaaaaaaaaiaaaagaaiaaaaaaaaagaaaaqaaaogacdzakiicaaaaaaaaaaaaaaaaaaaaaaaaaaaewac7kaociaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacd0faaaaaacaxq/rs=act90ohnsvy4ay7edvhncjjuopbj2qj49a?cb=121509378
https://www.google.com/gen_204?atyp=csi&ei=4pckarvxe_6owpaplj_fsqu&s=jsa&jsi=hd,st.1950,t.281,at.281,et.focus,n.vzr2rb,an.jt1ex,cn.1,ie.0,ett.2&zx=1787465955699&opi=89978449
https://www.google.com/gen_204?atyp=csi&ei=4pckarvxe_6owpaplj_fsqu&s=jsa&jsi=hd,st.2230,tni.3,atni.3,et.focus,n.vzr2rb,an.jt1ex,cn.2,ie.0,ett.2&zx=1787465955700&opi=89978449
https://edge.microsoft.com/autofillservice/v1/pages/chvdahjvbwuvmta5ljauntqxnc4xndksean11vq7sgck8rifdwlir0c=?alt=proto
https://www.google.com/gen_204?atyp=csi&ei=4pckarvxe_6owpaplj_fsqu&s=jsa&jsi=hd,st.1950,t.281,at.281,et.focus,n.vzr2rb,an.jt1ex,cn.1,ie.0,af.3,ett.2,sned.true,snei.true&zx=1787465955703&opi=89978449
https://www.google.com/gen_204?atyp=csi&ei=4pckarvxe_6owpaplj_fsqu&s=jsa&jsi=hd,st.2230,tni.3,atni.3,et.focus,n.vzr2rb,an.jt1ex,cn.2,ie.0,af.3,ett.2,sned.true,snei.true&zx=1787465955704&opi=89978449
https://fonts.gstatic.com/s/i/productlogos/googleg/v6/24px.svg
https://www.gstatic.com/og/_/js/k=og.asy.en_us.9c_ayamawpk.2019.o/rt=j/m=_ac,_awd,ada,lldp,qads,abld/exm=/d=1/ed=1/rs=aa2yrtv58eeanmbu_qdmup5cuxjwalxw7g
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 3153
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 8509
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 11265
comments 0

What is IcedID?

IcedID is a banking trojan-type malware that allows attackers to utilize it to steal the banking credentials of the victims. IcedID aka BokBot mainly targets businesses and steals payment information, it also acts as a loader and can deliver other viruses or download additional modules.

Researchers identified IcedID for the first time in Autumn 2017 when the first victims suffered from attacks by this malware. Upon further investigation, researchers revealed that IcedID is a modular virus that carries very advanced functions. In addition, it was initially reported that IcedID does not seem to feature any borrowed or stolen code from other trojans which is atypical for more developed malware samples like the one we are dealing with today.

General description of IcedID malware

It is thought that IcedID is being operated by a group of threat actors with connections to Eastern European cyber-bands. In addition, criminals behind IcedID are known to collaborate with creators or distributors of Emotet and TrickBot.

IcedID attacks are targeted mostly at banks in North America and a few select banking organizations in the United Kingdom. This malware targets mostly corporate bank accounts, payment card providers, mobile services providers, payroll, webmail, and e-commerce sites. We were not able to find any information about attacks directed at private users at this point.

However, this very well might change at some point in the future as evidence suggests that the criminals behind IcedID are preparing new and, possibly, bigger campaigns. There have appeared several removal tools, so it's no wonder hackers try to level the game up. As a matter of fact, network propagation functionality was added to this malware, giving it the ability to move across various endpoints.

Speaking of additions, IcedID is being actively maintained and upgraded by its authors despite several removal tools. For example, the second version of the virus significantly reworked the code and made the IcedID modular, giving it the ability to fetch plugins on-demand after the execution of the base file. This made the virus much harder to detect and defend against. While it is generally believed that this virus relies 100% on code created from scratch, some researchers suggest that the malware does, in fact, reuse code from version 2.0 of Pony malware. Apparently, the borrowed function is in charge of stealing data from email accounts although Pony code may have been used for other applications within the virus.

Unfortunately, constant upgrades are most likely one of the leading factors that contributed to the rising popularity of this trojan. This is bad news especially considering that this trojan is already using extremely advanced techniques as complex web injects.

Once the execution process is complete, IcedID creates a local proxy to intercept and control all web traffic of the infected user.

When the malware detects that a victim is navigating to the bank's website, IcedID can redirect the user to a replica of the webpage located on the server that is controlled by the attackers. Threat actors carefully reconstruct the webpage and make the experience as seamless as possible for the victim by maintaining an active connection with the real website all the time. This allows IcedID to use the correct URL in the address bar and even display a legit SSL certificate.

Of course, from this point on every action of the user is being recorded and social engineering is used to retrieve as many credentials and administrative information as possible.

IcedID malware analysis

A video recorded in the ANY.RUN interactive malware hunting service shows the execution process of IcedID. Users can utilize this information to take a deep dive into how this malware functions under the hood.

icedid execution process graph Figure 1: Shows the graph of processes generated by the ANY.RUN malware hunting service.

text report of the IcedID analysis Figure 2: ANY.RUN allows creating customizable text reports that contain detailed and nicely structured information. This function is perfect for making presentations.

IcedID execution process

IcedID authors constantly make changes to the malware, so its execution process can dramatically vary from one version to another.

Our example was distributed in the form of a malicious Microsoft Office document with macro. Maldocs macro dropped an obfuscated command-line file and started its execution. Wscript.exe was started through the command-line execution process to download the payload which was, in turn, executed by cmd.exe. After the payload started its execution, it injected into the svchost.exe process which, then, activated malicious activities such as stealing personal data, establishing a connection with the C2 server, creating scheduled tasks, and more.

Distribution of IcedID malware

IcedID uses a typical delivery method for banking trojans — attackers distribute it in malicious Microsoft Office documents that prompt the users to enable macros and, once it is done, activate the download of the executable to the victim's machine.

The unique aspect of IcedID distribution campaigns lies in the meticulous approach to email crafting that threat actors employ. While most malware types that use email campaigns as the mains distribution channel tend to target the broadest audience they can, IcedID authors choose to work with much narrower focus groups and craft every email with greater detail than the usual standard in the industry.

While any email with a malicious attachment is designed to lower your guard and make you download and open the file, usually attackers pick very general topics with little to no personalization.

IcedID authors use spear-phishing techniques, meaning that they learn details about their victims and use them to increase the effectiveness of their emails. If a latter carrying IcedID is directed at a car dealer from Arizona, it is likely to contain information about a car dealership in Arizona, references to local companies or even colleagues of the victim.

The creation of such targeted campaigns requires hackers to devote time to investigative work in preparation for each bunch of emails, but it is guaranteed to make messages look less like a scam and more like legit business communication.

It should be noted that in some cases IcedID may infect the system in tandem with other malware samples. It can download and can be downloaded by malware such as Emotet or TrickBot trojans.

How to detect IcedID?

This malware creates files that allow analysts to detect it with a high degree of certainty. To detect IcedID, Open the "Files" tab in the lower part of the task's window and take a look at the created files. If you see folders with names such as "lchej" and "ydmfipkzqfsb" within C:\Users\admin\AppData\Local\ directory and files with names "pczapabclgpba", "mtkdonmlmxelaa", "ozwzefgpkzmzba", and "zcnejolyretaa", as shown on the figure below, be sure that it is IcedID in front of you.

how to detect icedid Figure 3: File created by IcedID malware

Summary

IcedID trojan is one of the examples of the new generation of malware. Although it was built from the ground up by its creators, it uses a lot of unique code and has functions not much inferior to those found in the most advanced older viruses such as Trickbot.

However, what makes IcedID potentially even more dangerous is the evolved mentality of its authors, who use spear-phishing to increase the effectiveness of their distribution campaigns.

Before, we could secure ourselves from a lot of threats by removal tools and raising awareness about the dangers of suspicious emails and infected documents. With IcedID we need to rely more on technological lines of defense since some email templates that authors have used and will use again are indistinguishable from real professional communication.

Here, at ANY.RUN it is our job to provide cybersecurity researchers with all the necessary tools to study and neutralize threats like IcedID and we hope that you will find these tools extremely useful in your line of work!

HAVE A LOOK AT

ClickLock screenshot
ClickLock
clicklock
ClickLock is a macOS information stealer and remote backdoor distributed via deceptive, terminal-based social engineering pages. Once executed, it bypasses Gatekeeper checks by stripping download quarantine flags and signing its executable with ad-hoc digital certificates. If users resist its initial demands, the malware initiates high-frequency background loops that repeatedly kill vital operating system applications to force plaintext password entry. It exfiltrates captured browser data, system keychain credentials, and cryptocurrency wallets to a Telegram bot before establishing a permanent backdoor.
Read More
Kratos screenshot
Kratos
kratos
Kratos is a mature Phishing-as-a-Service (PhaaS) platform that evolved from the Sneaky2FA kit to specialize in stealing Microsoft 365 credentials through sophisticated Adversary-in-the-Middle (AiTM) techniques. The service provides low-skilled affiliates with a turnkey solution featuring an advanced administrative dashboard, integrated anti-bot defenses, and real-time data exfiltration via the Telegram Bot API. Although an international law enforcement action known as Operation Olympus Blade disrupted its central infrastructure in July 2026, the kit remains a primary example of the industrialization of modern cybercrime.
Read More
LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
Kali365 screenshot
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 environments by stealing OAuth authentication tokens instead of passwords. First observed in April 2026, the service enables even low-skilled threat actors to bypass multi-factor authentication (MFA), gain persistent access to corporate cloud accounts, and compromise business communications, files, and collaboration platforms. Kali365 represents a shift from traditional credential theft toward session hijacking and token abuse, making it a significant threat to organizations that rely on Microsoft 365.
Read More
Netwalker screenshot
Netwalker
netwalker ransomware
Netwalker is ransomware — it belongs to a malware family which encrypts files and demands users to pay a ransom to get their data back. Netwalker utilizes several sophisticated techniques, such as process hollowing and code obfuscation to target corporate victims.
Read More
Sliver screenshot
Sliver
sliver
Sliver is an open-source command-and-control (C2) framework that has been increasingly adopted by threat actors as an alternative to tools like Cobalt Strike. Developed by security firm Bishop Fox, Sliver was initially intended for legitimate security testing and red teaming exercises. However, its robust features and open-source nature have made it attractive to malicious actors seeking to control compromised systems.
Read More