From IcedID to Dagon Locker Ransomware in 29 Days
· Published 29/04/2024 17:23 · Modified 01/05/2024 23:05
Essential information
- Published
- 29/04/2024 17:23
- Modified
- 01/05/2024 23:05
- Tags
- access token adfind anydesk aws collector cobalt strike discovery domain account encrypted icedid manipulation modify system powershell prometheustds rclone seatbelt sharefinder shell utility
- Related entities
- 33 observables, 33 techniques (mitre), 2 malware
Description
This intrusion started in August 2023 with a phishing campaign that distributed IcedID malware. The phishing operation utilized the Prometheus Traffic Direction System (TDS) to deliver the malware and victims were directed to a fraudulent website, mimicking an Azure download portal.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (33)
87.251.67.16851.89.133.345.15.161.97194.58.68.187159.89.124.188151.236.9.176151.236.9.166159.223.95.82143.110.245.3823.159.160.88http://87.251.67.168:443http://194.58.68.187:443http://159.89.124.188:443http://159.223.95.82:443http://151.236.9.176:443http://151.236.9.166:443http://143.110.245.38:443winupdate.us.toultrascihictur.comrpgmagglader.comrestohalto.sitepatricammote.comoopscokir.commoashraya.commagiraptoy.comfraktomaam.comewacootili.comf6e5dbff14ef272ce07743887a16decbee2607f512ff2a9045415c8e0c05dbb4a0191a300263167506b9b5d99575c4049a778d1a8ded71dcb8072e87f5f0bbcf9da84133ed36960523e3c332189eca71ca42d847e2e79b78d182da8da4546830839cf7905dc3337bebe7f8ba127961e6cd40c52ec3a1e09084c9c1ccd202418e65edf9bc2c15ef125ff58ac597125b040c487640860d84eea93b9ef6b5bb8ca6332afc80371187881ef9a6f80e5c244b44af746b20342b8722f7b56b61604953
Techniques (MITRE) (33)
-
Permission Groups Discovery
-
Data from Network Shared Drive
-
Network Share Discovery
-
Inhibit System Recovery
-
Domain Trust Discovery
-
System Time Discovery
-
Create Account
-
Exfiltration Over Web Service
-
System Location Discovery
-
Unsecured Credentials
-
Account Discovery
-
Remote Services
-
Encrypted Channel
-
Service Stop
-
Data Encrypted for Impact
-
System Binary Proxy Execution
-
System Information Discovery
-
Ingress Tool Transfer
-
File and Directory Discovery
-
Application Layer Protocol
-
Windows Management Instrumentation
-
Process Injection
-
Automated Exfiltration
-
Remote Access Tools
-
Access Token Manipulation
-
User Execution
-
System Owner/User Discovery
-
Obfuscated Files or Information
-
Archive Collected Data
-
Scheduled Task/Job
-
Impair Defenses
-
OS Credential Dumping
-
Command and Scripting Interpreter
Malware (2)
-
FamilyPublished 29/04/2024 19:15 · Modified 29/04/2024 19:15
-
FamilyPublished 16/12/2024 14:25 · Modified 16/12/2024 14:25