Telecom Tidbits
Jared's Network and Security Blog
  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links

BOLO: IcedID Banking Trojan/Emotet Trojan

November 14, 2017 Jared Hall BOLOs

A unique banking trojan called IcedID is hitting businesses throughout the US and Canada. In most implementations, IcedID is being bundled with another Trojan called Emotet and delivered via spam Email of infected Word documents.

What makes IcedID unusual is that it propagates through a business network.  It sets up a Command and Control channel using SSL encryption.  It installs a proxy server and listens for online banking connections.  The user’s credentials are then intercepted and sent to the hacker.

Comments in the code suggest the malware was developed in the Russia/Ukraine/Eastern-Europe region.

  • Make sure all antivirus and malware detection systems are up to date.  
  • Be careful what you click on.
« The Cyber Kill-Chain: Revisited » Exploiting Virtual Machines with RAM Row-Hammer Attacks

Tools & Downloads

Download Center

Categories

Good Reads (PDF)

Recent Posts

  • PayPal Woes and Degenerative AI
  • A Pathetic Defense of Julian Assange
  • Damned if you do. Damned if you don’t.
  • ProtonMail? Not Worth an Electron!
  • Give it a REST: Serious WordPress Bugs
$
Select Payment Method
Personal Info

Donation Total: $20.00

↑

  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links
Temporal Based Intelligence © 2017