cyber_threat_intelligence/campaigns/IcedID
2022-08-04 12:18:19 +02:00
..
README.md Update 2022-08-04 12:18:19 +02:00

IcedID - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the campaign known as IcedID. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor

Actors

These actors are associated with IcedID or other actors linked to the campaign.

ID Actor Confidence
1 IcedID High
2 UAC-0098 High
3 TA551 High

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of IcedID.

ID IP address Hostname Actor Confidence
1 5.61.46.161 - IcedID High
2 5.149.252.179 hnh7.arenal.xyz IcedID High
3 31.24.224.12 1f18e00c.setaptr.net IcedID High
4 31.24.228.170 31.24.228.170.static.midphase.com IcedID High
5 31.184.199.11 dalesmanager.com IcedID High
6 37.120.222.100 - IcedID High
7 45.129.99.241 354851-vds-mamozw.gmhost.pp.ua IcedID High
8 45.138.172.179 - IcedID High
9 45.147.228.198 - IcedID High
10 45.147.230.82 - IcedID High
11 45.147.230.88 mailnode7.bulletproof-mail.biz IcedID High
12 45.147.231.113 - IcedID High
13 45.153.240.135 - IcedID High
14 45.153.241.115 - IcedID High
15 46.17.98.191 - IcedID High
16 46.21.153.211 211.153.21.46.static.swiftway.net TA551 High
17 46.249.62.199 - IcedID High
18 79.141.161.176 zzs7bp73.copycomdigital.com IcedID High
19 79.141.164.241 x6ts.mtsgamingpro.fun IcedID High
20 79.141.166.39 webimpa.com IcedID High
21 ... ... ... ...

There are 79 more IOC items available. Please use our online service to access the data.

References

The following list contains external sources which discuss the campaign and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2022 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!