PULSE NAME
Recent IcedID (Bokbot) activity
WHITE AlienVault 2023-04-12 Modified: 2023-04-12
17
IOCs
MEDIUM VOLUME
IcedID (Bokbot) was distributed through thread-hijacked emails with PDF attachments. The PDF files have links that redirect to Google Firebase Storage URLs hosting password-protected zip archives.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Trojan:Win32/Bokbot IcedID
Indicators of Compromise (17)
All URL hostname FileHash-SHA256 IPv4 domain
TYPEINDICATORDESCRIPTIONCREATED
URL https://firebasestorage.googleapis.com/v0/b/logical-waters-377622.appspot.com/o/MCRERY0iJA%2FDocs_Inv_April_11_450.zip?alt=media&token=799ca8a7-44ce-44e8-b93d-a346faaf0ea3 2023-04-12
hostname logical-waters-377622.appspot.com 2023-04-12
FileHash-SHA256 52d3dd78d3f1a14e18d0689ed8c5b43372f9e76401ef1ff68522575e6251d2cf 2023-04-12
FileHash-SHA256 54d064799115f302a66220b3d0920c1158608a5ba76277666c4ac532b53e855f 2023-04-12
FileHash-SHA256 5953f8f23092714626427316dd66ff2e160f03d2c57dcb1a4745d2e593c907ae 2023-04-12
FileHash-SHA256 59e0f6e9c4ce2ab8116049d59525c6391598f2def4125515d86b61822926784f 2023-04-12
FileHash-SHA256 6d07c2e05e76dd17f1871c206e92f08b69c5a7804d646e5f1e943a169a8c50ee 2023-04-12
FileHash-SHA256 dbf233743eb74ab66af8d1c803f53b7fe313ed70756efcc795ea4082c2f3c0c8 2023-04-12
IPv4 162.33.178.40 CC=US ASN=AS399629 BLNWX 2023-04-12
IPv4 172.86.75.64 CC=NL ASN=AS399629 BLNWX 2023-04-12
IPv4 192.153.57.82 CC=NL ASN=AS399629 BLNWX 2023-04-12
IPv4 193.149.176.100 CC=US ASN=AS399629 BLNWX 2023-04-12
IPv4 45.61.137.159 CC=NL ASN=AS399629 BLNWX 2023-04-12
IPv4 80.77.23.51 CC=GB ASN=AS212228 servinga GmbH 2023-04-12
domain deadwinston.com 2023-04-12
domain shoterqana.com 2023-04-12
domain villageskaier.com 2023-04-12