{"id":3196,"date":"2021-07-02T11:34:25","date_gmt":"2021-07-02T16:34:25","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3196"},"modified":"2021-07-02T11:34:26","modified_gmt":"2021-07-02T16:34:26","slug":"icedid-dangerous-banking-trojan","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/","title":{"rendered":"IcedID dangerous banking trojan"},"content":{"rendered":"\n<p>A new banking Trojan called IcedID, detected by researchers last September, has wreaked havoc among financial institutions in the US, UK, and Canada, including banks, payment card providers, mobile service providers, and e-commerce sites. The impact of the banking Trojan is not yet clear, but initial reports show that its impact is still limited at the time of publication.<\/p>\n\n\n\n<p>Initial analysis of the Trojan reveals that its delivery method is via the botnet infrastructure of another Trojan known as EMOTET. In this case, the botnet is being used as a malware delivery platform, similar to previous attacks where it dropped the DRIDEX Trojan as a payload. Once IcedID is on the infected system, it will carry out its attacks via redirection and web injection. The malware also contains a network propagation module that gives it the ability to move, not only to other endpoints, but possibly to terminal servers as well.<\/p>\n\n\n\n<p>This threat has been circulating at an increasing rate, thanks to a series of email campaigns using Microsoft Excel spreadsheet attachments, according to Uptycs researchers Ashwin Vamshi and Abhijit Mohanta. In fact, in the first three months of the year, Uptyc telemetry flagged more than 15,000 HTTP requests for more than 4,000 malicious documents, most of which 93% were Microsoft Excel spreadsheets with the extensions .XLS or .XLSM malicious of course.<\/p>\n\n\n\n<p>IcedID shares some similarities with other banking Trojans such as Zeus and Gozi with common characteristics such as the use of redirection and web injection techniques in their routine. Despite the similarities, IceID&#8217;s analysis shows that it does not appear to borrow code from other banking Trojans, meaning that it is not based on existing Trojans, but is new malware in its own right. It is also likely that IceID will see further evolution of its features as its authors develop it, so being informed is important because it is not known when new versions of it will be released. <\/p>\n\n\n\n<p>The best we can do against this is to protect users and businesses from these threats by detecting malicious files and spam messages, as well as blocking all related malicious URLs.<\/p>\n\n\n\n<p>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/\">Trickbot malware that steals banking credentials<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/bizarro-dangerous-new-banking-trojan\/\">Bizarro dangerous new banking Trojan<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new banking Trojan called IcedID, detected by researchers last September, has wreaked havoc among financial institutions in the US, UK, and Canada, including banks, payment card providers, mobile service providers, and e-commerce sites. The impact of the banking Trojan is not yet clear, but initial reports show that its impact is still limited at [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3203,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36,106],"class_list":["post-3196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-trojan"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>IcedID dangerous banking trojan - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"As we well know, the threats of the Web do not stop resting with updates and new appearances and today we will see a Trojan called IcedID....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"IcedID dangerous banking trojan - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"As we well know, the threats of the Web do not stop resting with updates and new appearances and today we will see a Trojan called IcedID....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-02T16:34:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-07-02T16:34:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Trojan.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"IcedID dangerous banking trojan\",\"datePublished\":\"2021-07-02T16:34:25+00:00\",\"dateModified\":\"2021-07-02T16:34:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/\"},\"wordCount\":368,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Trojan.png\",\"keywords\":[\"Cybersecurity\",\"Trojan\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/\",\"name\":\"IcedID dangerous banking trojan - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Trojan.png\",\"datePublished\":\"2021-07-02T16:34:25+00:00\",\"dateModified\":\"2021-07-02T16:34:26+00:00\",\"description\":\"As we well know, the threats of the Web do not stop resting with updates and new appearances and today we will see a Trojan called IcedID....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Trojan.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Trojan.png\",\"width\":1280,\"height\":720},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/icedid-dangerous-banking-trojan\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"IcedID dangerous banking trojan\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"IcedID dangerous banking trojan - Truxgo Server Blog","description":"As we well know, the threats of the Web do not stop resting with updates and new appearances and today we will see a Trojan called IcedID....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/","og_locale":"es_MX","og_type":"article","og_title":"IcedID dangerous banking trojan - Truxgo Server Blog","og_description":"As we well know, the threats of the Web do not stop resting with updates and new appearances and today we will see a Trojan called IcedID....","og_url":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-07-02T16:34:25+00:00","article_modified_time":"2021-07-02T16:34:26+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Trojan.png","type":"image\/png"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"IcedID dangerous banking trojan","datePublished":"2021-07-02T16:34:25+00:00","dateModified":"2021-07-02T16:34:26+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/"},"wordCount":368,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Trojan.png","keywords":["Cybersecurity","Trojan"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/","url":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/","name":"IcedID dangerous banking trojan - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Trojan.png","datePublished":"2021-07-02T16:34:25+00:00","dateModified":"2021-07-02T16:34:26+00:00","description":"As we well know, the threats of the Web do not stop resting with updates and new appearances and today we will see a Trojan called IcedID....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Trojan.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Trojan.png","width":1280,"height":720},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"IcedID dangerous banking trojan"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3196"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3196\/revisions"}],"predecessor-version":[{"id":3205,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3196\/revisions\/3205"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3203"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}